{"id":80912,"date":"2023-05-18T12:51:20","date_gmt":"2023-05-18T16:51:20","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=80912"},"modified":"2024-03-27T09:29:03","modified_gmt":"2024-03-27T13:29:03","slug":"troubleshooting-service-account","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/troubleshooting-service-account","title":{"rendered":"Troubleshoot: macOS Service Account"},"content":{"rendered":"\n
JumpCloud uses a service account on macOS systems to let users unlock FileVault encryption. When you install the JumpCloud agent on a macOS system, it silently creates this system account to:<\/p>\n\n\n\n
The service account provides security-level services to other JumpCloud managed user accounts and has the following restrictions:<\/p>\n\n\n\n
If you\u2019re installing the JumpCloud Mac agent and encounter a failure to create the service account, it may be due to the service account\u2019s restrictions.<\/p>\n\n\n\n
Under all of the following conditions:<\/p>\n\n\n\n
The JumpCloud Service account fails to be created.<\/p>\n\n\n\n
Cause<\/strong> Resolution<\/strong> Keep in mind that Apple only allows an organization to register one MDM solution.<\/p>\n\n\n\n <\/p>\n\n\n\n A macOS device might have an Invalid status because of any of these situations:<\/p>\n\n\n\n Cause<\/strong>
The JumpCloud Service Account generates a very long random password, so when your MDM solution tries to apply a complex password policy, the random password may fail and stop the account from being created.<\/p>\n\n\n\n
We know this is an issue and are working to resolve it. In the meantime, we recommend you use one of the following workarounds:<\/p>\n\n\n\n\n
Known Issue: Invalid Status<\/strong><\/h2>\n\n\n\n
\n
JumpCloud has identified a problem on certain macOS devices where the JumpCloud Service Account is unable to perform necessary tasks related to user management. If the service account is not repaired on these devices, future users added to the machine will not be able to decrypt the disk successfully during login and the JumpCloud agent will be unable to successfully take over existing accounts. Some devices are easily recovered from this state with a local administrator account that has been issued a secure token on the device.
Resolution<\/strong>
There are two ways to resolve this situation:<\/p>\n\n\n\n