Need to create a smart group: Find computers that don't have the local admin FV2 Enabled

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on
09-19-2018
04:38 PM
- last edited on
03-04-2025
04:34 AM
by
kh-richa_mig
Hello does anyone know how to create a smart group that finds machines that don't have the local admin enabled for FV2? I need to grant secure tokens to these machines through self service.
- Labels:
-
Self Service
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 09-19-2018 04:47 PM
Do you mean Local Admin Account or your Management Account?
https://donmontalvo.com

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 09-20-2018 10:59 AM
@donmontalvo We use local admin accounts to support users.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 09-20-2018 03:27 PM
If you've the same local admin on all your Mac, or just few different admin member account, you can use the native criteria SmartGroup "FileVault 2 User".
If you don't know all local admin, it's possible to create a Extension Attribute linked to a script getting admin group members names and return a YES/NO after check if one of all local admin is used in FV2
