High Sierra & preStage require authentication

wsg
New Contributor III

We setup DEP and preStage successfully. preStage enrollment requires Active Directory credentials, which we verified to be working before enrolling. The Active Direcotry login populates the local user information (e.g. First, Last name along with uid) correctly. The local account is created correctly, and when it loads, the managementFramework enrollment is not fully complete. In JSS, the computer status ends up in an 'unmanaged' state.

Conversely, when using the QuickAdd.pkg (downloaded from user-initiated enrollment page) with the same login credentials, we observe that the enrollment is fully successful and the computer is Managed by the Management Account. We have reproduced the same issue on multiple computers with multiple user credentials to rule out any potential anomalies. Additionally, we have verified the JSS hosts are able to communicate with APNS, HTTPS, etc.

1 ACCEPTED SOLUTION

cbrewer
Valued Contributor II

This may have to do with your "User-Initiated Enrollment" settings. Do you have "Restrict re-enrollment to authorized users only" checked? Have you tried removing the username from the computer record before re-enrolling?

View solution in original post

3 REPLIES 3

cbrewer
Valued Contributor II

This may have to do with your "User-Initiated Enrollment" settings. Do you have "Restrict re-enrollment to authorized users only" checked? Have you tried removing the username from the computer record before re-enrolling?

wsg
New Contributor III

@cbrewer Thank you, that was it. We couldn't figure it out during jumpstart, and I probably should have started by inquiring from the community :)

cbrewer
Valued Contributor II

If you want to leave "Restrict re-enrollment to authorized users only" turned on, then just remember to clear the username from the computer record prior to wiping/resetting.