Advice on Profile Exclusions

dstranathan
Valued Contributor II

All of my managed Macs have a login window Profile that prevents automatic login. End result: Everyone must authenticate at the OS X login window with AD (or cahched) credentials. Typical IT privacy/secuirty policy etc.

I deployed a new home/remote office Mac for an executive. Other than having a non-AD local account, I didnt give his Mac any special configurations or policies/profiles etc. His Mac is (nearly) configured idential to everyone else.

The executive got home and booted-up his Mac.He requested for me to allow Automatic Login ("my previous Macs let me do it..."). He wants to be able boot right into his user session without being prompted. Yes - this is a secuirty issue etc but that's what he wants and he's the boss so...)

I went back to the JSS and I created an exclusion for the login window Config Profile. The JSS indicates that the Mac no longer has the Profile installed, however, the option to enable Automatic Login is still grayed-out in the System Preference Pane (even though he is a local admin).

This is my first time managing a remote "special case" system with JAMF, so I'm still figuring out these types of logistics etc.

Questions:

Why is this particular Mac still "holding on" to the original login window settings even though I excluded his Mac later and the profile is no longer present on said Mac?

What do I need to do to make sure this particluar Mac will allow Automatic Login again?

5 REPLIES 5

davidacland
Honored Contributor II
Honored Contributor II

Does the Mac have FileVault enabled? You can't switch on auto-login if FV is turned on.

dstranathan
Valued Contributor II

Good catch! No, the Mac in question does not have FDE enabled.

Worth mentioning that I am able to reproduce this exact behavior with a test Mac here in IT.

If I retract/kill the login window profile (via an Exclusion) the payload settings for Automatic Login remain, and I cant access the drop-down menu (its grayed-out).

Profile is definetley removed. No longer shows up in the JSS or on the device via the Profile Pane GUI or the /usr/bin/profiles -P command.

davidacland
Honored Contributor II
Honored Contributor II

There were some changes around that in Yosemite. What does a cleanly installed Mac look like that hasn't been enrolled with Casper?

You may need to disable the "Require password to wake from sleep or screensaver" setting as well.

dstranathan
Valued Contributor II

My IT test Mac is a "clean" image of 10.11.4 (Casper Imaging and AutoDMG)

dstranathan
Valued Contributor II

Bingo.

Removing the Security & Privacy Configuration Profile did the trick on my IT test Mac. Ill push it to my executive's home office Mac next and have him confirm.

I should have guessed this might be the issue since we have seen so many issues related to these two specific Profiles in recent months (and Im still running 9.81 too, by the way).

Thanks, David.