Skip to main content
Question

How to give admin access to only one user on multiple computers?

  • August 19, 2026
  • 7 replies
  • 54 views

Forum|alt.badge.img+4

I often have different research groups that need to have admin access on their computers due to the type of work and research they are doing, but currently I don’t have a method to give them this access in the way they would like. Additionally, these research computers are shared between the primary researcher that can have admin access, and additional researches that cannot be given admin access.

  1. I use Jamf Connect with Entra SSO.
  2. Pre-stage enrollment creates all new users as standard users.
    1. When we use a command or trigger to elevate someone to Admin, this reverts to standard at their next login.
  3. Using Self-Service+, users can select temp admin access when they need it, but applying this to device means all users on the device have access, even those that shouldn’t, and applying it to a user makes it available to that user on any device, not just the device they need it on.

I don’t know if there’s any other setting, configuration, or options I could use that would make this function the way I want to. If this requires a change that might negatively impact my entire fleet or interrupt my fleet of users, I wouldn’t be able to make it. I am hoping for some direct policy or configuration that might help.

Any ideas?

7 replies

st02264
Forum|alt.badge.img+1
  • New Contributor
  • August 19, 2026

Why not creating a smart group throw those computers in it. 
then create a CP with LocalAdmin account and push it in the smart group
then you will have one universal admin account and they can use on their computers


thebrucecarter
Forum|alt.badge.img+16

Why do they even need admin access?  A lot of our researchers THINK they need admin access, or they WANT admin access, but when pressed about for what specific tasks they need it, they are often at a loss...


yugandhar
Forum|alt.badge.img+1
  • New Contributor
  • August 20, 2026

I often have different research groups that need to have admin access on their computers due to the type of work and research they are doing, but currently I don’t have a method to give them this access in the way they would like. Additionally, these research computers are shared between the primary researcher that can have admin access, and additional researches that cannot be given admin access.

  1. I use Jamf Connect with Entra SSO.
  2. Pre-stage enrollment creates all new users as standard users.
    1. When we use a command or trigger to elevate someone to Admin, this reverts to standard at their next login.
  3. Using Self-Service+, users can select temp admin access when they need it, but applying this to device means all users on the device have access, even those that shouldn’t, and applying it to a user makes it available to that user on any device, not just the device they need it on.

I don’t know if there’s any other setting, configuration, or options I could use that would make this function the way I want to. If this requires a change that might negatively impact my entire fleet or interrupt my fleet of users, I wouldn’t be able to make it. I am hoping for some direct policy or configuration that might help.

Any ideas?

Hello Phinull,

 

With Jamf Connect and Entra you can assign some users when they login they will become as Admin users in that machine. 

For using Jamf connect we will register an app in Entra there we will create Roles as Admin and standard. 

In Enterprise App for Jamf connect under users and Groups add the users and Set the role to Admin for your researchers. 

So when ever the research user login, they will become Admins. 


Forum|alt.badge.img+4
  • Author
  • Contributor
  • August 20, 2026

I often have different research groups that need to have admin access on their computers due to the type of work and research they are doing, but currently I don’t have a method to give them this access in the way they would like. Additionally, these research computers are shared between the primary researcher that can have admin access, and additional researches that cannot be given admin access.

  1. I use Jamf Connect with Entra SSO.
  2. Pre-stage enrollment creates all new users as standard users.
    1. When we use a command or trigger to elevate someone to Admin, this reverts to standard at their next login.
  3. Using Self-Service+, users can select temp admin access when they need it, but applying this to device means all users on the device have access, even those that shouldn’t, and applying it to a user makes it available to that user on any device, not just the device they need it on.

I don’t know if there’s any other setting, configuration, or options I could use that would make this function the way I want to. If this requires a change that might negatively impact my entire fleet or interrupt my fleet of users, I wouldn’t be able to make it. I am hoping for some direct policy or configuration that might help.

Any ideas?

Hello Phinull,

 

With Jamf Connect and Entra you can assign some users when they login they will become as Admin users in that machine. 

For using Jamf connect we will register an app in Entra there we will create Roles as Admin and standard. 

In Enterprise App for Jamf connect under users and Groups add the users and Set the role to Admin for your researchers. 

So when ever the research user login, they will become Admins. 



Unfortunately, that has the added problem of giving them admin access on any computer they use and not just those assigned for their research.


Forum|alt.badge.img+4
  • Author
  • Contributor
  • August 20, 2026

Why do they even need admin access?  A lot of our researchers THINK they need admin access, or they WANT admin access, but when pressed about for what specific tasks they need it, they are often at a loss...

 

While the security manager and myself both agree with you, we’re not in a position to give flat denial in these circumstances and instead need to work towards solutions.


Forum|alt.badge.img+4
  • Author
  • Contributor
  • August 20, 2026

Why do they even need admin access?  A lot of our researchers THINK they need admin access, or they WANT admin access, but when pressed about for what specific tasks they need it, they are often at a loss...

 

While the security manager and myself both agree with you, we’re not in a position to give flat denial in these circumstances and instead need to work towards solutions.

Why not creating a smart group throw those computers in it. 
then create a CP with LocalAdmin account and push it in the smart group
then you will have one universal admin account and they can use on their computers

 

Local admin accounts don’t have all of the same access to on-premise resources and create a new avenue for potential security problems. They’re also accessible by other users if the password is shared as they don’t require MFA like our standard SSO login through Connect.


thebrucecarter
Forum|alt.badge.img+16

Why do they even need admin access?  A lot of our researchers THINK they need admin access, or they WANT admin access, but when pressed about for what specific tasks they need it, they are often at a loss...

 

While the security manager and myself both agree with you, we’re not in a position to give flat denial in these circumstances and instead need to work towards solutions.

I fully understand and sympathize.