So you want an office of Apple Macs - here's a survival guide
Trevor Pott digs out the tools to keep fanboi workers happy
Apple Macs are ready for the enterprise. Unsurprisingly, they can already be found in organisations of all sizes. The five sigma announcement by CERN of the Higgs boson bordered on an Apple advertisement. IBM has more than 10,000 Macbooks deployed. My own SME clients have heterogeneous networks, some are even Mac only.
With so many organisations deploying so many Macs, we can no longer rely on the psychological crutch that these units are seeing service simply because of the ego or desire of a handful of top brass. My personal experience says that business Mac usage is being driven by employees looking for comfortable and familiar environments; the results of BYOD policies at IBM, Intel, Google and other large organisations would seem to agree. It would seem that when everyday people are given the choice of computer platform, we do not all choose the same thing. Let's review what it takes to make the jump.
Playing nicely with others
A network of any appreciable size has some form of centralised authentication in place. Synchronising local users so everyone can access shared resources isn't feasible; a directory service becomes the logical choice. Coaxing Macs into playing along with directory services has sometimes proven to be a small challenge. Fortunately for sysadmins everywhere, this has changed with recent releases.
For small networks - or Mac-only networks - I see little advantage to using Active Directory to tie your network together. In a Windows-only environment, Group Policy Objects (GPOs) and Preferences (GPPs) give small-network administrators powerful options to control systems on their networks. Their ROI argument is diminished in modern heterogeneous environments.
LDAP-based directories - which share common ancestry with Active Directory - are available from multiple vendors. Virtually every Linux distribution comes with one; Apple's own OS X Server has one as well. For deployments below 25 devices, I prefer using the LDAP server built into Synology DiskStations. Synology's NASes are excellent "small-business server" appliances. Using pGina, legacy Windows systems can be joined to these open LDAP servers.
For predominantly Microsoft deployments, Active Directory is the only sensible choice. Macs don't disappoint; OSX 10.8 (Mountain Lion) "just works" [PDF] with Active Directory. A few simple clicks and you are logged in with domain credentials. If you want more robust Active Directory integration than is provided by OS X itself, Thursby's ADmitMac has a cult following and for good reason.
Taking authentication a step further means adapting Microsoft's Group Policy for the Mac world. Centrify and Quest both make products that extend Microsoft's Group Policy to Apple's operating system. Naturally, whenever discussion turns to pushing GPO-like configs to endpoints, Puppet also deserves a mention; the depth of Puppet's offer surpasses the others mentioned above.
None of this should be taken to suggest that Macs cooperate in a centrally managed environment without their own quirks. Macs don't require you to enter the domain portion of a login, instead iterating through its directory search sequence in a linear fashion. You can specify a domain suffix (firstname.lastname@example.org, for example) or you can log in with just your username and hope that the user isn't replicated in any of the other domains on the trust list. Not a problem for smaller organisations; potentially big headache for larger ones.
Mac OS X Mountain Lion also contains a bug regarding profile naming. If the user email@example.com has been accessing the system, the Mac is disjoined and then rejoined to a new domain and then firstname.lastname@example.org logs in, the Mac will assign email@example.com's profile to firstname.lastname@example.org. This can lead to some truly bizarre behaviour, such as phantom icons in the dock, or system preferences applets crashing when you try to launch them. (Specifically, the "Users & Groups" and "Security & Privacy" applets.) Deleting the offending profile and logging back in resolves the issue.
Macs have robust, reliable software for accessing shared company resources. NFS and SMB shares "just work". Whereas it took fiddling in previous versions to get Macs to play nice with Windows network, Mountain Lion has given me no grief at all using either Windows Servers, my Synology NAS or the Drobo B1200i I have on loan.
The globalSAN iSCSI initiator works like a charm; the Drobo is screamingly fast and fed LUNs for virtualisation and backups quite reliably. I haven't been able to tip any Macs over using any of these common file-server protocols on either IPv4 or IPv6. Mountain Lion also comes with a solid VPN client, sealing the deal on communicating with other systems in most business networks.
Designed for Windows doesn't mean you must use Windows.
What if you have Windows-only applications that Mac users need to use? A lot of legacy software is still Windows-only, and there remain today developers who don't make their software cross-platform. If you must use these applications, don't despair. Solutions to this problem exist.
