Previously, we have a script that binds our macOS devices into AD. We allow our staff to become the admin on the computer by setting the AD staff group under "Allow administration by". The user has admin privilege when they are inside the network, and it got removed when they are outside of the network.
We switch over to the DEP PreStage process and set up the Directory step. The macOS devices bind to our AD but it doesn't respect Allow Administration Group setting within the DEP PreStage. We try the group AD name (AllStaff) and domain name before the group (districtAllStaff) to no available.
Does anyone successfully assign admin privilege to an AD group with the DEP PreStage Directory step?
