Jump to content

MacOS Active Directory User and FileVault password out of sync


Div

Recommended Posts

Hello!

we are trying to manage MacOS via Workspace One and currently got a problem with the FileVault and Active Directory user. If we change our password on a windows pc, the user needs to fill in the old password for FileVault and the new one to be able to login. How can we fix this?

Thanks in advance!

Link to comment
Share on other sites

The FileVault password is never going to update itself, it's always going to require user intervention. But you should move away from binding your Macs to AD and instead use the Apple Kerberos Single Sign-on extension. This will allow you to use local accounts, which are synced to AD.  The Kerberos extension would pick up that the passwords don't match and will prompt the user to sync. 

Binding to AD is no longer recommended by Apple. 

  • Like 1
Link to comment
Share on other sites

My user used the single sign-on extension of Apple Kerberos to synchronize the AD password to the local password. However, once the user forgot the local password and AD password of his computer, which caused him to fail to log in to the system. When I logged in with the hidden administrator created by DEP, I could not change the password of the user's local account. The device is not logged in to the Apple ID, is there any other way to help the user reset the password?

Link to comment
Share on other sites

  • 1 month later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...