I have machines that are managed by AD, and I want users to be able to log in to the login window of Windows, but authenticate off of OD. I would use pGina, however I need to have certain users in certain groups, like Debuggers, Power Users, etc., and because of the lab environment I’m managing, I can’t just put these users in local machine groups in a PDC type setup, all the while maintaining my ability to push group policies through AD to the machine.
They need to be in OD as well because I need to have a replica structure that extends to many sites that do not have the greatest network connection. For several reasons we have chosen OD as our distributed and replicated directory structure for our ~70 sites. The sites that are network-stability-deprived do not have PCs that need user authentication in that matter but they do need reliable OD authentication.
Comments are closed