resetting passwords with local account policy and filevault recovery key

jalhathanaya
New Contributor II

Hello community,

 

I am stuck trying to figure out a way to reset password of forgotten computer password that is used to log in to the computer. I have read here that you could do reset a computer's password with local account policy and I have tried that and it is not working. i am not sure which triggers i should enable for this to work or any other option i should include. 
Also, the reset option in local accounts policy says: This does not update the account's login keychain password or FileVault 2 password.  can i update the those credentials later with the filevault recovery key that i hold?

I also have tried the filevault approach, but i can only see the reset password with apple id option and not the using filevault recovery key. 


Thanks for the help in advance

 

 

2 ACCEPTED SOLUTIONS

TrentO
Contributor II

The simplest way would be the manual method. Basically reboot to Recovery and unlock FV with either the FV password or the Recovery Key. Then from the Utilities menu open Terminal and type resetpassword. 

Here's the Apple article: https://support.apple.com/en-us/HT212190

View solution in original post

AJPinto
Honored Contributor II

You are in a rock and a hard place with a Secure Token. JAMF cannot reset Secure Token holding passwords due to Apples design. Documentation should really be updated to make this more clear.

 

Your best option is to use the FileVault recovery key to reset the accounts password.

View solution in original post

2 REPLIES 2

TrentO
Contributor II

The simplest way would be the manual method. Basically reboot to Recovery and unlock FV with either the FV password or the Recovery Key. Then from the Utilities menu open Terminal and type resetpassword. 

Here's the Apple article: https://support.apple.com/en-us/HT212190

AJPinto
Honored Contributor II

You are in a rock and a hard place with a Secure Token. JAMF cannot reset Secure Token holding passwords due to Apples design. Documentation should really be updated to make this more clear.

 

Your best option is to use the FileVault recovery key to reset the accounts password.