If you toggle privileges and you're using timer and then reboot the Mac - privileges comes back up on login without a timer and user has admin forever
Angelworks opened this issue · comments
I've tested this on MacOS 12.x and 13.x - if you toggle privs - you'll get a countdown timer (if your using one) and if you reboot the Mac - privileges comes back up after login and the user will have local admin forever and no timer.
Do forgive me if this is already logged as a bug - I tried searching and couldn't find anything.
There is an example LaunchAgent available which demotes the user logging in to being a standard user:
https://github.com/SAP/macOS-enterprise-privileges/tree/main/sample_launchagent