Virtual Desktop Infrastructure (VDI) is a popular solution to the legacy application problem. For simple applications, straight up RDP will do; Microsoft offers a client with its Office suite. CoRD has proven to be a reliable alternative for those choosing another productivity package. VMware's View is ready for OS X if you need a high-performance centrally delivered desktop.
Client-side virtualisation is also a worthy consideration. Macs don't tend to skimp on the hardware. Both Parallels and VMware's Fusion are capable of delivering fully graphically accelerated Windows environments on your Mac. Everything from CAD software to video games works smoothly in either application. If your needs tend more towards the delivery of a single application, App-V is a great transition technology.
Most software vendors have realised that the days of Windows-only environments are numbered. Nobody wants to be relegated to a legacy software provider that entire companies can't wait to ditch, and so the number of applications being written either native to the Mac or for web delivery is on the rise. Many critical business applications, such as Microsoft Lync, now have Mac clients and this trend isn't looking to reverse any time soon.
Next page: Backups. You do have backups, right?
"A lot of legacy software is still Windows-only, and there remain today developers who don't make their software cross-platform"
The fact that something isn't Windows-only doesn't make it 'legacy', it probably means that there was no sensible business case for making Mac or Linux versions.
I can't much comment on the rest, but I will say that re: Time Machine, it's great until for no obvious reason the bloody thing starts dicking around. I've had people using Lion and Mountain Lion find their systems crash hard due to Time Machine, with no obvious fix in sight (with Apple Support's responses being of the helpful "Have you done a PRAM reset? Have you reinstalled? Have you tried another drive? Because despite Time-Machine-related OS updates it's not possible that it could be our side that's b0rked" variety).
The fact that software distribution to OS X is easier with KACE than with native OS X utilities is pretty bad.
But the big, BIG one for enterprise support that you've glossed over is hardware support. If you buy Apple portables, the best support you'll get on the hardware is collect-and-return with a 1-week turnaround (if you're lucky and you fall within the catchment area) or you can waste someone's time taking it to the Apple Store. Only their much-maligned desktops get on-site service.
The above, for me, are the problems. Some of my users want them, but I make damn sure they understand these issues before I let them buy one, and when they have an (increasingly likely) hardware issue the shine starts to wear off of their iShinies....
Support agreement with Apple?
I'd have thought that the "harder to fix" nature of the more modern Macs made them more challenging in a corporate environment? With my work Dell machine, when the hard drive dies, it's trivial to pop it out and put in another — if the SSD on my Air were to die, I'm not sure there would be a huge amount I could do without Apple's assistance? Having a stack of spare machines may be a workaround, to give time to get the borked machine to Apple, but keeping a stack of hard drives on hand seems easier and cheaper?
(Purely a guess on my part, based on being a Windows user at work, and a Linux/Mac/BSD user at home.)
How about open up a decent Unix command line without having to install cygwin?
I know this has been mentioned already but it really is worth mentioning again that this article misses out on one of the biggest problems with Mac in the enterprise; hardware support (or lack thereof).
I oversee a 100% Windows and Linux environment. 100% with the exception of one director, that is.
Not long ago the Macbook Pro of said director suffered an unknown logic board failure. The quickest solution was to fail over to a spare Macbook Air we had around and without going into the details lets just say the whole transition from Pro to Air, waiting for two weeks for Apple to mend the Pro, and then going from the Air back to the Pro was nothing short of a major pain in the arse... and a complete waste of time.
With our Windows and Linux systems however we have varying levels of ON-SITE hardware support (ranging from 24/7 4-Hour response times for upper management to Five-Days-a-Week Office Hour 4-Hour response times for everyone else, at minimum). Even without said support in place most trivial problems are a breeze to fix with a small cache of spare parts lying around.
Furthermore, for emergencies where even a 4-Hour response time is deemed too slow, non-drive related failures are as easy as pulling out the drive from a dead system, putting it into a functional spare, and updating TPM. Most staff however are comfortable with doing something which doesn't involve their computer during the 4-Hour downtime and with our experience thus far spare parts are always delivered via DHL Express within 30-60 minutes of me putting the phone down (and our vendor lets our own in-house staff do the fixing, though an engineer can also come down for trickier replacement procedures more typical with notebooks).
So... until Apple can come up with similar hardware support; thanks, but no thanks.