By and large all users get admin access to our Macs when the device is deployed to them. I am trying to sort out a way to give our IT staff admin access without having to use JAMF shenanigans whenever they need to do something with a Mac. We have a Mac_Workstations_Administrators group that has admin access in directory utility that works fine for the GUI. I am wondering if that same group can be given SUDO Access for CLI stuff. Anyone have any musings in this area they could share?
If I can get sudo sorted out I plan on trying to tackle SSH access the same way. Giving Mac_Workstations_Administrators SSH access and hopefully that is inherited by the users in the group. One step at a time :)
In out environment our Macs are domain bound and we use mobile accounts, this will not change anytime soon as its a security policy.
