10.13.4 beta 3 secureToken dialog

Under 10.13.4 beta 3 on unencrypted AD bound clients, like say an iMac in a research lab, when an AD user logs in it presents a dialog box


Enter a SecureToken administrator's name and password to allow this mobile account to login at startup time.


Prior to 10.13.4 all the secureToken quirks have been gated behind FileVault 2. There is very little documentation on secureToken. Is apple expecting us to station a tech to enter admin passwords of a secureToken enabled user every time a new directory user needs to log onto a client?

Replies

Apple,

This is a step in the Wrong direction, and will cause more problems for our users...

As it stands, we have had to do some script to get a 'management' account with a token that can give out tokens to users with an interactive script...

This confuses users more, as WE CANNOT ALL STAND OVER THEIR DESK AND TYPE OUR PASSWORDS.


Please allow us to disable this ridiculous dialog option at the management level, as you will do nothing but confuse our users.


All you have to do is this--- allow MDM to push out tokens, based on a certificate that we have created and put on the machine with enrollment to our MDM servers... or just quite frankly allow any mobile AD/OD/Directory user to automatically get a token, as these people have ALREADY proven that they are authenticated by our systems.


This secureToken business has been a big, short-sighted joke...

And the sysadminctl binary is still nothing if not 'fragile', and has next to no documentation.

Fix this secureToken garbage asap, or allow us to disable it completely, cuz it does not work well in many enterprise/educational institutions.


ks

We just alerted Jamf Software about this new "feature".


We are also going to send feedback to our Apple Rep and directly to Apple.


Whoever is making decisions at Apple needs to wrap his/her head around enterprise needs.


Between User Allowed MDM Enrollment, now this "Enter a SecureToken administrator's name and password to allow this mobile account to login at startup time" prompt...wow...really?