Which then downloads the DMG file from the browser. I configure each Adobe application separately on Adobe admin console. With that said, below is a brief summary of my implementation:ġ. And with recent Adobe updates to its applications, all apps seems to now function on Intel and M1's Macs. But most recently, I've had the apps install complete properly without any error messages. I would sometimes get installation failed errors on Self Service, but the install was actually completed, with a complete status in the actual policy logs. About a month ago, I was having a lot issues getting a handful of Adobe apps to run on M1 Macs. Note: There is no need to change the Method for Setting Password or Password Length settings.I recently was able to deploy Adobe 2021 packages to Intel and M1 machines through Self Service. Under Platforms: macOS, uncheck the Create management account setting. Go to Management Settings: Global Management and select User-Initiated Enrollmentģ. To set the QuickAdd packages generated by the user-initiated enrollment process to not create the management user account, use the following procedure:Ģ. The same method can used with user-initiated enrollment. Note: The computer will still appear in the Jamf Pro server’s inventory as a managed computer with the management account listed. The Recon application will generate a QuickAdd package that will enroll the Mac in the appropriate Jamf Pro server, but the newly-created QuickAdd will not create the Jamf Pro management account on the Mac as part of the installation process. This will cause the In the Method for Setting Password: drop-down menu to display Specify password…, but the Create… button in the lower-right corner will remain active. Uncheck the Create management account if it does not exist option The Create… button in the lower-right corner will go from grayed-out to active.ĥ. The Create management account if it does not exist option will be enabledī. This will cause two things to happen in the Recon interface.Ī. In the Method for Setting Password: drop-down menu, select Randomly generate password. Specify the name of the management account you want to useĤ. Here’s how you can configure Recon to generate a QuickAdd package that does not install the Jamf Pro management account:ģ. The usual method of enrolling a Mac into Jamf Pro uses a QuickAdd installer package, generated by Jamf’s Recon application or via user-initiated enrollment. If you are not using Jamf’s Remote application for remote screen sharing, or enabling the Jamf Pro management account for FileVault 2, it is not necessary to install the Jamf Pro management account on Jamf Pro-managed Macs at all. To provide the option of enabling the management user account for FileVault 2.To provide SSH connectivity for Jamf’s Remote application.The reason for this is that the Jamf Pro agent by and large does not need the Jamf Pro management account in order to work properly.Īs of Jamf Pro 9.99.0, the Jamf Pro management account is used for the following: These protections include including the ability to set a random password for the account on a per-machine basis and the ability to rotate the password on a regular basis.ĭepending on your needs though, it is also possible avoid setting up the Jamf Pro management account on Macs. To help protect against the Jamf Pro management account being compromised, Jamf has added some protections. This may cause issues in some Mac environments, where the creation of local user accounts is tightly controlled to help minimize opportunities for malicious third parties to compromise unused accounts. Jamf Pro-managed Macs usually have a management account on the Mac, which is normally created as part of the Mac’s enrollment in the Jamf Pro service.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |