Posted on 03-02-2015 03:31 PM
Hi -- We have a problem where our technicians enroll macs for users. They use their personal domain credentials to sign into the enrollment page, and use the "Assign To:" field to assign the end-user. In the JSS the technician shows as the user, instead of the end-user, even though we filled out the "Assign To:" field. Any one ever experience this?
Solved! Go to Solution.
Posted on 03-03-2015 03:23 AM
@frivera, which version of the JSS are you using? I was having the same problem as what you describe but it was fixed when I updated to 9.65. Interestingly, this was only a problem for OS X enrolments. Enrolling iOS clients and assigning them to other LDAP users worked fine.
Posted on 03-02-2015 03:56 PM
Why not just create a QuickAdd.pkg with Recon and have your techs use that? I believe that leaves everything as it is in the JSS, user location etc
Posted on 03-02-2015 07:39 PM
On the assign to part, when they click the magnifying glass does it come up with a check beside the entered name?
In the jss after the machine has been enrolled, if you edit the user and location info, enter the correct user and press the magnifying glass will it fill in the rest of the fields correctly?
If a user enters their own credentials to eroll does it fill out the User and Location info correctly?
I would also be wary of entering personal credentials on a user's machine. I use an account I set up in the JSS with just enrollment privileges if I ever need to do this.
@usher.br][/url Because that adds an extra step, having to enroll the machine and then go in to the jss, look up the machine and edit the user and location field, as opposed to just visiting the /enroll page and signing in.
Posted on 03-02-2015 07:46 PM
@Matt.Sim I'm pretty sure installing the pkg from recon doesn't modify the user and location. Am I wrong with that?
Posted on 03-02-2015 07:51 PM
@usher.br][/url][/url][/url That is correct, but if you DO want the User and Location field filled in then it isn't ideal. The Quickadd.pkg downloaded from the jss/enroll page (normally) fills in the info with whomever logged in, or whomever it was assigned to if the user logged in has rights to assign to another user.
Posted on 03-03-2015 03:23 AM
@frivera, which version of the JSS are you using? I was having the same problem as what you describe but it was fixed when I updated to 9.65. Interestingly, this was only a problem for OS X enrolments. Enrolling iOS clients and assigning them to other LDAP users worked fine.
Posted on 03-03-2015 05:37 AM
Create a local user in the JSS, give them rights to enroll and have the techs that account to enroll. After they enter those credentials, then they can enter the LDAP name of the user they want to assign to the device (if you're using LDAP that is).
Posted on 03-03-2015 06:22 AM
All you have to do is add the techs domain accounts to the jss with enrollment rights and they will be able to enter the userid of the assigned user when using the eroll page on the jss.
Posted on 03-03-2015 07:24 AM
Oh, I see where I went wrong. Totally read this as a "Re-enroll" issue.
What everyone above this post (excluding me) has said is true. Give your techs enrollment rights for the JSS and they can choose who to enroll a computer to after signing in to /enroll
Posted on 03-17-2015 08:46 AM
Thank you all for helping! It sounds like its a bug that is addressed in 9.65, we are planning on upgrading this weekend.
Posted on 06-01-2016 01:33 AM
I am having similar issue in giving access to assign user while enrolling. If I give the user "Enrollment Only" Privilege then user has option to assign the LDAP user in enrollment page but if give the same access with Custom Privilege the option assign to user in enrolment page is removed. I think its a bug in 9.81.
Thanks & Regards,
Karthikeyan