header

The Good, the Bad, the ugly of local admin management

JNUC Video Posted on Youtube

YOUTUBE Video

Additional Resources:

Apps

"Jamf Pro 10.45 introduced a new "Local Administrator Password Solution" (LAPS) API endpoint. LAPS helps admins avoid the practice of creating a single static admin account password on their managed devices."

The PRK [Option + Shift + Return]

prklogin

On a Mac with Apple silicon using macOS 12.0. 1 or later, press Option-Shift-Return to reveal the entry field for the PRK, then press Return (or click the arrow). macOS starts up. There is only one PRK per encrypted volume, and during FileVault enablement from MDM, it can optionally be hidden from the user.

Manage FileVault with mobile device management

The Flow

flowchart