I am piloting Jamf Connect with Google as our IdP for some students in K-12. (with the hope of also doing staff)
Currently if they forget their password, we need to reset their Google password, and then, as admin reset the local password on their computer.
This requires physically having access to their computers. There's almost no point to have Jamf Connect if a password reset requires local login to finalize.
(Further, after this process, it always requires the "verify" step... I think that's a different issue, but now some students have to type their PWs twice to get in.)
Is this everyone else's experience too? Seems pretty untenable. What would people do with a globally disperse workforce where IT can't physically have access to the machine?)
Would Azure or another IdP handle this better?

