Posted on 08-20-2018 06:12 AM
Hi,
Does anyone know if it is possible to force user to use their AD-ID when they enrol the Mac to Jamf. in DEP and in UserInitiated Enrolment.
Posted on 08-20-2018 06:44 AM
I'm not sure if it's possible to force them to use their user ID. However, the Access section in User-Initiated Enrollment allows for you to setup the usage of LDAP for authentication.
Regards,
TJ
Posted on 08-21-2018 01:23 AM
Yep, I know that part, but I think that is only for the access to the enrolment profile.
Posted on 08-24-2018 05:23 AM
Well, I can tell you that it is possible, but what I've come up with is messy so far. Currently, I am in the process of converting our student enrollment from an "imaging" type enrollment to one that is now user initiated. We do NOT bind our machines to AD, nor do we use any type of LDAP account. What I am trying to finish is the process of converting the students existing personal (local) accounts to ones using their AD credentials, locally. I'm working this through a workflow involving SplashBuddy, Enterprise Connect and a script that I've put together from various resources (smart people) here on jamfnation.
Long story short, swapping the account is easy. Basing it on AD credentials is... interesting. So far, I can have our users log into Enterprise Connect and then use those credentials (by methods that are not very secure, FYI) to create and move their account using the new info. It's messy, but hey. I've got about 10 days to get it into production so... As I progress and get things a little more stable I'd be happy to share... unless anyone here wants to help me pick through when I'm trying ;-)
Posted on 08-24-2018 09:57 PM
Saw this article.
https://nstrauss.info/posts/nomlad-login-jamf-dep-workflows/
Is that what you're asking for?