Posted on 08-30-2022 06:47 AM
Hi Everyone,
Local accounts created using the local account policy does not seem to work on Catalina. the policy runs and creates the account fine however it does not show on login screen and just shakes if you try login using other.
has anyone else come across this issue?
thanks
Posted on 08-30-2022 02:05 PM
It sounds like you are trying to login at the FileVault screen. Account created by Jamf are not granted a Secure Token. Until they have been grated a Secure Token, they can not unlock the drive.
To give a Secure Token to an account you need to do one of three things:
Unfortunately, there is no easy way without some user involvement.
I will raise this question. Why do you need an account created by Jamf to have an ST? Most time I have seen accounts created by Jamf is for a "backdoor" tech account. It is considered bad security to give a general use account a Secure Token (unless you are using something like LAPS to have individual passwords for each computer). If that password was ever compromised, your whole fleet would be accessible to a bad actor.