Hi there. I'm a little confused about what you're asking here. I may be completely misunderstanding you, but are you asking if it's possible to prevent a site admin from Site A from seeing FileVault Personal Recovery Keys from Macs enrolled into Site B?
If so, that's the default configuration when talking about Site access. A site admin can only see Macs/iOS devices enrolled into the site they are part of, and by extension, can only see the PRKs of Macs in that site. You have to be able to view Computers in order to see the keys. And technically even being able to see those keys is a privilege that can be revoked or granted based on permissions assigned to the account or group.
Am I completely off on what you're asking about here?
Hi there. I'm a little confused about what you're asking here. I may be completely misunderstanding you, but are you asking if it's possible to prevent a site admin from Site A from seeing FileVault Personal Recovery Keys from Macs enrolled into Site B?
If so, that's the default configuration when talking about Site access. A site admin can only see Macs/iOS devices enrolled into the site they are part of, and by extension, can only see the PRKs of Macs in that site. You have to be able to view Computers in order to see the keys. And technically even being able to see those keys is a privilege that can be revoked or granted based on permissions assigned to the account or group.
Am I completely off on what you're asking about here?
Hi,
My apologies for responding this late. But yes, you are correct. And that is what I thought as well. Thanks. But, by doing so, it will limit the access to Scripts and Packages. Is this by design or can this be made available to them?
with regards,
Roland