|
Mac OS X 10.3 & 10.4 play very well with AD (Active Directory), especially 10.4 which is easy to bind to AD and authenticate a local user account and/or network services on both AFP SMB servers, AD is actually very flexible now, even true single-sign-on services. It is completely possible to convert a local account into a full AD account flawlessly, even caching the local credentials so if the authentication server dies you can still work. What’s really cool is the ability to embed AD users in local OD (Open Directory) groups on a Mac OS X Server so you can manage Mac shares with very granular control. The big political challenge is getting the AD Admin to extend the AD schema so you can manage client MCX (preferences/Home Directory). You can still do a lot without this extension though. 10.5 is going to make all this stuff even better which will use OD4 (Open Directory v4). OD4 doesn’t need the AD schema extended in short.
The best web sites to use are: afp548.com (the directory services product manager for Apple is a moderator here) macwindows.com
|
|
|