Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-7425: What UID generation method should be used upon OS X Active Directory join?

Centrify Identity Service, Mac Edition ,  

2 September,16 at 11:52 PM

Applies to: Centrify Identity Service, Mac Edition

Question:

Which UID generation method should be used upon joining a Mac to Active Directory?  Apple UID or Centrify UID?

Answer:

There are two UID generation methods that Centrify supports for joining Macs to Active Directory:
  • Centrify UID Generation (default):
    • This method should be used if the Macs were never bound to Active Directory before using Centrify.  
  • Apple UID Generation:
    • This method should be used if the Macs were previously joined to Active Directory using Apple's native AD plugin.  This ensures compatibility for existing users.
  • Enabling Apple UID Generation:
    • AutoZone Mode:
      • During AD Join with Centrify Join Assistant:
        • In the "Advanced Options", click the checkbox next to "Utilize Apple UID generation scheme"  
        • Please see the below screenshot for an example:
                                             User-added image
  • Using Group Policy:
    •  Enable the following Group Policy:
       
      Computer Configuration / Centrify Settings / DirectControl Settings / Adclient Settings / "Generate new uid/gid using Apple scheme in Auto Zone"
       
      (See the Explain tab of this GP for more information on this setting)
  • Zone Mode:
  • Using Centrify Access Manager:
    • Open the DirectManage Access Manager and open the Zone properties where the user accounts have been added.  
    • Under the "User Defaults" tab, set the UID to "Use Apple UID scheme".
    • If necessary, do the same for the "Group Defaults" tab and the GID value.
    • Remove and re-add the users' UNIX Profile in that Zone
    • Please see the below screenshots for an example:
                                            User-added imageUser-added image


For more information on UID generation please see the following community article:
 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.