I have a machine I'm trying to enroll into JSS. As soon as it is successfully enrolled, the user can no longer log in, getting the error message:
Your account has been disabled. Contact your system administrator for more information.
When this is happening, the only account I can use to log in is the hidden jss_admin user that's been created on the machine. (Created during initial enrollment.) I've attempt to correct this using the CLI command pwpolicy, but it has no effect.
If I remove the MDM profile of the machine, the user is able to log in again. (Almost immediately: no need to reboot.)
I believe I need a way to reset the failedpasswordattempt count within the JSS for this machine.
