Mac OS X Server User Managment
Total Page:16
File Type:pdf, Size:1020Kb
Mac OS X Server User Management Version 10.6 Snow Leopard K Apple Inc. Apple, the Apple logo, AirPort, AppleShare, Bonjour, © 2009 Apple Inc. All rights reserved. FireWire, iCal, iTunes, Mac, Mac OS, MacBook, Macintosh, QuickTime, SuperDrive, Xgrid, Xsan, and Xserve are The owner or authorized user of a valid copy of trademarks of Apple Inc., registered in the U.S. and other Mac OS X Server software may reproduce this countries. Apple Remote Desktop, Extensions Manager, publication for the purpose of learning to use such Finder, iWork, and Safari are trademarks of Apple Inc. software. No part of this publication may be reproduced Mac is a service mark of Apple Inc. or transmitted for commercial purposes, such as selling copies of this publication or for providing paid-for Adobe and PostScript are trademarks of Adobe Systems support services. Incorporated. Every effort has been made to ensure that the The Bluetooth® word mark and logos are registered information in this manual is accurate. Apple Inc. is not trademarks owned by the Bluetooth SIG, Inc. and any responsible for printing or clerical errors. use of such marks by Apple is under license. Apple Java and all Java-based trademarks and logos 1 Infinite Loop are trademarks or registered trademarks of Sun Cupertino, CA 95014-2084 Microsystems, Inc. in the U.S. and other countries. 408-996-1010 www.apple.com UNIX is a registered trademark of The Open Group. Use of the “keyboard” Apple logo (Option-Shift-K) for Other company and product names mentioned herein commercial purposes without the prior written consent are trademarks of their respective companies. Mention of Apple may constitute trademark infringement and of third-party products is for informational purposes unfair competition in violation of federal and state laws. only and constitutes neither an endorsement nor a recommendation. Apple assumes no responsibility with regard to the performance of these products. 019-1415/2009-08-01 Contents 13 Preface: About This Guide 13 What’s New in Workgroup Manager 14 What’s in This Guide 15 Using Onscreen Help 16 Documentation Map 17 Viewing PDF Guides Onscreen 17 Printing PDF Guides 18 Getting Documentation Updates 18 Getting Additional Information 19 Chapter 1: User Management Overview 19 Tools for User Management 19 Workgroup Manager 20 Server Admin 21 Server Preferences 21 Command-Line Tools 21 Accounts 22 Administrator Accounts 23 User Accounts 24 Group Accounts 25 Computer Accounts 25 Computer Groups 25 The User Experience 25 Authentication and Identity Validation 27 Information Access Control 28 SIDs and Windows Interoperability 29 Chapter 2: Getting Started with User Management 29 Setup Overview 32 Planning Strategies for User Management 32 Analyzing Your Environment 33 Identifying Directory Services Requirements 33 Determining Server and Storage Requirements 3 35 Choosing a Home Folder Structure 36 Devising a Home Folder Distribution Strategy 36 Identifying Groups 37 Determining Administrator Requirements 38 Chapter 3: Getting Started with Workgroup Manager 38 Configuring the Administrator’s Computer and Account 38 Setting Up an Administrator Computer 39 Creating a Directory Administrator Account 40 Using Workgroup Manager 40 Using Mac OS X Server v10.6 to Administer Earlier Versions of Mac OS X 40 Connecting and Authenticating to Directory Domains in Workgroup Manager 41 Major Workgroup Manager Tasks 42 Modifying Workgroup Manager Preferences 43 Finding and Listing Accounts 43 Working with Account Lists in Workgroup Manager 44 Listing Accounts in the Local Directory Domain 44 Listing Accounts in Search Policy Directory Domains 45 Listing Accounts in Available Directory Domains 46 Refreshing Account Lists 46 Finding Specific Accounts in a List 47 Using Advanced Search 47 Sorting Users and Groups 48 Shortcuts for Working with Accounts 48 Using Presets 48 Editing Multiple Accounts Simultaneously 50 Importing and Exporting Account Information 51 Chapter 4: Setting Up User Accounts 51 About User Accounts 51 Where User Accounts Are Stored 52 Predefined User Accounts 53 Administering User Accounts 53 Creating User Accounts 57 Creating Augmented User Records 58 Editing User Account Information 59 Editing User Account Information from the Command Line 59 Working with Read-Only User Accounts 60 Working with Guest Users 60 Working with Windows User Accounts 61 Deleting a User Account 62 Disabling a User Account 63 Working with Presets 4 Contents 63 Creating a Preset for User Accounts 64 Using Presets to Create Accounts 64 Renaming Presets 64 Editing Presets 65 Deleting a Preset 65 Working with Basic Settings 65 Modifying User Names 66 Modifying Short Names 67 Choosing Stable Short Names 68 Avoiding Duplicate Names 69 Modifying