Hi Jamf Nation,
I am wondering what the best practice is for managing local admin accounts on corporate MacOS devices. We have over 500 Silicon Macs in our environment and currently configure a local admin via PreStage Enrollment as well as a policy to push our local admin account to a few non-Business Manager devices. We try to avoid typing this password in locally at all cost, but it happens from time to time. When we need to cycle the password, we do not have an easy way to do this today.
I am skeptical this is the best way to manage local accounts and feel like there should be a solution like FileVault where each device has a unique local admin password that is escrowed in Jamf Pro. In doing some google searches, I found reference to something that may be similar for Windows called LAPS.
What is everyone else doing to securely manage local admin accounts?
