Microsoft Active Directory integration on macOS

For companies using Microsoft Active Directory on-premise or via Azure (Microsoft Cloud), Apple has had an excellent integration for years to link the Mac to the Active Directory domain. Benefits are that network users can log in to the Mac without creating a local account for this and all Macs are viewable in Active Directory. In short, you log in with the same name and password on your Mac as you do on the server or your Microsoft Office365 environment.

There are also some drawbacks for companies that are increasingly moving toward a hybrid setup with Azure Active Directory. In this blog, we look at Active Directory integrations and how this helps achieve the zero-touch deployment model and ensure security.

Moving away from the Active Directory linkage

In many cases it is quite possible to use local accounts instead of network accounts. More and more people are choosing a MacBook Air or MacBook Pro instead of a desktop model, eliminating the need for multiple users to log in to the same device. Yet we are concerned that this still happens too infrequently and many devices are still shared there.

Zero-touch Deployment

Delivering the MacBook to the user (home or business) and having them unpack it themselves is a unique experience. Thanks to Apple Business Manager and Apple's Automated Device Enrollment, all it takes is an Internet connection to automatically prepare the MacBook with apps and configurations without IT intervention.

To enable installation outside the corporate network, a local account created using Azure Active Directory login credentials will be used. Thanks in part to Mobile Device Management, the user can get started right away. In a subsequent blog we will dwell on the possibilities of such MDM namely JAMF, Jamf Now, Jamf Federation and Jamf Pro herein as MDM.

Kerberos Single Sign-On Extension

Now what if the user's password expires in Active Directory Apple has built an extension into macOS from version Catalina: Kerberos Single Sign-On Extension. This easy-to-use tool provides the functions below:

  • Active Directory account management: users can easily change the AD password and receive notifications when it is about to expire. The local account password is automatically updated.
  • Kerberos support: the extension automatically retrieves a Kerberos TGT ticket for authentication on websites, apps and file servers, for example.
  • Password policy: password requirements can be easily configured to comply with policies in Active Directory.

The extension becomes visible with a key icon in the status bar and detects if the Mac is connected to the corporate network (via VPN). The user is automatically prompted to log in once.

Azure AD Seamless Single Sign-On

In a hybrid environment with Active Directory and Azure Active Directory, Seamless Single Sign-On can be used. This means that the user is automatically logged in to all web applications linked via Azure AD. Thanks to the Kerberos ticket, the email address is read and the user is automatically logged in. This is especially useful when working with software like office365. You are already logged in the same account and when you go to the office365 website you are immediately logged in. It is also increasingly possible to link applications and Web applications with SSO (Single Sign-on).

Many of our customers do not know and/or did not know that this is also possible with the Mac. And that the Mac can certainly be a full-fledged workplace in a secure office environment. Of course we are happy to help you with this, for more information please contact us. contact with us.

Recent blogs

apple header
Blog
Apple 50 Years: 50 Years of Daring to Think Differently
This year, Apple celebrates its 50th anniversary. A milestone that cannot simply be overlooked. Because whether you are a fan or not: Apple has permanently changed the way we work, communicate, and create. At Analyst ICT, we are proud to be part of this ecosystem. As an Apple Technical Partner, we work daily with technology that is not only powerful but, above all, logical and pleasant to use. A different perspective on technology Apple has always distinguished itself by one simple conviction: technology should help people, not hinder them. No unnecessary complexity, but simplicity and ease of use. That aligns seamlessly...
browser password
Blog
Why saving passwords in your browser is not a good idea
The blog post below was created in response to a question during our engineering meeting. Every two weeks, we get together with all of our technical staff to discuss the latest developments in technology or with clients. Good client questions also arise during these meetings, such as this one. Time to do some research. Thank you, Wiebe! You've probably experienced this: you log in to a website, and your browser asks if it should remember your password. Convenient, fast, and you don't have to remember anything. However, there's a risk involved. In practice, we see that many security incidents start with something small. Like saving passwords…
Apple Business
Blog
Apple is taking a big step with Apple Business
Apple announced something special this week. Not a new device, but something that might be even more interesting for many organizations: Apple Business. A completely new platform with which Apple brings all its business services together in one environment. And frankly: this is a development that we at Analyst ICT are following with great interest. The problem: fragmented tools and unnecessary complexity Many organizations working with Apple will recognize the problem: Multiple portals (Apple Business Manager, Business Essentials, Connect) Different tools for management, branding, and support Additional costs for basic functionalities such as device management This leads to a lack of clarity and costs time. And…

A newsletter

Superlogic right?