Struggling with PreStage Enrollment

neildavies44
New Contributor

I have my device configured using Apple Business Manager, when I reset the device with my custom PreStage Enrollment, I should be creating a local account during the setup where the user is a non-admin, however every time it runs through my account is an admin.

I've tried creating a new PreStage Enrollment, not working.  The device also becomes managed by the 'administrator' account I pre-configure.  Any help would be appreciated!!

1 ACCEPTED SOLUTION

dmccluskey
Contributor

I have included a screenshot on the prestage settings.

You have to check the box to make a local admin in order to for your logged in user to be set as standard.

All of our macs have been setup this way since day one, none of our users are admin.

2023-04-14_15-42-20.png

 

also your User-initiated enrollment needs have the Username match the prestage admin aaccount and the Create management account unchecked otherwise it fights with the prestage setting. If you do need Create management account then make sure the username created is different then the prestage account.

2023-04-14_15-47-27.png

View solution in original post

5 REPLIES 5

AJPinto
Honored Contributor II

The 1st account on macOS must be an administrator, the account created with PreStage will always be an Admin as its that 1st account. If you are wanting a nonadmin account, it will need to be created with a policy after the enrollment finishes. 

Is that the case even if we have a 'managed admin' account created as well?

AJPinto
Honored Contributor II

Hrm, I have never actually tried to create two accounts with PreStage. In theory if you are creating a local admin account (Checking the Create a local administrator account before the Setup Assistant box), then clicking Standard Account for Local User Account Type. It should create any accounts after the account crated as a standard account, keep in mind for the "standard account" option to work, you must have the create a local administrator account before the setup assistant box checked.

 

Computer PreStage Enrollments - Jamf Pro Administrator's Guide | Jamf

dmccluskey
Contributor

I have included a screenshot on the prestage settings.

You have to check the box to make a local admin in order to for your logged in user to be set as standard.

All of our macs have been setup this way since day one, none of our users are admin.

2023-04-14_15-42-20.png

 

also your User-initiated enrollment needs have the Username match the prestage admin aaccount and the Create management account unchecked otherwise it fights with the prestage setting. If you do need Create management account then make sure the username created is different then the prestage account.

2023-04-14_15-47-27.png

Ah ha, perfect, that seems to have been it.  We have a policy to configure a local managed account with user-enrollment and disabling that, it now works as expected.  Thank you!!