thus far, we've had only one problem in running InstallLion.pkg via self service or by policy: although it does, indeed, update macs from 10.6.8 to 10.7.4, the problem (as some of you have already experienced) is that apple's installer deletes any local, hidden accounts on the mac in question when updating to lion. and, in our case, the local casper mgmt account on each machine is one of those hidden accounts.
this means that once a mac has been updated to 10.7.x via that mechanism, i can no longer run any other capser policies. and that, in turn, means i have to find a way around this issue. my first attempts were to create a firstboot script that puts back the deleted admin account but...
i'm having problems. our script/agent which runs from it's location in /Library/LaunchAgents is failing with permission errors. and this, even though both the script and the agent are owned by root:wheel and set to permissions of 644.
how are you folks dealing with this issue and what specific solutions have you used to solve the problem on your end?
cheers,
david koff
sysadmin, the j. paul getty trust
los angeles