Require Password After X Minutes Issue

apizz
Valued Contributor

I've been struggling with this for a few days now but can't seem to figure out what's going.

We are deploying two configuration profiles on our machines - one setting the Login Window preferences and another for Security & Privacy where the user is prompted to enter their password 5 minutes after the computer goes to sleep.

However, I'm getting a weird issue where even though I haven't set the user to be prompted to enter their password immediately after the computer sleeps, a number of machines have this setting locked. I've tried reapplying the config profile several times, but it's very inconsistent, mostly defaulting to prompt the user immediately after sleeping.

Looking at the details of the two config profiles, however, I'm seeing this:

455e5e955fee4519afe67557ce95a414
65a5a6169ed446dc9c31fa0e6d2d46cb

And these are my config profile settings

a3ebd0c928dd44579de50b8e9d4fb744
57eb166fa35648f7be36b5ee0c38db2c

Even though there's no setting for it, it appears the Login Window payload has a screensaver preference which doesn't require a password.

Does anyone know why the Login Window has a screensaver setting in the config profile, or how to remove it? Does this seem like the root of my problem, or something else I haven't looked at?

It does appear to be a function of some management setting, as when I login as the local admin and hold down option to disable management temporarily, the Security & Privacy password prompt behaves normally.

1 ACCEPTED SOLUTION

apizz
Valued Contributor

Of course, it takes the effort of writing a post in order to think outside the box ...

I combined the two separate config profiles into one and my desired 5 minute password prompt appears to have overwritten the login window setting. Seems to have resolved the issue.

View solution in original post

4 REPLIES 4

apizz
Valued Contributor

Of course, it takes the effort of writing a post in order to think outside the box ...

I combined the two separate config profiles into one and my desired 5 minute password prompt appears to have overwritten the login window setting. Seems to have resolved the issue.

gachowski
Valued Contributor II

Yep,

The real issue is that config profiles are a progression from old MCX... and not a clean new break. Back in time with MCX having like setting grouped together was a ok idea.

Now with config Profiles, we really need one key/setting per profile. Having to push new profiles to all you devices because one setting in that profile changed it not very smart. Also the fine control would be a good improvement.

C

That said I don't think we will see that as it would look really ugly in the server app and Apple won't go for that.

lee_smith
Contributor

@aporlebeke

What version of the JSS are you running?

I am curious because I am needing to make some similar settings. I am currently running 9.65.

Thanks!

apizz
Valued Contributor

@lee.smith, I am running 9.73