On Apr 30, 2005, at 9:24 AM, Michael Bumbalough wrote:
The another is to run two directories, AD for authentication and OD
for
WGM. This would necessitate configuring the workstations to
authenticate
against both of directories. This method also has some quirks, but
nothing is perfect.
This is what I've done a few times for customers. You auth the Macs
against the AD but you have them get management info at a group or
computer level from an OD server. It works great once you get it set up.
We have an OD-AD Integration paper on the site.
I'm not sure what "dinging" they are worried the Macs are going to do
to the server. With the AD plugin the DCs will hardly know it's not
just another Windows PC. They will authenticate with LDAP and
Kerberos, just like anything else. The only strange bit is binding
which is done with LDAP.