<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007mRXWdCAOOkta Classic EngineAuthenticationAnswered2022-07-08T20:31:54.000Z2022-07-07T15:44:44.000Z2022-07-08T20:31:54.000Z

SteveB.99087 (digital partners incrporated) asked a question.

Supporting Macs in an AD World

TLDR: Can Okta help Mac users not bound to AD not have to initially login to AD/Okta with a PC first?

 

Here is the long version:

Company with several thousand Windows PC users and around 100 Mac users. I help support the Mac users.

Currently the group that supports Active DIrectory says that any new Mac user must first login and set their initial password for their Active DIrectory Network account via a PC before they can log on to their Mac. The Macs currently use a product called JAMF Connect which syncs their local Mac account password to their Okta password. This also makes the Mac user authenticate against Okta when logging into their Macs. The Macs are not bound to AD and use local accounts, not network accounts.

The issue is that all the Mac users are being issued PC laptops as well a Mac laptop. The only thing most of the PC laptops are being used for is the initial login via AD, set the new password and then they get put in a drawer.

The Mac users need an AD entity associated with their Okta credentials because that how the security guys assign group rights for to apps like Zscaler Service-Now etc.

Since I'm not a Windows/AD guy I was wondering if anyone could offer guidance on how I could avoid all my Mac users also being issued a PC but still having an AD entity without binding?

 

Thanks


This question is closed.
Loading
Supporting Macs in an AD World