We're new to Jamf and I've been putting together a policy that's triggered by prestage enrollment on a clean installation of High Sierra (10.13.3) to get everything all set up in a convenient, hands-off way. Everything works beautifully except for giving the Administrator account full privileges to remotely manage the Mac.
I'm using this script: https://www.jamf.com/jamf-nation/third-party-products/files/217/enableard-sh-enable-ard-and-configure-remote-management-settings I've tried hard-coding the Target Username and using parameter 4.
I know the script is running since Remote Management is getting enabled, but the "Allow Access for: Only these users: Box" remains empty. I thought maybe those commands just don't populate that box but sure enough, screen sharing doesn't work for the administrator account unless I manually add it to that Box.
I've tried with various accounts, running the script while logged in, at login, and at startup.
Everything I've found so far on Jamf Nation simply points me toward those same commands and similar scripts.
Was hoping someone could point out some tiny thing I'm missing here.
Thanks!
Best answer by easyedc
So it used to be that Apple Remote Desktop would create an .pkg to set all your settings with remote access. After I started looking into it, I found it was broken and with a support case with Apple they had no plans to fix it. They did work with me to create my needs, though, and I came up with this:
puts the Remote sharing icon in the menu. The other settings assign the actual users who get rights and then we grant all rights to those users. Works for us as an policy triggered by Enrollment.
After installing the QuickAdd.pkg I also have to run this shell script afterwards to make sure Casper Remote works just for Casper (VNC will only recognize Casper Remote not regular VNC connections), might help might not:
So it used to be that Apple Remote Desktop would create an .pkg to set all your settings with remote access. After I started looking into it, I found it was broken and with a support case with Apple they had no plans to fix it. They did work with me to create my needs, though, and I came up with this:
puts the Remote sharing icon in the menu. The other settings assign the actual users who get rights and then we grant all rights to those users. Works for us as an policy triggered by Enrollment.
Thank you both so much for your quick responses! Easyedc, I tried your script and it worked wonderfully, exactly what I was looking for. Thank you so much!
@diegogut90 Yes. In my script, when using the -users flag, it's just added to one of the list of accounts to enable. Our JAMF management account is hidden, but it's seen by the system. If you run a
dscl . list /Users | grep -v '^_'
You should see your management account listed, and so if it's on that list, you're fine.
Try updating (or re-typing) the Management account username and password under the Computer info for that Mac in the JSS, see if that works. I will try and do more testing. What version of JAMF are you using also?
I am having a similar problem. I have about 10 out of 600+ computers that are in ARD, and authenticated... but when I try to view remotely, they say they are not authenticated. Each of these computers show that I am not allowed to run reports on them. I am assuming that maybe the user turned remote management off, but 're-enable ARD' policy in the JSS seems to do nothing. They are all picking up the correct prestage settings. This is happening afterwards. I can delete them from ARD, and easily add them back with the correct name/password. But I still can't view them. I am wondering if I sent the above script as a policy if that would correct these few laptops?
@easyedc I am getting the same error message as @diegogut90 when I try to observe, control, or view reports. I have tried retyping the admin creds in the iMac get info. Any guidance would be appreciated. Thanks
We use 3 different kinds of cookies. You can choose which cookies you want to accept. We need basic cookies to make this site work, therefore these are the minimum you can select. Learn more about our cookies.