Jump to content

Recommended Posts

Posted (edited)

Dear Edugeek Community,

 

One of the schools in our Trust has a large number of domain-joined Mac devices running OSX in their fleet.

 

In the main, things work well, but one residual problem that keeps occurring is around the Keychain feature of OSX.

 

Whenever an administrative password change takes place, however it is done (any way except a user doing it on their OSX console), the next time they log in the user sees a prompt asking if they'd like the operating system to Reset their Keychain. If they click Reset, everything works fine, but very often they click 'Cancel' and things are then not fine.

 

There are several immediate reflections here, not least that Apple is not properly geared up for corporate networks, but that's by the by as we are where we are. Another is that it is unavoidable needing to do administrative resets in any user community, let alone one where over a thousand young people are involved.

 

We've tried putting up posters, attempting to education staff and students, but to no avail. We have tried running some Powershell behind the scenes upon resetting the password (to bin out the Keychain directory), but it takes several seconds to run and in a classroom environment, this is an age and would not be tolerated. We could also bung in a Powershell element to run 'later' into a database and pick this up on a cronjob, but this would take even longer.

 

There is another post on here that discusses stripping out the Keychain directory during a holiday-period mass password reset exercise and I could achieve this perfectly easily, but it would not solve the post in-class password reset impact of the OSX user experience.

 

Has anyone found a satisfactory solution to this conundrum? It seems to me that there should be a GPO equivalent policy that would force the O/S to assume the user wishes to Reset their Keychain and not prompt them to make a decision. Does such a thing exist?

 

Any thoughts gratefully received!

 

Richard

Edited by rjmayer
Posted
The issue becomes worse with forced password changes when staff are using Mac's with Outlook, OneDrive etc. You can't simply delete the keychain. It helps that Mac's are being used 1:1 in this scenario. When a password is changed users have to update the keychain password. I can't see a way around this.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...