Posted on 05-14-2024 11:09 AM
We ran into an issue where one of the higher-ups within our organization was having printer troubles and one of our technicians remotely logged into their Mac with the managed admin credentials. The higher-up took issue with this as the user's account does contain sensitive documents and they're not a fan of the possibility that anyone in our department is able to remotely log in using the Screen Sharing app. Any ideas on how to designate Jamf Remote Assist as the only RD software and possibly disable or remove Screen Sharing capabilities without completely disabling RD? Ideally, the end-user would have to allow the screen sharing session and the Screen Sharing app allows any user to connect if they have the correct admin credentials.
Posted on 05-14-2024 12:04 PM
If you use the Disable Remote Desktop button under Management Commands on the Management tab of a computer record, that will disable Screen Sharing (and VNC).
Posted on 05-14-2024 12:07 PM
If you guys need more access control in connecting to remote devices, you likely need a tool like Beyond Trust Remove Support, or Team Viewer. I would have larger conversations about this issue before making any decisions.
05-14-2024 12:22 PM - edited 05-14-2024 12:22 PM
Anyone with admin privileges will be able to access anything on a user's computer regardless of whether they're using remote control software, command line tools, or even management systems like Jamf Pro. That's the nature of support.
Can that support be abused? Yes. This is why you hire trustworthy professionals and you put mechanisms in place to audit what they can do.
This is probably where you'll need to educate your higher-up and your staff.
As you can see, I'm approaching this as a people issue not a technical issue. You can't be both an administrator and non-administrator. But you can you can set expectations and use technology to hold yourselves accountable.
Posted on 05-24-2024 02:51 PM
If you hide the local admin account, only User allowed sessions can occur
Posted on 06-03-2024 05:30 AM
Thank you so much for the suggestion.