Is there a way, on User enrolled devices, to take away admin privileges to be as close to a Pre-Stage enrollment as possible?
Just starting to integrate Jamf in with our creative Team , they use Adobe with a lot of plug-ins and file transfer services, I sent out one pre-stage enrolled device and got alot of backlash in blocking the users workflow.
That being said, I want to be able to test with a user that I can work closer with but is User enrolled so the circumstances are a little different.
Let me know any suggestions , Thanks
User Initiated Enrollment - How do you take away Local Admin Permissions?
Best answer by Tribruin
So, want to understand what you mean by "User Initiated" enrollment because you are mentioning Prestage.
The Prestage is used for Automated Enrollment only. User Initiated Enrollment is when a user takes an already setup comptuer, goes to a web page (https://company.jamfcloud.com/enroll) and logs in to enroll.
If you are usign a PreStage, you can create Administrator account in your PreStage before the user is created/logs in. Please be aware that Jamf will be moving the PreStage created admin to a LAPS account in early 2024 and you will not be able set the password anymore.
If you are using UIE, you can create a policy to create an admin account on the computer and specify the password. Then you run a policy to demote the user. Seach in Jamf Admin for script to demote the logged in user.
You can also look at tools such as SAP Privileges to manage whether the user is an admin or standard account.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
