You can create a managed local administrator account, also known as the "managed administrator", and configure the local account information for the primary user during Automated Device Enrollment.
On computers with macOS 10.15 or later, you can also configure the following:
Pre-fill the primary user's local account full name and account name. If your environment includes an LDAP or cloud IdP server, you can enter user variables. You can also prevent the enrolling user from editing this information during enrollment.
- Managed administrators can receive a secure token during login if a Bootstrap Token is escrowed to Jamf Pro.
For more information, see Use secure token, bootstrap token, and volume ownership in deployments in Apple Platform Deployment.
For more information about how to manually create and escrow the Bootstrap Token on the computer and to allow Jamf Pro to store the token, see the Manually Leveraging Apple's Bootstrap Token Functionality article.
To enable the user variables to populate with the value for the LDAP or cloud identity provider (IdP) attribute, you need an LDAP or cloud IdP server configured in Jamf Pro. For more information, see LDAP Directory Service Integration and Cloud Identity Providers.