10.3.3, AD plugin, granting admin control
So I am using 10.3.3 with the new AD plugin, and am able to authenticate against our AD server. My mac appears in the computers OU. The basic part works.
However, I cannot get AD accounts to have local admin rights on panther. This is currently a showstopper for me, because people need admin rights to their machines. I've added groups, but they are being ignored.
I've been looking for docs and tweaks but have found nothing useful. unfortunately I missed the macosxlabs.org presentation yesterday and it looks as if it'll take a few weeks to be posted.
So, the questions are:
1- will the ad plugin support granting admin rights?
2- is single sign on with windows 2000 servers supported?
3- is kerberos being used at this point? Will I be able to change a windows account password?
All this is working for me using admitmac. I'd rather save the company some money and not deploy that if possible. Thanks for any answers!