joshua-d-miller / macOSLAPS

Swift binary that will change a local administrator password to a random generated password. Similar behavior to LAPS for Windows
MIT License
387 stars 58 forks source link

Setup #100

Open sfle298201 opened 1 year ago

sfle298201 commented 1 year ago

I have Active Directory, do we have to actually create a local account to use MacOS laps on each machine?

crsleeth commented 1 year ago

Yes. Or the local admin account needs to be created through automation/MDM. Be sure whatever setup you go with gives the account a Secure Token.

joshua-d-miller commented 9 months ago

@crsleeth is correct @sfle298201. You would either use MDM to create the administrator account to be used with LAPS or use a too lot create the administrator account on the device. When macOS devices are bound to AD they will write the password to the same field in AD as Windows devices do.