Posted on 10-16-2013 09:20 PM
We currently use Active Roles for AD account management and have our users set up security questions and answers in the account claiming process. Active Roles puts out a nice plugin for Windows machines that allows you to click "Forgot Password" at the login screen and pulls up a browser to access the website of our password manager allowing users to reset their own passwords and log in to the machine. From what I can find, I'm unable to duplicate this on OS X. Any ideas? All of our clients are 10.7 or higher.
Another idea that I had was to deploy a generic password account to all of the machines that would auto launch the website. Unsure of how feasible this is as I don't want it to have a full user home.
Posted on 10-17-2013 06:37 AM
Due to security reasons Apple doesn't allow applications to launch over the Login window, so I don't think its possible to get to what you're looking for. There are some ways to make certain apps or dialogs open above it, but its tricky and is something that needs to run as root. I doubt very much a regular user account would be able to activate something to do that.
Besides, there isn't any way I know of to get a link on the Login Window to even initiate something like that.
It might be possible to do your second idea though. Create a very locked down user account with Parental Controls applied that would only allow Safari to launch at login and maybe even restrict it from going anywhere other than your password manager site. I don't have specifics for you on how to do that, but I'd say that's a lot more feasible than getting a browser to open over the login window.