Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-3049: How to use the "Map zone groups to local admin group" GP for Mac systems

Centrify Identity Service, Mac Edition ,  

12 April,16 at 11:19 AM

Applies to: All versions of Centrify DirectControl on Mac OS X
 
Question:
 
The following group policy has been enabled and an AD security group called "Local Admins@domain.com" has been added into the list:
 
Computer Configuration / Centrify Settings / Mac OS X Settings / Accounts / "Map zone groups to local admin group"
 
However members of that group are not being detected as Local Admin users when they log into a target Mac.
 
How can this GP be used properly?
 
 
Answer:
 
The group name formatting for this policy differs depending on if the target Mac systems are joined in Zone Mode or Auto Zone mode.
 
 
=== Auto Zone ===
 
If the Mac systems are joined in Auto Zone mode, then the format should be:
 
AD Group Name@domain.com
 
Note: This is the default format returned when using the Browse button when adding the group into the list:
 
User-added image
 
 
 
=== Zone Mode ===
 
If the Mac systems are joined in Zone Mode, then the GP should use the UNIX group name as entered in the DirectManage / DirectControl console.
 
The Browse button cannot be used here and the name needs to be manually entered:
 
User-added image
 

 
=== ======== ===
 
Note that if both Auto Zone and Zone mode systems are in the same environment, then both formats can be inserted into the GP at the same time:
 
User-added image
 
 


 
 
== For Zone Mode environments only: Adding an AD group into a Zone ==
 
  1. Open the DirectManage / DirectControl console and expand to the target Zone > UNIX Data > Groups
     
  2. Right-click and select "Create UNIX Group...", search for the AD group to be added and enter a GID and UNIX group name.
     
    User-added image
     
  3. Once the GP has been configured and the UNIX profile for the AD group has been created, go to the Mac, open the Terminal and run the following commands:
     
    adgpupdate
    sudo adflush
    adquery user -A ad_username
     
  4. Look in the unixGroups: section of the adquery output, if the user is a member of that AD group, then the UNIX group name will appear in the list:
     
    User-added image
     
  5. Once the UNIX group names matches, then the next time the user logs into the Mac, it will be recognised as Local Admin account:

    User-added image

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.