Alright JAMF Nation, we've got a "fun" one...
I noticed that a computer was removed from my smart group (Out of Contact) and had finally checked in with the JSS after 30+ days. I also noticed that the computer name was now "Admin's MacBook Pro" -- going against our naming convention.
Turns out, the laptop had been stolen a month prior, and the thief has now added an account called admin to a laptop still enrolled in JAMF. The nice thing about this is that I can still manage it and get its IP address at all times.
So far, my solution has been to copy the Safari cache to an afp share at login, giving me some information as to who the person is with this laptop. I know there are software packages out there (Hidden and Undercover) that will snap pictures, lock the screen, etc. The problem with these is that you can't install after it has been stolen (haven't tried packaging and deploying with JAMF, yet).
Does anyone have any terminal commands or discrete ways of getting more information on this thief? Obviously if it is visible to the user, he's going to reimage the machine! Any help would be appreciated...
Thanks!
