network accounts in JSS inventory

corbinmharris
Contributor

All our Macs are bound to AD via Centrify. For an upcoming security audit, I need to generate a list off all AD users that have admin rights on their Macs. Right now, JSS only shows local accounts -

https://www.evernote.com/shard/s57/sh/c3adf68b-73d1-4012-818d-070e56275463/d4af88765f2613be8ac901641d24f4b0

I need JSS to show the information provided in the User/Groups preference panel such as shown -
https://www.evernote.com/shard/s57/sh/bf6ccb3e-1d20-45a5-99bb-131f60e9c30c/32c5f35464d7833ff21d966dc3f2eaa0

Any assistance is appreciated.

Thanks!

Corbin

2 REPLIES 2

mm2270
Legendary Contributor III

Just taking a guess here, but from your second screenshot it looks like you're using straight network accounts, not cached mobile accounts. As such, the OS doesn't really consider those accounts "local" and Casper can't capture them in inventory. They only exist as long as the Mac is connected to your AD/domain controllers.
If they were cached, they'd show up as "Admin, Managed, Mobile" instead of "Admin, Network" as an example. The "Mobile" part is the key, since it means I have a local account folder the operating system is aware of and can be inventoried.
Again, this is just a guess on what the issue it. Could be something else entirely too, but I believe that may be your issue.

If it is, I'm not sure how to solve that one for you. There may be a way to capture this information with an Extension Attribute. I know Centrify includes some command line tools installed on the client that can get called during an inventory report which may be able to pull that information in.

There are a couple of existing threads here on Centrify that might help point you in the right direction:
https://jamfnation.jamfsoftware.com/discussion.html?id=5502
https://jamfnation.jamfsoftware.com/discussion.html?id=7104

mscottblake
Valued Contributor

If the admin accounts are network accounts, could you use the AD security group membership to generate your list?

If you login to your JSS and go to Settings > Casper Admin > AD binding, you should be able to see what security groups are being granted admin access.