We are presently using Macbook Airs to Logon to a windows domain. The Macbooks are binded to the domain. We are a corporate environment, and require our users to change their password every 90 days. We run a RDS host server farm of 16 servers. We allow our salesmen and others in the company to use a web version of the RDS host when they are not at the corporate site. A majority of our Macbook users are salesmen. They are never at Corporate. They work from home. When they change their password remotely on the RDS host through the web. Obviously, The macbook doesn't update the Local Profile with their new password. They are left with them using the old password to sign on to their macbook for their domain account. This causes 2 issues: 
1. They have 2 passwords now and when they login. The keychain will ask for a password. Also it will ask for a password for each entity that is in the keychain( Email password, RDS host password, and others). It will keep asking for these every single time they login to the laptop. This will becoming so annoying for the user they will contact the help desk and we will use the 1st aid utility to create a new keychain.
2. Which comes to problem # 2 - With the new keychain we would have to add the login server info for RDS( it is saved in the keychain and also their email information is also in the keychain. They would need to configure their email password as the password would not sync up with their present email password because they never locally sign in to our corporate network.
We have thought about removing the laptop completely from the domain, but the amounts of passwords that a user would need to use to sign in to DFS Active Directory protected Servers and Shares would be to aggravating on a daily basis to work with.
Please Help we just want these macbooks to work with our environment!!! Apple support is no help!!!
			
			1. They have 2 passwords now and when they login. The keychain will ask for a password. Also it will ask for a password for each entity that is in the keychain( Email password, RDS host password, and others). It will keep asking for these every single time they login to the laptop. This will becoming so annoying for the user they will contact the help desk and we will use the 1st aid utility to create a new keychain.
2. Which comes to problem # 2 - With the new keychain we would have to add the login server info for RDS( it is saved in the keychain and also their email information is also in the keychain. They would need to configure their email password as the password would not sync up with their present email password because they never locally sign in to our corporate network.
We have thought about removing the laptop completely from the domain, but the amounts of passwords that a user would need to use to sign in to DFS Active Directory protected Servers and Shares would be to aggravating on a daily basis to work with.
Please Help we just want these macbooks to work with our environment!!! Apple support is no help!!!
 
				