Hacker News new | ask | show | jobs
by solatic 2091 days ago
That's great until you work for a company that bought Macs for everyone for their design and upper-management likes to keep it that way.
1 comments

You can do it on Mac. I wouldn't recommend binding Macs anymore since Apple broke filevault for AD accounts in high Sierra (AD accounts don't get the secure token by default which is needed to unlock the drive)

But since Catalina there's now a great Kerberos SSO plugin that you can push through MDM. Previously this was known as enterprise connect but only available from Apple professional services.