Hello All,
In an effort to lock down our Macs with the goal of removing local admins, we've created a Configuration Profile applying to machines which set various Restrictions. This includes what is accessible for users in System Preferences, Applications, functionality, etc.
We also are using Admin By Request to allow users to request elevation for their Account Type to Admin to facilitate installs, updates, etc.
However, with the way the Configuration Profile is applied, even when users elevate to Admin, the Configuration Profile with restrictions still applies.
Is there a better way to lock down functionality of these machines so elevated Admins aren't bound by the restrictions? Or, is there a way to apply the Configuration Profile at a user level for only Standard account - so Admins bypass it?
Thank you for an assistance