We're testing a way to make it a little faster for users when they come in to get their new Mac's. We setup a staging profile, login with that account, we sign in to self-service with the user who will be getting it, at the prompt to enter local password, we put in the staging password and then run a script that switches the user on the device. We then go in to Jamf and change the user info there. The Mac shows encrypted, filevault 2 is new user and the user has a secure token. We're able to change the password, but when you log back on to jamf connect, it says incorrect password with either the current or staging password. Not sure if there is a way around this.
Enrolling Mac with staging profile
Best answer by honestpuck
You've got far too many moving parts in that system. I'm not surprised it's breaking.
According to your list you are enrolling each machine twice? That's not good. That's bound to break things. Why are you enrolling twice? I assume the second time must be user-initiated.
My thinking is that you have broken the FileVault encryption so that the user has an FV token but with another password on it. I assume you have tried both user names with all the passwords the machine has ever known?
I'm sorry but with all that complexity I have no idea where to start to recommend a possible fix. My advice would be to give up and let the end user enrol from the beginning. Unless you are installing a huge amount of software it's not a long time for them to wait. You're throwing away all the advantages of ADE and Jamf Connect.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
