Hey everyone, i know this isn't a direct issue with Jamf, but wanted to see if anyone else in a school district has tackled this issue.
We use cached mobile accounts, and machine authentication to our 802.1x wireless network. No matter the current state of the students active directory account( disabled, broken, no group membership) they are able to login to a laptop that has their account cached. we have recently started getting requests to disable or remove a students computer access/privileges for anywhere from a day to a week. Previously we had thought that disabling the AD account would prevent login, and apparently thats only the case if the user/student has never logged into a laptop before. Does anyone have a trick out that that would essentially allow us to prevent a single or group of users from logging into a laptop they have a cached account on? Anything involving a policy push out would likely not work, since it takes days for the majority of our laptops( 2,000+) to all receive a policy. Thanks for any advice!