I've run into a very puzzling issue on our Apple Silicon MacBook Pros. A little background: We have a post-image/refresh workflow in Jamf Pro that does a bunch of things, such as renaming the Mac, binding it to AD, and installing various pieces of software. It has worked for several years now, and has been updated to work with Big Sur. Everything functions as expected on Intel Macs running both macOS Catalina and Big Sur. However, when it the workflow runs on an Apple-Silicon based Mac, the Mac doesn't give admin privileges to an AD group that should have admin on that machine. So, when I log into the machine using my AD credentials, I should be admin, but I am not.
Because I can log in with AD credentials, I know the machine is bound to the domain. If I run /usr/sbin/dsconfigad -show, the group is shown as an allowed Admin group. Running dsmemberutil checkmembership -U USERNAMEHERE -G admin shows that my user is a member of that group. I've tried leaving the machine connected to ethernet for 20-30 minutes, and rebooting, but nothing seems to resolve it.
The weirdest part is that if I run an Intel machine through this workflow, the AD group is recognized, so I'm an admin. I confirmed this on Friday by wiping two M1 MacBook Pros and one Intel MacBook Pro, so they would run through the workflow. I did this several times with each Mac, and every time, the M1's failed, but the Intel worked.
Does anyone know what might be causing this? I've run out of things to try and my google-fu has failed me. Any suggestions would be greatly appreciated. Thanks in advance!
