Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] When erasing a mac and enrolling user as standard, no secure token is given #543

Open
zpropheter opened this issue Mar 3, 2025 · 1 comment
Assignees
Labels
bug Something isn't working

Comments

@zpropheter
Copy link

Describe the bug
When erasing a mac and enrolling user as standard, no secure token is given

To Reproduce

  • Trigger Erase-Install to erase and re-enroll a mac
  • Use Jamf Connect or other Privilege Management Tool to create user as standard during enrollment
  • Try to enable filevault

Expected behavior
On a new enrollment your first logged in user should be granted a secure token, regardless of privileges. ECAS and MDM wipe perform as expected in same environment.

@zpropheter zpropheter added the bug Something isn't working label Mar 3, 2025
@zpropheter zpropheter changed the title [BUG] [BUG] When erasing a mac and enrolling user as standard, no secure token is given Mar 3, 2025
@grahampugh
Copy link
Owner

This appears to be an issue with startosinstall in circumstances where you skip account creation during enrollment and then create a standard account using Jamf Connect or similar post-enrollment process.

An FB has been opened with Apple as this would appear to be a bug. I would recommend you do the same to raise impact. You may need to remove erase-install from the mix and just use the straight startosinstall --eraseinstall command to get Apple to listen.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants