JAMF 7 > admin users becoming non-admins

Not applicable

Folks,

Anyone have/know the command line for ODowngrading an Admin account to
Standard User'.

We want to kick down existing Admin users on local machines to Apple's
Standard User.
I know it's a tick button per computer in the System Preference and log in
and out (That is 150 trips of explaining myself and then the whole ONo you
don't understand, I MUST be an Admin!!')

Would love to push this out as a Policy unbeknownst to them.
Been looking at dscl, dseditgroup and so far have managed to remove the
Admin Group, so now all local account have become Standard!
LOL .. It's a test machine eh.

I think it's just a remove of the UserName from Admin Group .. But my
blunder killed the Admin group thus killing all accounts from 'Admin-ibilty'

Has anyone tried this?
Wise?

Thanks all!!!

-P@

DISCLAIMER 7/31/2009

This communication is intended only for use by casper at list.jamfsoftware.com. It may contain confidential or privileged information. If you receive this communication unintentionally, please inform us immediately. Thank you. 180 has registered companies in the United States and in the Netherlands. 180 Los Angeles LLC . (180) 1424 Second Street, Suite 200 and 300, Santa Monica, California 90401, is registered with the trade register in the US in Delaware under file number 4260284 and the corporation's FEIN is 20-5982098. 180 Amsterdam BV (180) Herengracht 506, 1017 CB, Amsterdam is registered with the trade register in the Netherlands under number 34253037 and VAT number NL8161.54.673.B.01. The content of this communications is not legally binding unless confirmed by letter or telefax. Please note that 180 is neither liable for the proper transmission nor for the complete transmission of the information contained in this communication or for any delay in its receipt. Also please note that the confidentiality of email communication is not warranted. All services and other work provided by 180 are subject to our general conditions (supplier terms and conditions). The conditions are available for inspection at Herengracht 506, Amsterdam and at the Chamber of Commerce in Amsterdam. If you wish to receive a hard copy of these conditions, please send an e-mail with your address to info at 180amsterdam.com <mailto:info at 180amsterdam.com>

In the event you send to 180 any unsolicited ideas and/or materials (whether consisting of texts, images, sounds, software, information or otherwise) ("Materials") by e-mail or otherwise, 180 shall be entitled to use, copy and/or commercially exploit such Materials to the fullest extent, free of charge and 180 will not be bound by any confidentiality obligation in respect thereof.

2 REPLIES 2

Bukira
Contributor

would it not be removing them from the admin group 80? modify the admin
group, or maybe push out a new admin group file with just the default
admins in, it will be in the db folder under groups

id create a new group folder and push that out, thus removing all users
from the admin group

Criss Myers
Senior Customer Support Analyst (Mac Services)
Apple Certified Technical Coordinator v10.5
LIS Business Support Team
Library 301
University of Central Lancashire
Preston PR1 2HE
Ex 5054
01772 895054

Not applicable

Brilliant!
Did it!
Works like a charm ... Cannot do it with Remote.. Must be done by Policy as
Root (for the obvious)

Thanks Chris!!
:)

-P@