Skip to main content
Question

Block security and privacy except...

  • February 12, 2015
  • 1 reply
  • 3 views

Forum|alt.badge.img+8

The goal of this policy is to block Security & Privacy from all users except the local admin that we push to all computers.

Here is what I have tried

Configuration profile

Under General
category = none
Distribution Method = Install automatically
Level = User Level

Under Restrictions
Preferences = uncheck extensions and security & privacy

Under Scope
Target = add the computers we want to push the policy to
Exclusions = "local account name" LDAP/Local User

Doing this leaves the Configuration Profile status as pending.
If I switch from user level to computer level it blocks security and privacy for everyone (the exclusion does not work).

1 reply

Forum|alt.badge.img+16
  • Valued Contributor
  • February 12, 2015

The user-level restriction will be applied as soon as you log into a directory-based account or an MDM-enabled account on the machine in question. If you're not using directory-based accounts, there's a guide here about enabling your accounts for MDM.