Migrating to Kerberos Extension

fraserhess
New Contributor III

We wish to migrate to macOS Catalina and the Kerberos SSO Extension. We have previously used AD binding. As part of manually migrating a computer, we put it in a static group called "Unbound". This group is scoped with configuration profiles for Kerberos SSO and is excluded from profiles that bind to AD.

My question is about new computers coming into the environment. Is there a way to automatically put new computers in this group prior to enrollment? I don't see anything about group membership in PreStage enrollments. (I also have about 40 Macs coming onboard from an M&A where there's no DEP.)

As I type I wonder if it would be better to put the existing computers in a static group and reverse my logic on the profiles.

But any ideas are welcome. Thanks.

(Running Jamf Pro 10.15.1 on-prem with a 10.19 upgrade scheduled this week.)

1 ACCEPTED SOLUTION

walts_9
New Contributor III

You could use a smart group that pulls machines enrolled after a certain date and change your binding to happen after enrollment then exclude the smart group. Not sure if that fits your workflow.

View solution in original post

1 REPLY 1

walts_9
New Contributor III

You could use a smart group that pulls machines enrolled after a certain date and change your binding to happen after enrollment then exclude the smart group. Not sure if that fits your workflow.