This software simplifies the process of granting local administrator privileges to the user currently logging into the computer.
To ensure that the user has the necessary permissions, the software checks if they exist in Open Directory and are part of a group named 'administration'. It is crucial that the group name is an exact match, without any quotes. If the user is a member of this group, they are automatically added to the local admin group on the computer they are logging into. This enables them to perform local admin tasks on the workstation.
Once you remove the user from the Open Directory administration group (and they log out), the software will also automatically remove their local admin privileges from the workstation. Thus, it enables dynamic assignment of admin access without requiring manual intervention on the individual machines.
This software is compatible with Mobile Accounts (PHD's). If you want to create a mobile account for a user via Workgroup Manager, this tool will also make them a local administrator on their computer without needing to check the box in System Preferences.
In case you want to revoke their admin rights, you can remove the user from the Open Directory administration group, and after they logout and log back in, they will no longer have local admin access. However, the first user created with a UID of 501 is an exception to this script, and it cannot be used with this software tool.
Overall, this package installer is a useful and time-saving solution for granting dynamic and controlled local admin privileges.
Version 3.1: N/A