Prevent Users from Removing Configuration Profiiles

Matt
Valued Contributor

What is the best way to do this minus no admin rights? I tried to limit the System Preferences but what ends up happening is all Prefs in the "Other" section are disabled as well. What is the best way to stop users from removing the profiles? This is the future replacement for MCX after all :D

7 REPLIES 7

nkalister
Valued Contributor

enable the passcode payload, and set a password on the profile. Even local admins will need to supply the password you set to remove the profile.

Matt
Valued Contributor

Interesting!!! Let me give that a go. Ill mark as answer once I verify.

Thanks!

Matt
Valued Contributor

Interesting!!! Let me give that a go. Ill mark as answer once I verify.

Thanks!

Matt
Valued Contributor

Maybe I am missing something but I see the passcode payload, where is the passcode actually entered?

fritz_schlapbac
Contributor

I didn't see the option to add a passcode in the JSS.

I made a profile on Lion Server with password protection and imported it to the JSS.

The JSS seems to keep the password setting.

eleven
New Contributor III
New Contributor III

Hi Matt,

Maybe this article will help out:

https://jamfnation.jamfsoftware.com/article.html?id=204

We can add preference panes from the 'Other' section and keep them enabled.

nkalister
Valued Contributor

oh, sorry, I use profile manager to create my profiles, not the JSS. The JSS does not make this setting available, but as fritz said, the password will survive uploading to the JSS.
Also, my memory apparently sucks, because it's not the passcode payload, it's in the General payload, Security section. Sorry for the confusion!
Screenshot:
external image link