Max OSX 10 on Large Windows Domain

Max OSX 10 on Large Windows Domain

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Max OSX 10 on Large Windows Domain RollNpc 09-13-2006
Posted by =?Utf-8?B?Um9sbE5wYw==?= on September 13, 2006, 10:23 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Can anyone please point me to a resource that would explain the security
risks to placing Mac's on a Windows domain. I am trying to find how/if group
policy is/isn't applied and other security problems that can arise in a mixed
environment.

Thanks.
--



Posted by Lanwench [MVP - Exchange] on September 13, 2006, 10:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Can anyone please point me to a resource that would explain the
> security risks to placing Mac's on a Windows domain. I am trying to
> find how/if group policy is/isn't applied and other security problems
> that can arise in a mixed environment.
>
> Thanks.

Security? Well, I don't know that I'd be worried about *security* risks in
having Macs and Windows in the same domain.
Group policy is irrelevant, because only Win2k/XP will be able to make use
of it, but that isn't really a security issue per se. What are your exact
concerns?




Posted by S. Pidgorny on September 14, 2006, 6:21 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I'd say, Mac in Windows environment can be of an issue if integration will
require relaxed security. Reversible passwords required for early Services
for Macintosh and LM hashes used in early versions of Samba are the
examples.

Typical integration points:

* File and print services - Samba on MacOS - NTLMv2 and Kerberos are
supported although Kerberos config is PITA
* Web services - NTLMv2 is now supported in Firefox, not sure about Safari.
SSL is there to help.
* Mail system: MS Entourage is a native Exchange client, Evolution for MacOS
X also supports Excvhange; OWA is always an option. Those using Notes can
run the client on Windows in VirtualPC.
* PKI - limited capability, virtually no smart card support

Which makes Mac a reasonably secure client. Proper configuration and
assessment required.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-


"Lanwench [MVP - Exchange]"
>> Can anyone please point me to a resource that would explain the
>> security risks to placing Mac's on a Windows domain. I am trying to
>> find how/if group policy is/isn't applied and other security problems
>> that can arise in a mixed environment.
>>
>> Thanks.
>
> Security? Well, I don't know that I'd be worried about *security* risks in
> having Macs and Windows in the same domain.
> Group policy is irrelevant, because only Win2k/XP will be able to make use
> of it, but that isn't really a security issue per se. What are your exact
> concerns?
>
>
>



Posted by Robert Moir on September 14, 2006, 5:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
RollNpc wrote:
> Can anyone please point me to a resource that would explain the
> security risks to placing Mac's on a Windows domain. I am trying to
> find how/if group policy is/isn't applied and other security problems
> that can arise in a mixed environment.

Group Policies are not applied to Mac clients, as Lanwench noted.

The mac clients are quite configurable however, with various tools such as
the Apple Remote Desktop Tool, and if you have enough OS X clients to
justify it you can add a Mac server to your network, integrate it into AD,
and use this to centrally manage OSX client configuration and manage user
configuration from the Windows server as you do now.


--
--
Rob Moir, Microsoft MVP for Security
Blog Site - http://www.robertmoir.com
Virtual PC 2004 FAQ -
http://www.robertmoir.co.uk/win/VirtualPC2004FAQ.html



Posted by Joe Richards [MVP] on September 17, 2006, 6:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Look at the Centrify product suite as I believe they support MACs now.
That will give you good kerberos based secure logon and group policy
support.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


RollNpc wrote:
> Can anyone please point me to a resource that would explain the security
> risks to placing Mac's on a Windows domain. I am trying to find how/if group
> policy is/isn't applied and other security problems that can arise in a mixed
> environment.
>
> Thanks.

Similar ThreadsPosted
Problem Signing Large MSI file January 24, 2008, 10:03 am
In windows domain,if 'domain user' group has been remove from the May 19, 2006, 4:07 am
Microsoft Folder with large number (486,692) of files July 23, 2008, 8:34 am
domaine vergabe free de domains domain de eu domain name registrieren de be domain July 28, 2008, 4:14 pm
Windows cannot connect to the domain December 29, 2005, 8:14 pm
Can't login to Windows domain January 12, 2008, 6:58 pm
DMZs & Windows Domain Questions March 1, 2006, 10:57 pm
domain tree view in windows explorer December 4, 2006, 10:27 am
Find SID for the Windows 2000 domain user remotly August 8, 2007, 9:46 pm
Domain Isolation and non-windows IPSec capable systems September 5, 2007, 5:56 am

The site map in XML format XML site map

Contact Us | Privacy Policy