Skip to main content
Question

Advice on Profile Exclusions

  • June 14, 2016
  • 5 replies
  • 13 views

dstranathan
Forum|alt.badge.img+19

All of my managed Macs have a login window Profile that prevents automatic login. End result: Everyone must authenticate at the OS X login window with AD (or cahched) credentials. Typical IT privacy/secuirty policy etc.

I deployed a new home/remote office Mac for an executive. Other than having a non-AD local account, I didnt give his Mac any special configurations or policies/profiles etc. His Mac is (nearly) configured idential to everyone else.

The executive got home and booted-up his Mac.He requested for me to allow Automatic Login ("my previous Macs let me do it..."). He wants to be able boot right into his user session without being prompted. Yes - this is a secuirty issue etc but that's what he wants and he's the boss so...)

I went back to the JSS and I created an exclusion for the login window Config Profile. The JSS indicates that the Mac no longer has the Profile installed, however, the option to enable Automatic Login is still grayed-out in the System Preference Pane (even though he is a local admin).

This is my first time managing a remote "special case" system with JAMF, so I'm still figuring out these types of logistics etc.

Questions:

Why is this particular Mac still "holding on" to the original login window settings even though I excluded his Mac later and the profile is no longer present on said Mac?

What do I need to do to make sure this particluar Mac will allow Automatic Login again?

5 replies

davidacland
Forum|alt.badge.img+18
  • Valued Contributor
  • 1811 replies
  • June 14, 2016

Does the Mac have FileVault enabled? You can't switch on auto-login if FV is turned on.


dstranathan
Forum|alt.badge.img+19
  • Author
  • Valued Contributor
  • 569 replies
  • June 14, 2016

Good catch! No, the Mac in question does not have FDE enabled.

Worth mentioning that I am able to reproduce this exact behavior with a test Mac here in IT.

If I retract/kill the login window profile (via an Exclusion) the payload settings for Automatic Login remain, and I cant access the drop-down menu (its grayed-out).

Profile is definetley removed. No longer shows up in the JSS or on the device via the Profile Pane GUI or the /usr/bin/profiles -P command.


davidacland
Forum|alt.badge.img+18
  • Valued Contributor
  • 1811 replies
  • June 14, 2016

There were some changes around that in Yosemite. What does a cleanly installed Mac look like that hasn't been enrolled with Casper?

You may need to disable the "Require password to wake from sleep or screensaver" setting as well.


dstranathan
Forum|alt.badge.img+19
  • Author
  • Valued Contributor
  • 569 replies
  • June 14, 2016

My IT test Mac is a "clean" image of 10.11.4 (Casper Imaging and AutoDMG)


dstranathan
Forum|alt.badge.img+19
  • Author
  • Valued Contributor
  • 569 replies
  • June 14, 2016

Bingo.

Removing the Security & Privacy Configuration Profile did the trick on my IT test Mac. Ill push it to my executive's home office Mac next and have him confirm.

I should have guessed this might be the issue since we have seen so many issues related to these two specific Profiles in recent months (and Im still running 9.81 too, by the way).

Thanks, David.