Anyone have any ideas on how to change a computer's management account without running recon? I have quickadd packages that have a standing invitation for new / re-enrollments. I use one quickadd for each of our sites and I would rather not have to update them every password rotation, but just one policy.
I'm trying to change/set/create the management account via policy when a machine is imaged and having this trigger on enrollment runs yet another recon - which I'm trying simply eliminate as not necessary during a re-image.
The current method I'm using is:
jamf recon -sshUsername '_hiddenuser' -sshPassword 'initialimagingpassword'
Running recon after just having run recon is ... dumb. Never mind the fact that the command also seems to fail to add the user to com.apple.access_ssh. Again.. .dumb. Its really just got two things to do and it fails at one of them. sigh
