Applies to: All versions of Centrify DirectControl on Mac OS X
Question:Under what conditions is it necessary to create a Mobile Account for Mac users?
Answer:There are three scenarios in which a Mobile Account is necessary on Mac machines:
- If the hard drive has been encrypted with FileVault; only users with local profiles are allowed to unlock FileVault systems (Mobile Accounts exist as both local and network accounts).
For more information, see:
KB-2148: How to set up FileVault 2 on Mac OS X
- If the user has a network home directory configured and wishes to keep backups of their home folder synced between a network file server and the local Mac.
- If the user has a network home directory configured and needs to use their AD credentials to login to the Mac while off the network.
Note 1:
- If the user is configured with a local home directory (e.g. /Users/username/ ), then Mobile Accounts are NOT required for offline logins.
- The Centrify Agent employs its own cache to allow for AD users to login offline.
Note 2:
- A Mobile Account user with a local home directory will see their Mobile Account Settings disabled in the Users & Groups Preferences panel. This is normal since there is no network directory specified and therefore nothing to sync with.
Note 3:
Further Reference:
Please see the following KBs for details on how to set up Mobile Accounts on Mac systems in different environments: