“DirectControl does a better job of integrating the Mac experience with Windows than any other solution.”
Jonathan Hassell, SearchWindowsServer.com
“DirectControl offers the simplest and most full-featured Active Directory integration solution for Mac OS X. Because it relies on Active Directory's Group Policy architecture, it functions more seamlessly for managing access ... particularly for systems administrators who are unfamiliar with Mac OS X.”
Ryan Faas, ComputerWorld
Centrify has joined forces with Atempo, Group Logic, LANrev and Parallels to define a suite of solutions that integrate Macs seamlessly with Windows systems.
Live Webinar: Centralized Mac Home Directories on Windows Servers
Take a technical deep dive into how to set up ExtremeZ-IP and Centrify DirectControl to configure DFS-based home directories for Mac users.
Centrify-Apple Webinar
Apple's Joel Rennich explains what IT managers need to know to deploy Macs securely in an Active Directory environment.
Centrify DirectControl enables Active Directory-based authentication and access control for both PowerPC- and Intel-based Mac systems and is the first and most robust solution that enables IT managers to centrally secure and configure Mac systems through Active Directory Group Policy. IT managers can streamline operations and strengthen security by establishing a single point of administration — Active Directory. And end-users gain single sign-on to their Macs through their Active Directory account. To learn more, click one of the following topics:
Strengthen Security
Support for OS X 10.6
Centrify added support for Snow Leopard on the day of its launch. Currently supported platforms:
*Ask your Centrify representative about the Early Access program, or submit a trial request.
Case Study
Atlanta-Journal Constitution Manages 1,000 Macs with Centrify DirectControl
Video Chalktalks
Centrify's David McNeely describes our industry-leading Active Directory integration for Mac OS X.
DirectControl enables you to strengthen security and enhance IT efficiency in the following ways.
Enhance IT Efficiency
“Having had the opportunity to work with both the existing set of Group Policies and to see a preview version of the ... expanded set, I was amazed at Centrify's success. The experience of managing Macs was exactly the same as managing Windows computers using Group Policies.”
Ryan Faas, ComputerWorld
Video Chalktalk
Learn about the architecture and features of Centrify's Group Policy solution for Mac OS X.
Centrify DirectControl is the first and most robust solution that enables IT manager to centrally secure and configure Mac systems through Active Directory Group Policy. Because Mac systems are used primarily as workstations, Centrify has enriched its existing DirectControl for Mac OS solution with a set of policies that have been tailored to the needs of IT managers who are responsible for the security and configuration of these systems. Using the same Active Directory tools they use today for Windows systems, IT managers can set security and configuration policies for Mac systems without needing deep platform-specific knowledge.
With DirectControl you can deploy Group Policies to remote Mac systems using the native Active Directory Group Policy tools. DirectControl already comes with more out-of-the-box policies than any other solution, and DirectControl for Mac OS enriches the base set with additional workstation-related security and configuration policies.
Group Policy support is built into the core DirectControl for Mac OS product; there is no additional software to license, install or configure. See Group Policy for UNIX, Linux and Mac for a general overview of how Group Policies work on non-Windows systems.
Summary of Major Computer Policies
| Category | Example Policies |
| Security |
|
| Sharing Services |
|
| Network |
|
| Firewall Settings |
|
| Internet Sharing |
|
| Accounts |
|
| Energy Saver Settings |
|
| Software Update Settings |
|
Summary of Major User Policies
| Category | Example Policies |
| Application Access |
|
| Desktop & Screen Saver |
|
| Dock Settings |
|
| Media Access Controls |
|
| Mobility Sync Settings |
|
| Security |
|
| Software Updates |
|
| System Preference Settings |
|
“We're thrilled that Centrify has taken advantage of the interoperability of Mac OS X to deliver a two-factor smart card authentication solution.”
Ron Okamoto
Vice President of Worldwide Developer Relations, Apple Computer
Video Chalktalks
View these videos for a deeper look into the features and architecture of Centrify's smart card solution.
DirectControl provides broad support for smart card login to Active Directory on Mac OS X supporting CAC, PIV and .NET smart cards. No special user configuration is required on the local system because all authentication and access control data is stored in Microsoft Active Directory. DirectControl supports both online and offline login with smart cards. This would enable an organization to, for example, require users logging on to a Macintosh on an airplane to authenticate using their smart card.
To streamline deployment of smart card-protected systems, DirectControl automates the configuration of the system to support smart card login as well as to ensure that the system trusts the root certificate authorities that are trusted by Active Directory when a Macintosh joins the domain. Active Directory enforces smart card access to Windows systems through the Account option "Smart card is required for interactive logon" policy. DirectControl enforces this policy on Mac OS X systems as well, giving you the ability to enforce smart card access consistently across your organization.
DirectControl also provides Group Policies to enable centralized management of smart card login. These Group Policies can be used to require a Macintosh system to go into screen lock or to force a logout when the smart card is removed from the reader during a session. This policy enforcement on Mac OS X systems enables organizations to easily enable the secured usage of Mac systems within their Windows environments leveraging the same tools, procedures and policies that they are already familiar with today.
The Centrify DirectControl for Mac OS X installation program, provided in universal binary format, makes it easy to deploy DirectControl on individual systems or across the enterprise. On individual systems, a graphic, interactive installation program walks users through the setup. System administrators can also extract the package file for use with Apple Remote Desktop; see Using Apple Remote Desktop to Deploy Centrify DirectControl on the Centrify web site for instructions. The installation package can also be distributed using third-party systems management solutions such LanREV.
In many organizations, Mac OS X workstations can be treated just like Windows workstations for access control purposes, permitting anyone with an Active Directory account to log in once the Mac has joined the domain. For those organizations, DirectControl's workstation mode streamlines installation using the same methodology to add a Mac workstation to an Active Directory domain as that used to add Windows workstations. The interactive installation program offers users the option to add the Mac in workstation mode. Remote installations can specify workstation mode through command-line parameters.
Macs operating in workstation mode have almost identical features to Macs operating in standard DirectControl mode. For example, end-users have transparent access to local or network home directories, and they enjoy the same single sign-on benefits to other Active Directory integrated services and applications. Administrators can also use Group Policy to remotely manage security and configuration settings on DirectControl-managed Macs in workstation mode.
A major advantage of workstation mode is that the installation process has been streamlined. You do not need to install the Centrify Administrator's Console first. You simply install DirectControl on a Mac and it is automatically joined to Active Directory and appears as a computer object in Active Directory Users and Computers. During workstation installation, Macs are not added to a DirectControl Zone, but if you want to use DirectControl's unique Zone-based access controls to limit access to Macs to a select set of users or groups, it it is easy enough to install the Centrify Administrator Console and add those Macs to a Zone. You can have a mixture of Macs in workstation mode and standard mode in Active Directory, giving you the flexibility to apply tighter access controls to select systems as needed.
Other solutions for integrating Macintoshes with Active Directory offer only limited integration. DirectControl is unique in its approach to providing enterprise-ready features for IT organizations responsible for managing large number of Mac systems.
End-users will be glad to know that DirectControl brings them the following benefits as well: