lithnet / access-manager

Access Manager provides web-based access to local admin (LAPS) passwords, BitLocker recovery keys, and just-in-time administrative access to Windows computers in a modern, secure, and user-friendly way.
Other
238 stars 20 forks source link

[HELP] MacOS LAPS Administration #232

Closed gbica-hzo closed 2 months ago

gbica-hzo commented 3 months ago

Unable to determine user of the MacOS LAPS password

We are testing LAPS using AMS on MacOS. Here is the scenario

What is the username associated with this LAPS password? Do we need to create an admin user called "Administrator" via MDM?

jcspencer commented 3 months ago

Hi @gbica-hzo,

In the current version of the AMS agent, the agent will set the password of the root account on macOS.

This account is disabled by default. However, in v2, you can change this account by modifying the local agent configuration file by following this guide.

— It is worth noting that, currently, the AMS agent does not support setting the password for accounts with Secure Tokens (i.e. FileVault enabled accounts). This is for a few reasons:

For these two reasons, the machine is unable to retrieve the existing password to change the password for FileVault-enabled accounts. However, accounts without FileVault can be changed.

There are a few things are in the pipeline on this one:

Unfortunately today, while you can specify custom accounts, you can only do so for accounts that don’t have FileVault keys associated.

Hopefully AMS v3 will help with some quality-of-life improvements around managing custom accounts for macOS. I’ll make sure to keep you up to date with the updates around AMSv3, and any improvements we make to secure token account management.

Let me know if you have any questions or concerns.

Thanks!

stale[bot] commented 2 months ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 7 days if no further activity occurs.