User IDs 70 Assigning a Password to a User 71 Assigning Administrator Privileges for a Server 72 Choosing a User’s Login Picture 73 Working with Privileges 73 Removing Administrative Privileges from a User 74 Giving a User Limited Administrative Capabilities 75 Giving a User Full Administrative Capabilities 76 Working with Advanced Settings 76 Enabling a User’s Calendar 77 Allowing a User to Log In to More Than One Computer at a Time 77 Choosing a Default Shell 78 Choosing a Password Type and Setting Password Options 79 Creating a Master List of Keywords 80 Applying Keywords to User Accounts 80 Editing Comments 81 Working with Group Settings 81 Choosing a User’s Primary Group 82 Reviewing a User’s Group Memberships 82 Adding a User to a Group 83 Removing a User from a Group 84 Working with Home Settings 84 Working with Mail Settings 84 Enabling Mail Service Account Options 85 Disabling a User’s Mail Service 85 Forwarding a User’s Mail 86 Working with Print Quota Settings 86 Enabling a User’s Access to All Available Print Queues 86 Enabling a User’s Access to Specific Print Queues 87 Removing a Print Quota for a Queue 88 Resetting a User’s Print Quota 88 Disabling a User’s Access to Print Queues That Enforce Quotas 89 Working with Info Settings Contents 5 89 Working with Windows Settings 90 Changing a Windows User’s Profile Location 91 Changing a Windows User’s Login Script Location 91 Changing a Windows User’s Home Folder Drive Letter 92 Changing a Windows User’s Home Folder Location 92 Working with GUIDs 92 Viewing GUIDs 93 Chapter 5: Setting Up Group Accounts 93 About Group Accounts 93 How Group Accounts Track Membership 94 Where Group Accounts Are Stored 94 Predefined Group Accounts 96 Administering Group Accounts 96 Creating Group Accounts 98 Creating a Preset for Group Accounts 98 Editing Group Account Information 99 Creating Hierarchical Groups 102 Upgrading Legacy Groups 102 Working with Read-Only Groups 103 Deleting a Group 103 Working with Basic Settings for Groups 103 Naming a Group 104 Defining a Group ID 105 Choosing a Group’s Login Picture 106 Enabling a Group’s Web Services When Connecting to Mac OS X Server v10.5 107 Working with Member Settings for Groups 107 Adding Users or Groups to a Group 109 Removing Group Members 111 Working with Group Folder Settings 111 Specifying No Group Folder 112 Creating a Group Folder 114 Designating a Group Folder for Use by Multiple Groups 115 Chapter 6: Setting Up Computers and Computer Groups 115 About Computer Accounts 116 Creating Computer Accounts 117 Working with Guest Computers 118 Working with Windows Computers 118 About Computer Groups 118 Differences Between Computer Groups and Computer Lists 119 Administering Computer Groups 119 Creating a Computer Group 6 Contents 120 Creating a Preset for Computer Groups 121 Using a Computer Group Preset 121 Adding Computers or Computer Groups to a Computer Group 122 Removing Computers and Computer Groups from a Computer Group 122 Deleting a Computer Group 123 Upgrading Computer Lists to Computer Groups 124 Chapter 7: Setting Up Home Folders 124 About Home Folders 125 Hosting Home Folders for Mac OS X Clients 125 Hosting Home Folders for Other Clients 126 Distributing Home Folders Across Multiple Servers 127 Administering Share Points 127 Setting Up a Share Point 128 Setting Up an Automountable AFP Share Point for Home Folders 129 Setting Up an Automountable NFS Share Point for Home Folders 130 Setting Up an SMB Share Point 132 Administering Home Folders 132 Specifying No Home Folder 133 Creating a Home Folder for a Local User 134 Creating a Network Home Folder 136 Creating a Custom Location for Home Folders 138 Setting Up a Home Folder for a Windows User 140 Setting Disk Quotas 141 Setting Disk Quotas for Windows Users to Avoid Data Loss 142 Using Presets to Choose Default Home Folders 142 Moving Home Folders 142 Deleting Home Folders 143 Chapter 8: Managing Portable Computers 143 About Mobile Accounts 144 About Portable Home Directories 145 Logging In to Mobile Accounts 146 Resolving Sync Conflicts 146 About External Accounts 147 Logging In to External Accounts 148 Considerations and Strategies for Deploying Mobile Accounts 148 Advantages of Using Mobile Accounts 149 Considerations for Using Mobile Accounts 151 Strategies for Syncing Content 152 Setting Up Mobile Accounts for Use on Portable Computers 152 Configuring Portable Computers 153 Managing Mobile Clients Without Using Mobile Accounts Contents 7 153 Unknown Mac OS X Portable Computers 154 Using Mac OS X Portable Computers with One Primary Local User 154 Using Mac OS X Portable Computers with Multiple Users 156 Securing Mobile Clients 157 Optimizing the File Server for Mobile Accounts 158 Chapter 9: Client Management Overview 159 Using Network-Visible Resources 160 Customizing the User Experience