Mac OS and Azure AD LDAP Authentication

SebC 56 Reputation points
2020-08-10T17:30:36.227+00:00

Another forum that moved from very useful social.microsoft.com to this unfriendly Q&A site, pity!

But whatever.

There was a thread years ago about this:

https://social.msdn.microsoft.com/Forums/en-US/a06c8321-8aab-49c5-b0bc-59d9e84807bd/how-to-configure-ldap-authentication-for-mac-os-and-azure-ad?forum=WindowsAzureAD

Anybody has any info on current situation? (before I waste time to find myself that ie it does not work)

I could join my machines to local AD (which might be the case in the end), but while moving with all Windows machines to AAD/Intune, I would like to do the same with Macs (I am not yet in position to do Intune, as I do not have enough time for testing)
But at least authentication could be from AAD

Thanks

Seb

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,455 questions
{count} votes

11 answers

Sort by: Most helpful
  1. Jon Alfred Smith 541 Reputation points
    2020-08-10T18:37:37.337+00:00

    There is still no native option to join Macs to an Azure AD domain. You could, but should not, use Azure AD Domain Services (not recommend by Microsoft). You could look into Azure Active Directory SSO integration with Jamf Pro
    https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/jamfprosamlconnector-tutorial

    Personally I never liked to join my Macs to on-premises AD. In my wife's and my small Microsoft 365 Business Premium tenant, we use two Macs as our primary machines. They are registered in Azure AD and enrolled in Intune, though. Configuration and configuration policies with conditional access – all of which works very well. In addition to automatic distribution of software.

    2 people found this answer helpful.

  2. SebC 56 Reputation points
    2020-09-11T05:20:48.467+00:00

    If I do not join Mac to local AD then my users could not possibly login to that Mac (few shared machines)

    And how do you enroll Mac in Intune without going the full ASM (Apple School Manager)?
    I have that question opened with zero take up

    I am about to move away (management decision) from Jams, so will not be looking into it again...

    Seb


  3. Thomas Nagels 1 Reputation point
    2020-11-20T09:05:49.507+00:00

    A late reply, but maybe still relevant: I use Jumpcloud to achieve this. They have user /password sync for multiple platforms including the combination Microsoft365 and osx. Have been using the free tier of their product for quite a while now and it seems to work well.

    Thomas

    0 comments No comments

  4. SebC 56 Reputation points
    2020-11-24T20:38:20.317+00:00

    @Thomas Nagels
    Thanks, Jumpcloud free is not enough (only 10)

    @Paul Gately
    Thanks, generic login is not ideal, because that would never allow use of OneDrive app (which is a "must" for me)

    So AD join is still the only option I can see


  5. SebC 56 Reputation points
    2021-04-19T20:21:09.037+00:00

    I need a user to be able to login to Mac machine with they credentials (what is so surprising about it?)

    Users has ONE set of credentials: email & password (AD account synced to AAD)

    User uses the same credentials for OneDrive/Teams/proxy/printing/eStream etc

    I do not see any other option apart from having Mac joined to directory (AD in that case)

    Would love somebody to prove me wrong here!

    How could I select appropriate response as "Answered." when there is nothing answered, but only lots of lose random opinions?

    Windows can be joined to AAD only, user uses the ONLY ONE set of credential they have, and everything works