Sorry if I’m asking stupid questions, I am fairly new to system administration and this is my first time working with Jamf.
I am setting up my computers with a local admin account and then we create a local standard account for the user. After that we enroll the computer in Jamf and connect the computer to the user in Jamf via Cloud Identity Providers were I have set up Azure AD. I need to restrict the user from access lots of the system setting , but I need the admin account to be able to access these setting. I have a configuration profile set up to restrict the system setting however if I set it at the user level it doesn’t lock these down for any user no matter what I set under scope. If I set it at the computer level it is locking it down for all users. I also have a lot of Restricted Software under the Restricted Software section some of which the admin my need to access, I have not tried changing the setting in there yet but I expect it will behave the same way.
