OS X: Active Directory naming considerations when binding

When binding an OS X client to Active Directory, make sure that the computer names used in the binding process follow these standards.

To ensure that the computer binds as expected when binding with System Preferences, Directory Utility, or dsconfigad, use computer names that:

  • are less than 16 characters in length
  • only contain alphanumeric (A–Z, a–z), numbers (0–9), - (dash) and/or _ (underscore) characters

Entering a longer computer name or invalid characters might cause client binding to Active Directory to not work, or cause Mac OS X to bind to Active Directory with a truncated computer name. 

Although the underscore character is valid in hostnames, it is not a valid component in a DNS domain name. If the Active Directory domain being bound to contains an underscore in the domain name, binding and services will not function as expected.

For more information about the length and character set requirements for use with Active Directory, see this Microsoft article.

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Risks are inherent in the use of the Internet. Contact the vendor for additional information.

Last Modified:
Helpful?

Additional Product Support Information

Start a Discussion

in Apple Support Communities
See all questions on this article See all questions I have asked
United States (English)