Skip to main content
Question

AD bound clients and local admin account with static passwords.

  • January 27, 2020
  • 1 reply
  • 5 views

atomczynski11
Forum|alt.badge.img+18

Looking to make our environment more secure.

We are self hosted and clients are bound to a local/hosted Active Directory.
We rely less and less on AD and at some point will move to other solutions but for now that's where we are.
Our fleet of Macs are enrolled in Automated Enrollment (DEP) and we use Apple School Manager / Apple Business Manager.

We use FileVault for data encryption.
I'm looking for some documentation how to introduce revolving local admin password. Not sure what the requirements for this are and if we need to change our imaging workflow. Right now FV is part of our onboarding process.

1 reply

mark_mahabir
Forum|alt.badge.img+15
  • Jamf Heroes
  • January 28, 2020

Have you had a look at the macOSLAPS or LAPSforMac projects?