Those will function similar to iOS, you will use Configuration Profiles to do that. After a wipe and load reconfiguring one of our devices takes about 20 minutes and the tech only has to log in and click 1 button.Īs far as your Restrictions and System Preferences. Due to this we have a device configuration that is run from selfservice that installs all our software and runs the domain bind policy, its 1 click and runs a script with 25 or so policies and renames the computer before it AD binds. If you put AD binding in prestage it will join the domain with whatever default hostname the Mac has so you will get duplicates. AD Binding can happen automatically, but its best to not run it automatically.
If you disable an account on AD, it may still be able to log in to the Mac depending on the environment. SSO is not configured with AD binding, and you do not have the same account control. AD Binding will allow mobile accounts to log in, but keep in mind it does not function the same as Windows. AD Binding is done with a policy and is by far the most complex thing on your list.