Hello all,
First post.
We are configuring our Jamf Cloud Instance for deployment and we have found a few gotchas based on our configuration for the password policy.
In detail we have enabled a configuration policy for a Passcode payload which requires:
Allow simple values (unchecked)
Alphanumeric values (checked)
Minimum Passcode length (8)
Maximum Passcode age (90)
Passcode History (5)
.
.
Computer Level Scope
The issue that we are having is that our local admin account on the MacOS machines enrolled with Jamf will fall on the password configuration scope.
This means that every 90 days we will have to change the password on each computer enrolled in Jamf with a new password that is not 5 of our previous passwords.
So how are you guys handling local admin accounts with Jamf?
Do you guys have a means to get to the computer aside from the regular user account?
Is our password policy to strict?
In general what is your approach in this matter?
Thanks,
Ron