Just wondering from those that have gone zero touch on MacOS devices, are all of your users then local admins? Just in the work flows I have tested, the person setting up the device is a local admin. Yes I realize that could likely be scripted post setup to change memberships, but was wondering what others were doing. Not to say its that much of an issue at my organization, we do not have the need to drop ship new devices, and set up is down to just a couple hands on steps.
Solved
Zero Touch Deployment on Mac OS
Best answer by revive
We haven't used FireVault yet so we don't have a hidden management account but we use PreStage, create an Admin account and have the user be presented with the local account option from PreStage that are standard accounts.
No one has complained regarding admin rights as we can install the apps via policy or tell them to install it via self service. No Need to remote in and do it manually. Also, all apps we need for our company is always there on self service.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
