12.07.2015 Views

Using Centrify's DirectControl with Mac OS X - Cerberis

Using Centrify's DirectControl with Mac OS X - Cerberis

Using Centrify's DirectControl with Mac OS X - Cerberis

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CENTRIFY WHITE PAPERUSING CENTRIFY’S DIRECTCONTROL WITH MAC <strong>OS</strong> X• Locates the relevant domain controllers based on the Active Directory forest and sitetopology, also known as being site-aware.• Maintains time synchronization <strong>with</strong> Active Directory domain controllers if desired.• Maintains an MIT-based Kerberos environment so that existing Kerberosapplications will work seamlessly <strong>with</strong> Active Directory to provide users <strong>with</strong> singlesign-on access to network resources such as Windows file servers and print queues.• Ensures network security by resetting the password on its machine account at regularintervals according to Active Directory domain policies.• Enables logins using users’ Active Directory credentials. Logging on in this contextmeans not only logging into the <strong>Mac</strong> <strong>OS</strong> X graphic interface, but also connecting tothe <strong>Mac</strong>intosh through a remote SSH or Apple Remote Desktop interface.• Enables authentication <strong>with</strong> smart cards, including PIV, CAC and .Net cards.• Updates a user’s last login time upon Active Directory login to ensure that passwordexpiration policies are being enforced properly.• Stores user credentials and profiles so that users can log on when the computer isdisconnected from the network, which is especially useful for laptop computers<strong>with</strong>out requiring a locally defined mobile user.• Caches responses from Active Directory information queries to reduce the load onthe domain controllers.• Validates that the user has appropriate permissions to log in to the <strong>Mac</strong>intosh systembased on account policies. For example, Active Directory provides a set of accountspecificcontrols enabling the administrator to activate or disable a user’s ActiveDirectory account as well as to control the time of day the user is allowed to log in.• When the <strong>Mac</strong> is a member of a <strong>DirectControl</strong> Zone, validates that the user hasappropriate permissions to log in based on Zone memberships and allowed groupmembership.• Determines a user’s full UNIX-enabled Active Directory group membership(including nested groups) the first time the user logs on.• Supports users managing their Active Directory passwords from <strong>Mac</strong>intosh systemsboth for the ad hoc password change as well as for expired password at login.• Validates privileged account logins centrally from Active Directory when needed<strong>with</strong>out requiring previously defined local administrator accounts.• Dynamically creates home directories locally on the computer for users whoseprofile defines a local home directory path. <strong>DirectControl</strong> also supports seamlesslymounting network-based home directories from Windows servers or AFP servers as© 2006-2008 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. 7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!