Skip to main content
Question

Script to Allow users / groups that can log into a machine?

  • June 22, 2016
  • 1 reply
  • 2 views

Forum|alt.badge.img+12

I know that I can manually create a configuration and enter the groups / users that can log into a machine, but how would I go about this via script?

I have a first run script that is getting all of the relevant AD information, including groups that can log into the machine, but I don't know how to turn around and apply it to the machine.

Thoughts?

1 reply

Forum|alt.badge.img+15
  • Contributor
  • 589 replies
  • June 23, 2016

I imagine this could be done through AuthorizationDB or something. Sadly, I've no idea how.. I suppose I'd take the easy way (at least in the short term) and write a LaunchAgent that would kill 'loginwindow' process for any user that not in some list... That wouldn't prevent SSH connection, but can deal with that though the com.apple.access_ssh group.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings