Has anyone else experienced an issue with a kerberos ticket being granted to a user when they complete the admin elevation dialog?
In our school environment sometimes a student needs to complete an action that requires admin rights. Normally the teacher or support tech will enter their credentials in the prompt, without having to perform a full log-on to complete the action.
Turns out that at this point a ticket is granted for their credentials, which might be allowing the install of an app, or opening up a pref pane.
The problem with this is that we use single sign-on for O365, and the granting of the ticket means that the student then receives the email of the teacher or tech support.
Apple seem to think this is 'by design' and our problem because we use directory and not local accounts. Am I mad in thinking that granting a kerberos ticket for the admin elevation prompt is massive security risk? Managing 3500 macs and having to implement local accounts is going to be a massive nightmare.
