12.07.2015 Views

Using Centrify's DirectControl with Mac OS X - Cerberis

Using Centrify's DirectControl with Mac OS X - Cerberis

Using Centrify's DirectControl with Mac OS X - Cerberis

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CENTRIFY WHITE PAPERUSING CENTRIFY’S DIRECTCONTROL WITH MAC <strong>OS</strong> Xand add those <strong>Mac</strong>s to a Zone. You can have a mixture of <strong>Mac</strong>s in workstation mode andstandard mode in Active Directory, giving you the flexibility to apply tighter accesscontrols to select systems as needed.Organizations can view workstation mode as a permanent solution for managing <strong>Mac</strong>scentrally from Active Directory. Or the workstation mode installation may simplyrepresent a way to quickly deploy <strong>DirectControl</strong> and add <strong>Mac</strong>s to Active Directory whiledeferring the implementation of Zone-based access controls to a later date.On UNIX and Linux server systems that have not been centrally managed, Zones are alsofrequently useful for enabling the mapping of multiple UIDs and GIDs that may exist fora single user to that user’s Active Directory account. This issue does not exist on <strong>Mac</strong>sbecause logins and permission-based access to, say, network shares are not managedusing UIDs or GIDs but through Kerberos credentials. When a user logs in to a <strong>Mac</strong>joined to Active Directory in workstation mode, the <strong>DirectControl</strong> Agent automaticallyderives a valid, globally unique UID from the user’s Active Directory SID, which ensuresconsistency on all <strong>Mac</strong> <strong>OS</strong> X systems where the user logs in.<strong>DirectControl</strong>-managed <strong>Mac</strong>s can also be configured to leverage your organization’scentralized Windows home directory servers as specified in the user’s Active Directorynetwork home profile setting. If an Active Directory user has a network home folderdefined in their profile, then the <strong>DirectControl</strong> Agent mounts this network share as theuser’s home directory. If the workstation is a portable system, then the portable homedirectory feature can be used to establish a local home directory that is synchronized tothe user’s network home directory. IT administrators can control these settings for useraccounts using Group Policy. There is also a computer Group Policy that can overridethese settings – for example, to prevent local local home directories on a kiosk machineor to provide roaming profiles for <strong>Mac</strong> users.5 Strong Authentication and Single Sign-on through Smart CardLogin to Active DirectorySmart card-based authentication is a requirement in some industries and is gaining inpopularity in other organizations that, for security and/or compliance reasons, want tomove beyond user authentication based solely on an individual knowing a user name andpassword. <strong>DirectControl</strong> provides broad support for smart card login to Active Directoryon <strong>Mac</strong> <strong>OS</strong> X supporting CAC, PIV and .NET smart cards, enforces Active Directorydefineduser account policies for smart card use, and supplies Group Policies that enableyou to fine-tune smart card settings.© 2006-2008 CENTRIFY CORPORATION. ALL RIGHTS RESERVED. 23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!