Skip to main content
Solved

Upcoming change will enforce LAPS on Prestage admin accounts (important!)

  • January 9, 2024
  • 59 replies
  • 504 views

Show first post

59 replies

Deanna
Forum|alt.badge.img+11
  • Employee
  • February 23, 2024

Hi Deanna,

Right, I saw that response and replied. 

I understand you're trying to paint some nuance here, but the release notes do not have any of that. All the release note message conveys now is "we're doing this. we don't know when, but it's happening". Not "when we do it'll be optional" or anything. Which, brings us right back to ya'll hanging seriously workflow breaking changes over our head, only now we don't know when they'll happen. And worse, because it just lives in the release notes now, that could be seen as a "we gave everyone plenty of notice about this change, so we're doing it next release". 

I thought we all made it pretty clear this must be optional. 

What _should_ happen here is that message gets removed from the release notes, or better, a "reconsidered" note added, and a statement saying that when/if this is re-evaluated Jamf will reach out to admins across their customer base and discuss potential issues/solutions/etc. Or heck, they could even say: "In a future release, the ability to specify or modify a local administrator account password in a PreStage enrollment for computers may be removed from Jamf Pro." (emphasis is mine). 

Does all that make sense? I know time was spent getting all this ready, and we appreciate Jamf backing off on implementation... but now we're just waiting for the other shoe to drop. =(

Thanks. 


The release notes will be updated and I will advise once complete.  Until then, to re-iterate, LAPS is optional and admins will continue to be able to set a static password.  This has not changed from prior conversations/posts.  


Deanna
Forum|alt.badge.img+11
  • Employee
  • February 26, 2024

Hi Deanna,

Right, I saw that response and replied. 

I understand you're trying to paint some nuance here, but the release notes do not have any of that. All the release note message conveys now is "we're doing this. we don't know when, but it's happening". Not "when we do it'll be optional" or anything. Which, brings us right back to ya'll hanging seriously workflow breaking changes over our head, only now we don't know when they'll happen. And worse, because it just lives in the release notes now, that could be seen as a "we gave everyone plenty of notice about this change, so we're doing it next release". 

I thought we all made it pretty clear this must be optional. 

What _should_ happen here is that message gets removed from the release notes, or better, a "reconsidered" note added, and a statement saying that when/if this is re-evaluated Jamf will reach out to admins across their customer base and discuss potential issues/solutions/etc. Or heck, they could even say: "In a future release, the ability to specify or modify a local administrator account password in a PreStage enrollment for computers may be removed from Jamf Pro." (emphasis is mine). 

Does all that make sense? I know time was spent getting all this ready, and we appreciate Jamf backing off on implementation... but now we're just waiting for the other shoe to drop. =(

Thanks. 


The deprecation notice will be removed in 11.4 RC


A-bomb
Forum|alt.badge.img+7
  • Contributor
  • February 26, 2024

The deprecation notice will be removed in 11.4 RC


Thank you, @Deanna.


rstasel
Forum|alt.badge.img+13
  • Author
  • Valued Contributor
  • February 26, 2024

The deprecation notice will be removed in 11.4 RC


Yes, thank you Deanna! 


mark_lynch
Forum|alt.badge.img+5
  • Contributor
  • February 26, 2024

The deprecation notice will be removed in 11.4 RC


Much appreciated!


atomczynski11
Forum|alt.badge.img+18
  • Jamf Heroes
  • February 26, 2024

The deprecation notice will be removed in 11.4 RC


Thank you @Deanna for your help and the update.


dstranathan
Forum|alt.badge.img+19
  • Valued Contributor
  • February 27, 2024

LAPS is not required.  It is optional.  You can continue to create a static password.  We will update the document.  Thank you for the feedback. 


Just a heads-up, @Deanna -  that Jamf document I linked to previously is still incorrect (after 7 days). 

"Functionality to specify the local administrator account for computers in a PreStage enrollment

In a future release, the ability to specify or modify a local administrator account password in a PreStage enrollment for computers will be removed from Jamf Pro.

Once implemented, the local administrator password solution (LAPS) will provide equivalent functionality for securely viewing and modifying macOS account passwords on managed computers. For more information, see the Local Administrator Password Solution for Jamf Pro technical paper."


rstasel
Forum|alt.badge.img+13
  • Author
  • Valued Contributor
  • February 27, 2024

Just a heads-up, @Deanna -  that Jamf document I linked to previously is still incorrect (after 7 days). 

"Functionality to specify the local administrator account for computers in a PreStage enrollment

In a future release, the ability to specify or modify a local administrator account password in a PreStage enrollment for computers will be removed from Jamf Pro.

Once implemented, the local administrator password solution (LAPS) will provide equivalent functionality for securely viewing and modifying macOS account passwords on managed computers. For more information, see the Local Administrator Password Solution for Jamf Pro technical paper."


Hey @dstranathan fwiw, they don't change existing release notes... she mentioned today that the 11.4 release notes will remove the deprecation notice. https://community.jamf.com/t5/jamf-pro/upcoming-change-will-enforce-laps-on-prestage-admin-accounts/m-p/310951/highlight/true#M270126


dstranathan
Forum|alt.badge.img+19
  • Valued Contributor
  • February 27, 2024

Hey @dstranathan fwiw, they don't change existing release notes... she mentioned today that the 11.4 release notes will remove the deprecation notice. https://community.jamf.com/t5/jamf-pro/upcoming-change-will-enforce-laps-on-prestage-admin-accounts/m-p/310951/highlight/true#M270126


Thank you for clarifying.