All versions of Centrify DirectControl on Mac OS XQuestion:
Under what conditions is it necessary to create a Mobile Account for Mac users?Answer:
There are three scenarios in which a Mobile Account is necessary on Mac machines:
- If the hard drive has been encrypted with FileVault; only users with local profiles are allowed to unlock FileVault systems (Mobile Accounts exist as both local and network accounts).
For more information, see:
KB-2148: How to set up FileVault 2 on Mac OS X
- If the user has a network home directory configured and wishes to keep backups of their home folder synced between a network file server and the local Mac.
- If the user has a network home directory configured and needs to use their AD credentials to login to the Mac while off the network.
- If the user is configured with a local home directory (e.g. /Users/username/ ), then Mobile Accounts are NOT required for offline logins.
- The Centrify Agent employs its own cache to allow for AD users to login offline.
- A Mobile Account user with a local home directory will see their Mobile Account Settings disabled in the Users & Groups Preferences panel. This is normal since there is no network directory specified and therefore nothing to sync with.
Please see the following KBs for details on how to set up Mobile Accounts on Mac systems in different environments: