Strange Login Window Behaviour

RDowson
New Contributor III

I'm seeing some strange behaviour with the login window on devices in one Jamf environment but not in another.

All machines have the CIS L1 baseline and some additional lockdown restrictions on them. They should be asking for the username and password at the login window on startup and after a logout.

This works fine for devices in one environment but in the other I get the user account(s) listed on startup and only the password is required. It works as expected if you log out though.

I wondered if it was something relating to FileVault but, again, the configs between both Jamf environments should be the same. The only difference I can see is that one Mac is Intel (T2) and the other is M1.

Here are some examples of what happens on the Mac that isn't working as expected:-

Startup:

IMG_4451.jpeg

After logout:

IMG_4452.jpeg

Some of the settings applied:

image001.png

1 ACCEPTED SOLUTION

efil4xiN
Contributor II

i could be wrong but isn't this expected behavior for intel machines and filevault? This is  what I have seen this week working with intels again. 2nd screenshot is after logout and not reboot. didn't Rich cover this a few years back here 

View solution in original post

8 REPLIES 8

sdagley
Esteemed Contributor II

@RDowson make sure you don't have multiple Configuration Profiles configuring that setting as that will result in "undefined" behavior.

mvu
Valued Contributor III

Yeah, was thinking of multiple configuration profiles as well. We apply CIS level 2 here. I don't see this on Sequoia. 

efil4xiN
Contributor II

i could be wrong but isn't this expected behavior for intel machines and filevault? This is  what I have seen this week working with intels again. 2nd screenshot is after logout and not reboot. didn't Rich cover this a few years back here 

RDowson
New Contributor III

Thanks! I did wonder if it was an Intel vs Apple Silicon thing. Looks like it expected behaviour then.
The one in the screen grabs is an Intel machine so that makes sense.

mvu
Valued Contributor III

We have intel boxes. I don't see this, but then again we're using Microsoft Platform SSO.

RDowson
New Contributor III

We're using Platform SSO too.

mvu
Valued Contributor III

Interesting. If it makes a difference, we're using it with Smart Cards config.

RDowson
New Contributor III

We're just username and password so maybe that's why it's different.