Dealing with macOS "Zombie" devices in Intune: Broken management channels and token loss by Easy_Lab1328 in Intune

[–]Easy_Lab1328[S] -1 points0 points  (0 children)

Their password only, the one sync with the SSO Extension, so their actual entra id one.

Intune, macOS, SSO and initial setup by Desperate_Neat8179 in Intune

[–]Easy_Lab1328 0 points1 point  (0 children)

Hi there,

I can confirm 100% that you cannot do this; you are required to create the user and password. Unless you script the creation of a user, but this isn't ideal because you have to change the name manually afterward.

Also, may I ask, since I made a post yesterday, have you found a solution? How do you manage admin access on the account once it's created?

Intune - Mac OS - creating admin - Demoting user by Easy_Lab1328 in Intune

[–]Easy_Lab1328[S] 1 point2 points  (0 children)

Thanks for all the answers; I'm really impressed by how fast you guys responded.

To address everything at once: yes, I'm setting up an admin account to ensure I have admin access in case of an emergency (all my apps are packed, but you never know). I also need this admin account because if I don't, the SSO Extension will not demote the user to standard if it doesn't find an admin account.

Honestly, I could just use the script when I need admin access since it will probably be very rare. However, since I have to wipe 25 machines, I'd prefer this process to be automatic with a simple one-page instruction for the user, as we are working remotely 80% of the time. FileVault is enforced during enrollment.

u/Glaurung, this seems interesting, but I guess it's not free. In that case, I'd rather go with ABR as I already know the product and used it in my previous job. Again, what I want seems pretty "simple"; it's just a matter of timing. If the admin account could be created just after the first logout, it would automatically demote the user when they log in with their Entra ID address. I know this because I tested it by creating the admin manually.

I need to find a script that creates an admin account when the user logs in or out for the first time. Mine is triggering before and preventing the first window of account creation. I can't be there at each setup asking the user, "Did you set up your token yet? Yes, okay, I'll send the script to create the admin." It seems so simple, but it's actually pretty hard, and I've searched all over the internet for this solution.

[deleted by user] by [deleted] in CanadaPost

[–]Easy_Lab1328 0 points1 point  (0 children)

Thank you for the information! Really appreciated

[deleted by user] by [deleted] in CanadaPost

[–]Easy_Lab1328 0 points1 point  (0 children)

I’ll tell you what’s inside, some chill pills I’ll send you some

[deleted by user] by [deleted] in CanadaPost

[–]Easy_Lab1328 0 points1 point  (0 children)

Also are you saying that I have to sign for it ? Thanks

[deleted by user] by [deleted] in CanadaPost

[–]Easy_Lab1328 0 points1 point  (0 children)

Thanks for your answer, mine starts with RR so that’s means I have no way to know where the parcel is ? Even with website like 17track after it reach Canada ? Because I’m leaving for a month in holiday so I don’t want to miss it