We recently tested a scenario with Jamf Connect and Active Directory where we enabled the "Change password at next login" flag on the AD user account.
Here's what happened:
- I was logout of Jamf Connect and on the Self Service+ UI, I noticed the status said: “Password out of sync” and “Sign in to your Identity Provider”.
-
On the next login attempt via Jamf Connect, I expected a prompt to change the password. Instead, Jamf Connect displayed an error saying that the password is expired, with no option to change it directly from the login window.
This raises a few questions:
-
Shouldn't Jamf Connect handle the password change flow directly when AD requires it?
-
What are the recommended access limitations when a user is not signed into Jamf Connect?
-
Currently, I can still request admin access via Jamf Connect even if I'm not signed in.
-
However, if I log out and log back in, the system prompts me for the current password as expected.
-
How do you structure access policies around Jamf Connect login state in your organization?
Are there best practices for restricting local or admin privileges until the user is fully authenticated via Jamf Connect?
Would love to hear how others are handling this!
