Our security team is looking for a way that when a clients request for admin privileges they go through an approval process and if they do get approved, we create an AD account called USERNAME_loc. Since we have mostly PC on the campus, they have set up a special OU where these accounts leave and they use GPOs to set up the local account to only work on their assign computers.
Our security team wants something similar to the Mac environment where we give the USERNAME_loc local admin rights to the machine, however, they do not want the account to be able to log in. I already created a script to auto-create the account and give it admin rights using policy triggers on JAMF but what is holding me back is restricting the account to log in. Has anyone had any ideas on what I can do?
