Active Directory Settings

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
SettingDescription

Organizational Unit

The Organizational Unit (OU) where the joining computer object is added.

User Experience

Create Mobile Account at login

Select this option to create a mobile account. When this option is selected, the user's data is stored locally and they are automatically logged into a mobile account.

Default: false

Require confirmation before creating Mobile Account

Sends a confirmation message to the end user.

Default: false

Bypass the secure token Authentication prompt when creating a Mobile Account

Bypasses the "Secure Token Authentication" prompt.

Default: false

Note:

Enabling this option may prevent Mobile Accounts from being able to unlock FileVault. This is available on macOS 10.13.5 or later.

Force local home directory on Startup disk

Forces the local Home directory to be created on the Startup disk.

Default: false

Use UNC path from Active Directory to derive network home location

Select to determine the UNC specified in the Active Directory when mounting the network home.

Default: false

Mount Style

Choose either the AFP or SMB protocols.

Default: AFP

Default User Shell

Specify the default shell for the user after logging into the computer.

Default: /bin/bash

Mappings

Select the Mappings tab to specify an attribute to be used for equivalent acronym (GID). By default, these are derived from the domain server.

Administrative

Preferred Domain Server

Enter the name of the domain server to use for authentication.

Allow authentication from any domain in the forest

Allow any domain in the forest to authenticate.

Default: true

Allow Administration

All members of these groups will have Administrator privileges on this computer.

Namespace

Select the primary account naming convention based on forest or domain.

Default: domain

Packet Signing

Choose how to ensure data is secure.

Default: allow

Packet Encryption

Choose to encrypt data.

Default: allow

Restrict DDNS

Restrict Dynamic DNS updates to the specified interfaces (for example: en0 and en1).

Password trust interval

Set to determine how often the computer trust is updated.

Default: 14