Mac OS X Server User Management for Version 10.5 Leopard
Total Page:16
File Type:pdf, Size:1020Kb
Mac OS X Server User Management For Version 10.5 Leopard K Apple Inc. Apple, the Apple logo, AirPort, AppleShare, Bonjour, © 2007 Apple Inc. All rights reserved. FireWire, iCal, iTunes, Mac, Mac OS, MacBook, Macintosh, QuickTime, SuperDrive, Xgrid, Xsan, and Xserve are The owner or authorized user of a valid copy of trademarks of Apple Inc., registered in the U.S. and other Mac OS X Server software may reproduce this countries. Apple Remote Desktop, Extensions Manager, publication for the purpose of learning to use such Finder, iWork, and Safari are trademarks of Apple Inc. software. No part of this publication may be reproduced Mac is a service mark of Apple Inc. or transmitted for commercial purposes, such as selling copies of this publication or for providing paid-for Adobe and PostScript are trademarks of Adobe Systems support services. Incorporated. Every effort has been made to ensure that the The Bluetooth® word mark and logos are registered information in this manual is accurate. Apple Inc. is not trademarks owned by the Bluetooth SIG, Inc. and any responsible for printing or clerical errors. use of such marks by Apple is under license. Apple Java and all Java-based trademarks and logos are 1 Infinite Loop trademarks or registered trademarks of Sun Cupertino, CA 95014-2084 Microsystems, Inc. in the U.S. and other countries. 408-996-1010 www.apple.com UNIX is a registered trademark of The Open Group. Use of the “keyboard” Apple logo (Option-Shift-K) for Other company and product names mentioned herein commercial purposes without the prior written consent are trademarks of their respective companies. Mention of Apple may constitute trademark infringement and of third-party products is for informational purposes unfair competition in violation of federal and state laws. only and constitutes neither an endorsement nor a recommendation. Apple assumes no responsibility with regard to the performance of these products. 019-0938/2007-09-01 1 Contents Preface 13 About This Guide 13 What’s New in Workgroup Manager 14 What’s in This Guide 15 Using Onscreen Help 16 Mac OS X Server Administration Guides 17 Viewing PDF Guides Onscreen 17 Printing PDF Guides 18 Getting Documentation Updates 18 Getting Additional Information Chapter 1 19 User Management Overview 19 Tools for User Management 19 Workgroup Manager 20 Server Admin 21 Server Preferences 21 NetBoot 21 NetInstall 22 Command-Line Tools 22 Accounts 23 Administrator Accounts 24 User Accounts 25 Group Accounts 25 Computer Accounts 26 Computer Groups 26 The User Experience 26 Authentication and Identity Validation 27 Information Access Control Chapter 2 31 Getting Started with User Management 31 Setup Overview 34 Planning Strategies for User Management 34 Analyzing Your Environment 3 35 Identifying Directory Services Requirements 35 Determining Server and Storage Requirements 36 Choosing a Home Folder Structure 37 Devising a Home Folder Distribution Strategy 38 Identifying Groups 38 Determining Administrator Requirements Chapter 3 41 Getting Started with Workgroup Manager 41 Configuring the Administrator’s Computer and Account 41 Setting Up an Administrator Computer 42 Creating a Domain Administrator Account 42 Using Workgroup Manager 42 Using Mac OS X Server v10.5 to Administer Earlier Versions of Mac OS X 43 Connecting and Authenticating to Directory Domains in Workgroup Manager 44 Major Workgroup Manager Tasks 45 Modifying Workgroup Manager Preferences 46 Finding and Listing Accounts 46 Working with Account Lists in Workgroup Manager 46 Listing Accounts in the Local Directory Domain 47 Listing Accounts in Search Policy Directory Domains 48 Listing Accounts in Available Directory Domains 48 Refreshing Account Lists 48 Finding Specific Accounts in a List 49 Using Advanced Search 50 Sorting Users and Groups 50 Shortcuts for Working with Accounts 50 Using Presets 51 Editing Multiple Accounts Simultaneously 53 Importing and Exporting Account Information Chapter 4 55 Setting Up User Accounts 55 About User Accounts 55 Where User Accounts Are Stored 56 Predefined User Accounts 57 Administering User Accounts 57 Creating User Accounts 58 Editing User Account Information 59 Working with Read-Only User Accounts 59 Working with Guest Users 60 Working with Windows User Accounts 60 Deleting a User Account 60 Disabling a User Account 4 Contents 61 Working with Presets 61 Creating a Preset for User Accounts 62 Using Presets to Create Accounts 62 Renaming Presets 62 Editing Presets 63 Deleting a Preset 63 Working with Basic Settings 63 Modifying User Names 64 Modifying Short Names 65 Choosing Stable Short Names 66 Avoiding Duplicate Names 67 Modifying User IDs 68 Assigning a Password to a User 68 Assigning Administrator Privileges