Skip to main content
Solved

Migrating to Kerberos Extension

  • March 4, 2020
  • 1 reply
  • 14 views

fraserhess
Forum|alt.badge.img+6

We wish to migrate to macOS Catalina and the Kerberos SSO Extension. We have previously used AD binding. As part of manually migrating a computer, we put it in a static group called "Unbound". This group is scoped with configuration profiles for Kerberos SSO and is excluded from profiles that bind to AD.

My question is about new computers coming into the environment. Is there a way to automatically put new computers in this group prior to enrollment? I don't see anything about group membership in PreStage enrollments. (I also have about 40 Macs coming onboard from an M&A where there's no DEP.)

As I type I wonder if it would be better to put the existing computers in a static group and reverse my logic on the profiles.

But any ideas are welcome. Thanks.

(Running Jamf Pro 10.15.1 on-prem with a 10.19 upgrade scheduled this week.)

Best answer by walts_9

You could use a smart group that pulls machines enrolled after a certain date and change your binding to happen after enrollment then exclude the smart group. Not sure if that fits your workflow.

1 reply

Forum|alt.badge.img+7
  • Contributor
  • Answer
  • April 27, 2020

You could use a smart group that pulls machines enrolled after a certain date and change your binding to happen after enrollment then exclude the smart group. Not sure if that fits your workflow.