Skip to main content
Question

Need to create a smart group: Find computers that don't have the local admin FV2 Enabled

  • September 19, 2018
  • 3 replies
  • 15 views

Forum|alt.badge.img+8

Hello does anyone know how to create a smart group that finds machines that don't have the local admin enabled for FV2? I need to grant secure tokens to these machines through self service.

3 replies

donmontalvo
Forum|alt.badge.img+36
  • Hall of Fame
  • September 19, 2018

Do you mean Local Admin Account or your Management Account?


Forum|alt.badge.img+8
  • Author
  • Contributor
  • September 20, 2018

@donmontalvo We use local admin accounts to support users.


mpuyet
Forum|alt.badge.img+5
  • Jamf Heroes
  • September 20, 2018

If you've the same local admin on all your Mac, or just few different admin member account, you can use the native criteria SmartGroup "FileVault 2 User".

If you don't know all local admin, it's possible to create a Extension Attribute linked to a script getting admin group members names and return a YES/NO after check if one of all local admin is used in FV2