Admin Password management (MDM Command - macOS)
What
The Admin Password Management featurecommand inlets FileWave allows administrators to remotely change the managed local admin password on eligible macOS devices enrolledthrough viaMDM. Use it for the admin account that FileWave created during Automated Device Enrollment (DEP). This functionality utilizes MDM commands to securely update the admin account passwordDEP/ADE), without requiringneeding physical access to the device. The admin account must have been created during enrollment using DEP profile options.Mac.
When/Why
When to Use:use this:
EnhancingSecuritySecurityrotation::RegularlyChangeupdatemanaged admin passwordstoonmaintainastrongschedulesecuritythatprotocols.matches your organization's policy.RespondingSuspectedtoexposure:Security Threats: Immediately changeRotate theadminpassword ifasomeonesecuritywhobreachshouldornotunauthorizedknowaccessitismaysuspected.have had access.- Staff
Changeschanges::Updatepasswordsthe password whenpersonnelIT staff with admin access leavetheororganization.change roles. PolicyCompliance:Compliance:KeepEnforcelocalpasswordadminchangescredentialsto complyaligned withorganizational security policiesinternal or regulatory password requirements.
Why Useuse Thisthis Feature:feature:
- Remote
Accessibilitypassword reset::Change the managed adminpasswords remotelypassword acrossmultipleselecteddevices without physical intervention.
How
Prerequisites
DEPEnrollment:Enrollment:TheDevicesMac must be enrolledviathrough Automated Device Enrollment (DEP)DEP/ADE).- Apple OS/
Hardwarehardware::DevicesThe device must be an AppleSiliconsiliconmacOS systemsMac running macOS 15.0 orhigherlater. AdminManagedAccountadminCreationaccount::The admin account must have been created duringDEPDEP/ADE enrollment using the profile options.
Note that ifIf you create the admin account as required for this featurefeature, thenalso you should consider:review Bootstrap Token Management on macOS .
Steps to Changechange the Adminadmin Passwordpassword
- In FileWave
CentralCentral, select thedeviceMac,andthenrightchooseclick ->MDM-> Change Admin Password... from the device context menu.
Important Notesnotes
EncryptionSecureanddelivery:Security:FileWaveThesends the new passwordisthroughsecurely transmitted usingthe MDMprotocols.command channel.- User
Impactimpact::Changing the admin passwordmaycan affectscriptsscripts, services, orservicesworkflows that still rely onadminthecredentials.old credential. CommunicationTeam communication::Consider notifyingTell other IT staffaboutwhen the managed admin passwordchangechangestosopreventtheyaccessdoissues.not keep using the old value.
Common questions
TheIf you are looking for a way to reset a Mac's managed local admin password, rotate a DEP-created admin password, or change an ADE admin account password remotely, use the Change Admin Password ManagementMDM featurecommand empowers administrators to maintain strong security across all DEP-enrolled macOS devices efficiently. By leveragingfrom FileWave Central to manage admin passwords remotely, organizations can ensure compliance with security policies, respond swiftly to potential threats, and maintain centralized control over their device fleet.
By utilizing this feature thoughtfully and adhering to best practices, you can significantly enhance your organization’s security posture while streamlining administrative tasks.Central.