Binding Macs to AD
Contents
Account Requirements
Only those who have run SED Webnew can login.
- You must use an "-adm" account to join the machine.
- You cannot login with an -adm account, so your administrators group needs to include non-adm accounts.
- If an account doesn't work for joining or logging in, check with the OIT AD Administrators to see if the password encryption needs to be changed or Webnew re-run on the account.
Machine Requirements
- Must be 10.5.3 or later
Instructions
Based on http://www.bu.edu/pcsc/desktop/ad/AD-OD/AD-OD_10.5.2.pdf
Join the machine to AD
Applications -> Utilities -> Directory Utility
- Click on the +
- Change the type to Active Directory
- Put "ad.bu.edu" in for the Domain
- Put in the machine name (sed-username or sed-username-laptop or sed-department-1)
- Put in your -adm username
- Put in your -adm password
- Click okay.
Configure the machine
- If you get a successful join, click on Services
- Double-click on Active Directory
- Open Advanced Settings
- Under User Experience:
- Check "Create mobile account at login" if setting up a laptop
- Uncheck Use UNC Path...
- Under Mappings:
Set bu-ph-index-id-numeric for the UID attribute
- Under Administrative:
- Add "AD\SED-IT" to the list of administrative groups.
- Add any other groups that should be administrators. The primary user should be an administrator.
- Click OK
Under System Preferences -> Accounts -> Login Options be sure to:
- Set Automatic Login: Disabled
- Set Display login windows as: Name and password
- Set Allow network users to login to this computer
Go to System Preferences -> Sharing and set the sharing name to be the same as the AD name. This is optional but will reduce confusion.
If this is the first time you have joined THIS computer to AD
- Go to the Active Directory Users and Computers plug-in on a Windows box and move the machine to the correct OU, inside the SED top level OU.
Go here: https://oit-uwa.bu.edu/users/macadm/default.aspx and give the mac access.
Verify that the computer is a member of SED-VIEW-ADMINISTRATORS (Properties -> Member of)
Try it out!
- Reboot and test!
- If it fails, log back in with an local administrator account, and turn off and then back on "Force local home directory". This has worked in several cases.
Additional Settings
Make active directory share logins easier: run defaults write /Library/Preferences/com.apple.NetworkAuthorization UseShortName -bool YES from the command line.

