Skip to main content
This guide applies to Mac computers

About the Create User Accounts Parameter

The Create User Accounts parameter is a Blueprint parameter in Iru Endpoint that can be used to create both Standard and Administrator user accounts on Mac computers. This parameter is especially useful as the user accounts can be created in this state from device setup without the need to change the account ID, location, or modify any permissions after the fact.

How It Works

This parameter creates user accounts during device setup, allowing you to establish both Standard and Administrator accounts without needing to modify permissions or account settings after the fact.
This Parameter will not duplicate or modify any existing accounts. Iru Endpoint will only create the user account if that user account does not currently exist.
After completing the required fields of Full name, Short Name, and Password, you will have the option to select the path to the home folder and the account type. There is also a toggle to create a sub-500 user account.
Updating a user password in this parameter will not update a password for an existing local user. To rotate an administrator password, set Initial password in the LAPS Library Item to the password currently on the Mac. LAPS then takes over that account, replacing the password with a unique one on each Mac and storing it securely in Iru on the schedule you set.

What is a sub-500 hidden user account?

A sub-500 Hidden Account is an account that is created with a UID (User ID) with a value of less than 500. Accounts with a UID lower than 500 are hidden in multiple parts of macOS. Accounts with a UID lower than 500:
  • Are not shown at the macOS List of Users login window by default.
  • Are hidden from the fast user switching menu.
  • Are not shown in System Settings > Users & Groups.

Why should I place a hidden account in /private/var?

When you place a User Account’s home folder in /private/var, you ensure that the home folder is not in a place that another user might see, such as the /Users folder.

How can I log in with a Hidden Account at the macOS Login Window?

If your macOS devices use the List of Users Login Window style, then you may be unsure how to log in with a hidden user account. This can be done at the login window by pressing the following keys.
1

Press Down Arrow

Press the down arrow key.
2

Press Option + Return

Press Option + Return (Enter).
3

Enter Credentials

A username and password field will appear where you can log in with your hidden user account.
For more detailed information on Parameters, see the Parameters section of our Knowledge Base.

How do I unlock a FileVault 2 encrypted Mac with a user created by the Parameter?

When the Iru Agent creates a user based on the “Create user accounts” parameter, it does not automatically grant that user a secure token. This means that you cannot use these user credentials to unlock FileVault after a Mac restarts. You can enable a user for FileVault with the following steps:
1

Open FileVault settings

In System Settings, select Privacy & Security > FileVault.
2

Enable users

Select Enable Users.
3

Enable a specific user

Select Enable User for the user.
4

Enter the password

Enter the password, then select OK.

Configuring Parameters

Configure Blueprint Parameters, including Create User Accounts.

Configure the LAPS Library Item

Rotate passwords for local administrators created by this parameter. LAPS does not create accounts.

Configuring Apple Enrollment

Provision a local administrator (Auto Admin) during Automated Device Enrollment.

Configure FileVault

FileVault encryption and recovery keys on Mac computers.

Demote User Accounts to Standard

Convert local administrator accounts to Standard users after they are created.

Configuring Blueprints

Group devices and assign Parameters and Library Items.