Skip to main content
Question

Need to apply profiles to users but not admins

  • March 20, 2015
  • 8 replies
  • 26 views

Forum|alt.badge.img+2

Hi,

Looking into managing our Macs with profiles, and am wondering is there a way to just apply profiles to Active Directory users and not the admin user on machines?. I want to restricted access to PrefPanes but am finding that once done the restrictions are also applied to the admin user, which doesn't help ;-).

Thanks

8 replies

Forum|alt.badge.img+18
  • Valued Contributor
  • March 20, 2015

If you were an industrious admin, that should matter little to you. With and without Admin rights there are a handful of ways to get all of the preference panes available to you. I am loathe to post it again as Google makes it quite easy to find and has been discussed in JAMFNation several times so I would assume their search engine could help you as well.


Forum|alt.badge.img+2
  • Author
  • New Contributor
  • March 20, 2015

I'm well aware that there are ways to make the pref panes available to admins, but thats not the question I asked. I asked is there a way to apply profiles to standard users and not admins.

I do however thank you (nessts) for your time it took to reply.


Forum|alt.badge.img+7
  • Contributor
  • March 20, 2015

nessts, have a Snickers.


Forum|alt.badge.img+18
  • Valued Contributor
  • March 20, 2015

Oh that was me well fed and not grumpy. I am a bit coarse at times I suppose. I guess I should have included that profiles are machine based or user based. And, as far as I know there is no way to single out some users to be immune to their actions.


Forum|alt.badge.img+10
  • Contributor
  • March 20, 2015

@pburgess A few questions:

Are the users of the computers Directory (LDAP) Users? If yes, Using a User Level Configuration Profile will not effect non-LDAP users.

If answer is no to the above question:
Are you using 10.10? Are the other users Local Admins?


Forum|alt.badge.img+11
  • Valued Contributor
  • March 20, 2015

@pburgess

You could always create an AD Security group for your Admin's and then set the scope of the Configuration profile to exclude members of that AD Group. In our case we wanted to do something similar to only allow users of a specific AD Security group access to write to external drives. We created two config profiles one with permissions we wanted for all users but excluded the Admin AD Security group, and another we wanted to apply to only members of the AD Security group and limited to just that group.

Here is a quick screen grab of how our profiles look.

Hope this helps!


bentoms
Forum|alt.badge.img+35
  • Hall of Fame
  • March 20, 2015

Forum|alt.badge.img+6
  • Contributor
  • March 21, 2015

So holding down the option key when you click login with your admin account, and selecting "Disable Settings" — too troublesome?