Specifications

6 Click Search Policy and choose a search policy.
 Authentication: Shows the search policy used for authentication and most other
administrative data.
 Contacts: Shows the search policy used for contact information in applications such
as Address Book.
7 From the Search pop-up menu, choose “Custom path.”
8 Add directory domains as needed by clicking Add, selecting directories, and clicking
Add again.
9 Change the order of the listed directory domains as needed by dragging them up or
down the list.
10 Remove listed directory domains that you don’t want in the search policy by selecting
them and clicking the Delete (–) button.
11 Conrm the removal by clicking OK, then click Apply.
To add a directory that isn’t listed among the available directories, make sure the
computer has been congured to access the directory. For more information, see:
 Using Advanced Directory Services Settings on page 13 2
 Using Advanced LDAP Service Settings on page 13 3
 Using Advanced Active Directory Service Settings on page 15 8
 Specifying NIS Settings on page 174
 Specifying BSD Conguration File Settings” on page 175
Dening Local Directory Search Policies
Using Directory Utility, you can congure a Mac OS X computers authentication and
contacts search policies to use only the computers local directory.
A search policy that uses only the local directory limits the access that a computer has
to authentication information and other administrative data.
If you restrict a computer’s authentication search policy to use only the local directory,
only users with local accounts can log in.
To have a search policy use only the local directory domain (local directory):
1 Open System Preferences and click Accounts.
2 If the lock icon is locked, unlock it by clicking it and entering the name and password
of an administrator.
3 Click Login Options, then click Join or Edit.
4 Click Open Directory Utility.
5 If the lock icon is locked, unlock it by clicking it and entering the name and password
of an administrator.
13 0 Chapter 8 Advanced Directory Client Settings