Skip to main content
Solved

Local Users Not Allowed to Log In


nwebster
Forum|alt.badge.img+3

Hi everyone,

I work for a High School and I'm having a hard time figuring out the root of this issue. They authenticate via Google, then type their local password, to get an error message saying  "You are not allowed to log in at this time". 

Though, this is working on a few users of the same groups and all, so the inconsistency is throwing me for a loop. 

When I call for JamfConnectLogin.log, I get: authorizationhosthelper.x86_64[4394:7709] [com.jamf.connect.login:KeychainAdd] Tried to get the login name but couldn't find it.

 

macOS Version: 11.6.0
JamfConnect 2.6

 

Anyone have any ideas? Would be much appreciated.

Best answer by rabbitt

Look for a configuration profile applied to the machine with a Login Window payload.  Under Access, there is an option to deny login for any local users:

 This may have been applied to the machine if it was once bound to an on-premises Active Directory server.  Turn the first option - "Local-only users may log in" - back on OR unscope the config profile from target machines.

View original
Did this topic help you find an answer to your question?

2 replies

rabbitt
Forum|alt.badge.img+17
  • Valued Contributor
  • 72 replies
  • Answer
  • December 14, 2021

Look for a configuration profile applied to the machine with a Login Window payload.  Under Access, there is an option to deny login for any local users:

 This may have been applied to the machine if it was once bound to an on-premises Active Directory server.  Turn the first option - "Local-only users may log in" - back on OR unscope the config profile from target machines.


nwebster
Forum|alt.badge.img+3
  • Author
  • New Contributor
  • 6 replies
  • December 14, 2021
rabbitt wrote:

Look for a configuration profile applied to the machine with a Login Window payload.  Under Access, there is an option to deny login for any local users:

 This may have been applied to the machine if it was once bound to an on-premises Active Directory server.  Turn the first option - "Local-only users may log in" - back on OR unscope the config profile from target machines.


Nailed it! I had set an inactivity log-out under "options" in that config, and had that "Local-only users may log in" setting turned off. Appreciate you!


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings