PreStage Enrollment: Users Are Not Volume Owners on Computers with macOS 11.5–12 when the Recovery Lock Password is Set During Enrollment (PI-010304)

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Symptoms

Note:

PI-010304 was resolved in Jamf Pro 10.35.0. Jamf recommends upgrading to Jamf Pro 10.35.0 or later.

If user accounts on computers with macOS 11.5–12 were recently enrolled in Jamf Pro 10.32.0–10.34.0 and cannot authorize changes to local policy on their computers, allow software updates or kernel extension management, volume ownership may not be enabled for the user accounts. When computers with Apple silicon enroll via a PreStage enrollment and the Recovery Lock password is set during enrollment, user accounts are not volume owners in the following circumstances:
  • A computer with macOS 11.5–12 enrolls with Jamf Pro 10.32.0

  • A computer with macOS 12 enrolls with Jamf Pro 10.33.0

Volume ownership is required for users to authorize changes to local policy on computers with Apple silicon, and to allow software updates and kernel extension management.

Solution

To ensure user accounts on computers with Apple silicon and macOS 11.5–12.0 can be volume owners, you must do the following:
  1. Identify which computers have user accounts that are not volume owners.

  2. Erase and re-install macOS on the target computers. This will install macOS 12.0.1 on the computers.

To enroll computers with Apple silicon and macOS 11.5–12.0 via a PreStage enrollment, set a Recovery Lock passcode, and enable volume ownership for user accounts, you can set the Recovery Lock password after enrollment using the Jamf Pro API.