Skip to main content

We have been testing Pre-Stage enrollment on our system and with 10.13.4 just dropping we are now getting a window that pops up after the Jamf user initially logs into AD. It appears to have something to do with us binding to Active Directory and SecureToken.



The message displayed after first login to AD is:



"Enter a SecureToken administrator's name and password to allow this mobile account to log in at startup time."



We can bypass but not sure what future issues that could cause. We have not seen this window before 10.13.4 at all. Is there any fix for this or something new I need to be doing to bypass this extra step?



It appears someone has already opened a ticket with Apple:



https://openradar.appspot.com/38485212



AppleCare Enterprise Support as issue #100466781281



Thanks for any insight,



--Mike

@Johnny.Kim I had a similar issue but after logging in with an AD account without securetoken and enabling FileVault it will automatically assign SecureToken and encrypt the machine. Only other issue is that if you need to give the local admin account SecureToken the mobile account must be an admin account in order to do so. Standard accounts can not give other accounts securetoken


So i wanted to start testing 10.13.5 but for some reason I cant used DEP to enroll in Jamf using a Pre-Stage profile. It just hangs on trying to enroll. I contacted Jamf Support to see what the issue is.



@afarnsworth What OS verions and Jamf version? Also what is your "imaging" process?



The past year has been a great roller coaster ride with Apple and Jamf. It seems every time Apple changes something Jamf has to fix it, but in turn breaking something else, and we seem to be stuck in this circle.



-Peter


@McAwesome How do i import that into Jamf to create a profile to test?


I am seriously on my way to Windows machines in the near future. I am tired of fighting issues. I've worked in a Windows environment for close to 20 years so, yes, "I know what I am getting into". Macs are expensive, have to buy new adapters each time we upgrade (kind of like the iPhones, iPads, etc.) JAMF is expensive, etc. We are a school district and I am positive I can save us money going to Windows.


@McAwesome Or anyone else that could help, how do I create the plist for the configuration profile?


I'm still getting this pop-up, anyone ever find a good way to suppress it?


@brwnbn



Computer level config profile.
Preference domain: com.apple.MCX
Plist contents: {cachedaccounts.askForSecureTokenAuthBypass=true}


@cbrewer Thank you!


Reply