SAP / macOS-enterprise-privileges

For Mac users in enterprise environments, this application gives users control over the administration of their machine by elevating their level of access to administrator privileges on macOS. Users can set a timeframe in the application's settings to perform specific tasks, such as installing or removing an application.
Apache License 2.0
1.4k stars 150 forks source link

If you toggle privileges and you're using timer and then reboot the Mac - privileges comes back up on login without a timer and user has admin forever #54

Closed Angelworks closed 1 year ago

Angelworks commented 2 years ago

I've tested this on MacOS 12.x and 13.x - if you toggle privs - you'll get a countdown timer (if your using one) and if you reboot the Mac - privileges comes back up after login and the user will have local admin forever and no timer.

Do forgive me if this is already logged as a bug - I tried searching and couldn't find anything.

rtrouton commented 1 year ago

There is an example LaunchAgent available which demotes the user logging in to being a standard user:

https://github.com/SAP/macOS-enterprise-privileges/tree/main/sample_launchagent