Join Active Directory in OS X Lion
From ITSCWiki
These steps are for joining a OS X Lion AND Mountain Lion to the CLLA AD domain.
NOTE: The AD record must exist prior to joining. Create the computer account first then follow these steps.
- Open System Preferences (See Figure 1)
- Or click the Apple in upper left corner then choose System Preferences
- Open User & Groups (See Figure 2)
- Click Login Options (See Figure 3 - Item #1)
- Unlock if necessary (See Figure 3 - Item #2)
- Click Join... (See Figure 3 - Item #3)
- At the next Dialog that comes up select Open Directory Utility... (See Figure 4)
- In Directory Utility click the Services Tab and select Active Directory then click the Edit button (pencil icon) (See Figure 5)
- Once the settings for Active Directory open Make fill the two settings (See Figure 6)
- Active Directory Domain - clla.ad.tamu.edu
- Computer ID - computer's name that matches existing AD record
- Under the User Experience tab make the following changes (See Figure 6)
- Uncheck Use UNC path...
- Check Create mobile account at login
- Uncheck Require confirmation before creating mobile account
- Leave all checkboxes unchecked under Mappings tab
- Make the following changes under Administrative tab (See Figure 7)
- Uncheck Allow authentication from any domain in the forest
- Check Allow administration by:
- Remove existing groups from Allow administration by
- Add a domain admin group such as CLLA\CLLA dept-admins to the Allow administration by
- Enter your AD username and password and do not prefix the username with CLLA\ (See Figure 8)
- If prompted to replace existing account choose Replace
- Once the bind is complete and the Bind button turns to Unbind click Ok to get back to Directory Utility
- Select the Search Policy tab and under Authentication and Contacts delete the All Domains line.
- Under both Authentication and Contacts click the + sign to and add the domain path (See Figure 9)
- For CLLA use /Active Directory/CLLA/clla.ad.tamu.edu
- Double check that Authentication looks similar to Figure 10 (Note: /Local/MCX may not always be there)
- Double check that Contacts looks similar to Figure 11
- Click Apply then close Directory Utility.
- Back under User & Groups in System Preferences you should see a green orb next to CLLA (See Figure 12)