Giter VIP home page Giter VIP logo

Comments (9)

crsleeth avatar crsleeth commented on August 23, 2024

I am also seeing this both when I provide firstPass via config profile and when it is provided as an argument at command line manually. The workaround I have is to create a second local admin account, delete the first, recreate the first. Only then does macOSLAPS accept the password provided. My guess is that the initial user account created on the Mac is in some weird state when first setup and is causing this.

Only seeing this issue on some Macs like GabrielKemp said. I have not tested it thoroughly but the difference may be Macs 'fresh from the factory' vs. Macs that have been wiped and re-setup.

from macoslaps.

joshua-d-miller avatar joshua-d-miller commented on August 23, 2024

Interesting. It seems this is happening when a new macOS device is arriving and going through ADE for the first time. How are you creating your local administrator account used with LAPS?

from macoslaps.

crsleeth avatar crsleeth commented on August 23, 2024

Not sure about the original poster but I do not utilize ADE. Macs are enrolled via user enrollment manually--the first account created via Setup Assistant is the macOSLAPS one. I guess I could create it later, but I don't have a need for more than one local admin.

from macoslaps.

joshua-d-miller avatar joshua-d-miller commented on August 23, 2024

Is this account a volume owner or have a secureToken?

from macoslaps.

crsleeth avatar crsleeth commented on August 23, 2024

Both. If I can reliably reproduce the issue I will contact you via Macadmins Slack but it may be a few weeks.

from macoslaps.

joshua-d-miller avatar joshua-d-miller commented on August 23, 2024

That's quite alright. Happy to leave this open 👍

from macoslaps.

davisbr1 avatar davisbr1 commented on August 23, 2024

I'm experiencing this issue as well. I have a fresh VM with a local admin account configured through Setup Assistant. It's enrolled in our Jamf instance, not using ADE. I can run macOSLAPS with the firstPass argument, but isn't able to set the password. When I include firstPass in a profile and then attempt to reset the password, macOSLAPS is able to complete the reset.

from macoslaps.

joshua-d-miller avatar joshua-d-miller commented on August 23, 2024

@davisbr1 you mention Jamf. I'm curious if you might have Jamf LAPS enabled which would take control of the account. I don't believe Jamf's implementation is selective and is an all or nothing checkbox.

from macoslaps.

davisbr1 avatar davisbr1 commented on August 23, 2024

Jamf LAPS is not enabled.

from macoslaps.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.