Got a quick question. We have an admin management account that is created during UI enrollment, and a user account on the computers that starts out as admin, but is demoted to non-admin during the enrollment process.
I don't want the admin management account to get a secure token, I want the only account with a secure token to be the standard account.
The problem is that if I log into the management account for any reason, weeks or months after enrollment, the management account gets a secure token! (In addition to the standard account that had a token from the beginning.) How can I log into the management account without it getting a secure token?
Our devices are all mac-book airs and mac-book pros, and are running Big Sur and Montery. All accounts are local accounts.
Thanks,
Randy