I'm hoping someone has gone through this process and has some ideas. We are an on-prem Jamf Pro shop. We are looking at implementing some things with out macOS devices as part of our new security process.
I've tried doing the LAPS scripts that have been put out by Josh Miller, and PezzaD84 on Github. I've also tried setup up and configuring the new built in LAPS in 10.46. I've run into various issues with those options and figured I need some help. We have our setup as mostly set and forget, so I'm not well versed in Jamf as others might be.
The built in API LAPS option might work, but we don't have any computers that are currently enrolled with prestage. The test machine I'm using was manually enrolled.
The scripts from Perry seemed the most robust choice with password encryption etc. but seem to not be fully configured right on my end.
I'm wondering if some of the issue is since we are running on a Windows server, since that's or core infrastructure, and not a macOS based server. I sort of go the scripts to work, but they failed generating the password, and I think pulling down the app or scripts. I haven't been able to get the scripts in the policy to retrigger either.
Anyone that has some clearer directions for a Windows based implementation out there?