Hey all,
Question is in the subject. I've been trying to prevent standard users from gaining Admin privileges. We have FV2 enabled, and disable the root account on all our Macs right now.
Some of our users are using single user mode to remove the .AppleSetupDone file to prompts the startup screen, at which point they are making an Administrator account.
Is there any way to prevent this from happening? After researching online, all I could really find were options like firmware password(not really an option due to management of the password), or using a different encryption method other than FV2 which I dont think we will be able to change any time soon.
My major concern is that as long as the user can boot to single user mode, will they always be able to find a way around the controls to gain admin/root privileges? or is there any other way to disable single-user mode that I am missing?
Ive tried using startup triggers to re-create the .AppleSetupDone file but it doesnt seem to hit the machine before the setup screen.
thanks for any advice, Im kind of out of ideas :(