for a Server 69 Choosing a User’s Login Picture 70 Working with Privileges 70 Removing Administrative Privileges from a User 70 Giving a User Limited Administrative Capabilities 72 Giving a User Full Administrative Capabilities 72 Working with Advanced Settings 72 Enabling a User’s Calendar 73 Allowing a User to Log In to More Than One Computer At a Time 73 Choosing a Default Shell 74 Choosing a Password Type and Setting Password Options 75 Creating a Master List of Keywords 75 Applying Keywords to User Accounts 76 Editing Comments 77 Working with Group Settings 77 Choosing a User’s Primary Group 78 Reviewing a User’s Group Memberships 78 Adding a User to a Group 79 Removing a User from a Group 79 Working with Home Settings 80 Working with Mail Settings 80 Enabling Mail Service Account Options 81 Disabling a User’s Mail Service 81 Forwarding a User’s Mail 81 Working with Print Quota Settings 82 Enabling a User’s Access to All Available Print Queues 82 Enabling a User’s Access to Specific Print Queues 83 Removing a Print Quota For a Queue Contents 5 83 Resetting a User’s Print Quota 84 Disabling a User’s Access to Print Queues That Enforce Quotas 84 Working with Info Settings 85 Working with Windows Settings 85 Changing a Windows User’s Profile Location 86 Changing a Windows User’s Login Script Location 87 Changing a Windows User’s Home Folder Drive Letter 87 Changing a Windows User’s Home Folder Location 87 Working with GUIDs 87 Viewing GUIDs Chapter 5 89 Setting Up Group Accounts 89 About Group Accounts 89 How Group Accounts Track Membership 90 Where Group Accounts Are Stored 90 Predefined Group Accounts 91 Administering Group Accounts 91 Creating Group Accounts 92 Creating a Preset for Group Accounts 92 Editing Group Account Information 93 Creating Hierarchical Groups 94 Upgrading Legacy Groups 94 Working with Read-Only Groups 95 Deleting a Group 95 Working with Basic Settings for Groups 95 Naming a Group 96 Defining a Group ID 97 Choosing a Group’s Login Picture 98 Enabling a Group’s Web Services 99 Working with Member Settings for Groups 99 Adding Users or Groups to a Group 100 Removing Group Members 100 Working with Group Folder Settings 101 Specifying No Group Folder 101 Creating a Group Folder 103 Designating a Group Folder for Use by Multiple Groups Chapter 6 105 Setting Up Computers and Computer Groups 105 About Computer Accounts 106 Creating Computer Accounts 107 Working with Guest Computers 107 Working with Windows Computers 6 Contents 108 About Computer Groups 108 Differences Between Computer Groups and Computer Lists 108 Administering Computer Groups 108 Creating a Computer Group 109 Creating a Preset for Computer Groups 110 Using a Computer Group Preset 111 Adding Computers or Computer Groups to a Computer Group 111 Removing Computers and Computer Groups from a Computer Group 112 Deleting a Computer Group 112 Upgrading Computer Lists to Computer Groups Chapter 7 113 Setting Up Home Folders 113 About Home Folders 114 Hosting Home Folders for Mac OS X Clients 114 Hosting Home Folders for Other Clients 115 Distributing Home Folders Across Multiple Servers 116 Administering Share Points 116 Setting Up a Share Point 117 Setting Up an Automountable AFP Share Point for Home Folders 118 Setting Up an Automountable NFS Share Point for Home Folders 119 Setting Up an SMB Share Point 121 Administering Home Folders 121 Specifying No Home Folder 122 Creating a Home Folder for a Local User 123 Creating a Network Home Folder 124 Creating a Custom Location for Home Folders 127 Setting Up a Home Folder for a Windows User 129 Setting Disk Quotas 130 Setting Disk Quotas for Windows Users to Avoid Data Loss 130 Using Presets to Choose Default Home Folders 130 Moving Home Folders 130 Deleting Home Folders Chapter 8 131 Managing Portable Computers 131 About Mobile Accounts 132 About Portable Home Directories 133 Logging In to Mobile Accounts 134 Resolving Sync Conflicts 134 About External Accounts 135 Logging In to External Accounts 136 Considerations and Strategies for Deploying Mobile Accounts 136 Advantages of Using Mobile Accounts Contents 7 137 Considerations for Using Mobile Accounts 139 Strategies for Syncing Content 140 Setting Up Mobile Accounts for Use on Portable Computers 140 Configuring Portable Computers 141 Managing Mobile Clients Without Using Mobile Accounts 141 Unknown Mac OS X Portable Computers 142 Using Mac OS X Portable Computers with One Primary Local User 142 Using Mac OS X Portable Computers with Multiple Users 144 Securing Mobile Clients 144 Optimizing the File Server for Mobile Accounts Chapter 9 147 Client Management Overview 148 Using Network-Visible Resources 149 Customizing the User Experience 149 The Power of Preferences 150 Designing the Login Experience 151 Choosing a Workgroup 152 Working with Synced Homes 152 Improving Workflow Chapter