Skip to content

Active Directory Payload macOS

This payload can be used to join a macOS device to an Active Directory and configure the domain membership options.

All settings in the Domain group are mandatory.

Setting Description
Domain Name The Active Directory domain to join, as a fully qualified domain name (FQDN).
User Name The user name of the account used to join the domain, as a user principal name, for example user@example.com.
Password The password of the account used to join the domain.
AD Organizational Unit The organizational unit (OU) where the computer object is added, as a distinguished name, for example OU=MACOU,DC=EXAMPLE,DC=COM.
AD Mount Style The network home protocol to use: afp or smb.

Each optional setting has its own Enable or disable the … key checkbox. The setting is only included in the profile when you select that checkbox, and all the checkboxes are cleared by default.

Setting Description Value Default
AD Create Mobile Account At Login Create a mobile account at login. Boolean False
AD Warn User Before Creating MA Warn the user before a mobile account is created. Boolean False
AD Force Home Local Force a local home directory. Boolean True
AD Use Windows UNC Path Use the UNC path from Active Directory to derive the network home location. Boolean False
AD Allow Multi Domain Auth Allow authentication from any domain in the forest. Boolean True
AD Default User Shell The default user shell, for example /bin/bash. Text
AD Map UID Attribute Map the UID to an attribute. Text
AD Map GID Attribute Map the user GID to an attribute. Text
AD Map GGID Attribute Map the group GID to an attribute. Text
AD Preferred DC Server Prefer this domain server. Text
AD Domain Admin Group List, separated by semicolons ; Allow administration by the specified Active Directory groups. Text
AD Name space Set the primary user account naming convention: domain or forest. List domain
AD Packet Encrypt Packet encryption: allow, disable, require, or ssl. List allow
AD Restrict Dynamic DNS, separated by semicolons ; Restrict Dynamic DNS updates to the specified interfaces, for example en0;en1. Text
AD Trust Change Pass Interval Days How often, in days, the computer trust account password must be changed. 0 disables the change. Up to 5 digits. Number