I often have different research groups that need to have admin access on their computers due to the type of work and research they are doing, but currently I don’t have a method to give them this access in the way they would like. Additionally, these research computers are shared between the primary researcher that can have admin access, and additional researches that cannot be given admin access.
- I use Jamf Connect with Entra SSO.
- Pre-stage enrollment creates all new users as standard users.
- When we use a command or trigger to elevate someone to Admin, this reverts to standard at their next login.
- Using Self-Service+, users can select temp admin access when they need it, but applying this to device means all users on the device have access, even those that shouldn’t, and applying it to a user makes it available to that user on any device, not just the device they need it on.
I don’t know if there’s any other setting, configuration, or options I could use that would make this function the way I want to. If this requires a change that might negatively impact my entire fleet or interrupt my fleet of users, I wouldn’t be able to make it. I am hoping for some direct policy or configuration that might help.
Any ideas?
