Check the DenyLocal key in your .plist. Seems like it’s set to true.
-R
I didn't initially have DenyLocal in my plist, I added it after this error appeared and set it to false but to no avail.
Using Okta, but this might be applicable.
We recently noticed issues that seem to be caused by a change in the "First user" detection.
By adding our standard users group into the allow secondary logon preference, everyone can now log in.
Haven't had time to sort out why it's happening, but my guess is that we have our management account + another hidden admin created before first user login.
May or may not apply but at a previous company we used Apple Enterprise Connect and if a users Macbook was not connected to our wifi (or via VPN) AEC would throw a login error.
It appears to be linked to a Login window config profile, I removed it and now non admin users can login, I guess it's logical that as JAMF Connect effectively replaces the login window that existing login window config profiles would hit it for six.