Locking Out OS X Rights

Hi everyone, thanks for any help on this. Currently we have all of our users that have OSX set as administrator users. According to the policies here they have the ability to update their software as well as update the installed Adobe products and other programs they use.
We now have a new requirement that they need have the firewall and an antivirus program enabled and that they can't disable or uninstall either.
I'm doubting this but kind of grabbing at straws, is there anyway to still have the users as administrators where they can update their software but limit the ability to change anything with the firewall or antivirus.
Currently we are running on both 10.6 and 10.7. I've played around with the authorization file and I can give a standard user rights to software update but that is only for the installed apple products/os and excludes the other products that they need to install.  http://mattsmacblog.wordpress.com/2011/07/30/mac-os-x-10-7-lion-first-look-at-et cauthorization-usage/
Again, thanks for the help.
Mike

> 'm wondering if I can turn everything off in the firewall except SSH and open up other services only as needed?
That is the default. The server enables specific ports as needed, based on the services you're running. Therefore the active set of rules should be pretty tight.
You can check the current settings by running:
<pre class=command>sudo ipfw show</pre>
If there are some allow rules there that you don't understand/expect, post them here, otherwise rest assured it isn't in Apple's interest to blindly open ports that are not necessary.

Similar Messages

  • HT1212 Right, home button broken, locked out. Help... i need to access the recovery mode

    Right, home button broken, locked out. Help... i need to access the recovery mode

    Place the iPod in recovery mode using one of these programs:
    For PC
    RecBoot: Easy Way to Put iPhone into Recovery Mode
    If necessary:
    Download QTMLClient.dll & iTunesMobileDevice.dll for RecBoot
    and                         
    RecBoot tip
    For MAC or PC       
    The Firmware Umbrella - TinyUmbrella

  • HT201380 OK... I updated all "asked" items. Now I am "locked" out of my iPhoto. Any help PLEASE! I'm out of the USA right now, but it had been working fine up until today.

    How can I get into my iPhoto ?
    I updated ALL required updates and now I'm "Locked" out of iPhoto, saying I am "still" updating, but the App. Store says I am ALL updated?
    Thanks!

    Phillip...
    Tap Settings > General > Reset > Reset Network Settings
    Then restart the iPhone.
    If that didn't help, try here >  iOS: Troubleshooting Wi-Fi networks and connections

  • Unity Connection - Users with system default password getting locked out

    Hi all, hope everyone is well !!
    I am experiencing a strange problem and hope someone can give me some direction on where to start digging on this issue.
    I am getting a good number of users reporting they are getting locked out of their voice mail and they all claim that they have not changed their password and some user even got their greeting recorded by someone else. One thing in common for the users who reported the issue is that they all using the system default password. I am trying to trace to find out who/what has access to these users' mailbox but so far I have not had any luck.
    Thanks in advance !!
    Danny

    Thanks, yes am doing that now and cant really find any new/unique pattern. Plus the trace is pretty hard to follow. Cant really figure out any times stamps in the trace also. The current trace file is defaultTrace.18.trc and it has very simiiar content as some of the older ones before the problem. Right now the ESS portal is working and the slddsuser password is not locked. It seems the problem takes place on start up?
    /usr/sap/ESS/JC77/j2ee/cluster/server0/log
    Tough thing to test in production.
    I wonder what takes place at startup that would kick this problem off?
    brad

  • Locked out of my iPhone 4 but iTunes won't let me restore it. Help!

    I'm locked out of my iPhone 4 but when I try to connect it to iTunes to unlock and restore it, iTunes is requiring me to enter my passcode on my phone, which the phone won't let me do because I'm locked out. Help please!?

    You need to restore using the computer you previouisly synced with, otherwise you'll be asked for the passcode.
    You didn't forget your passcode (that you use every day) AND lose the computer you sync with on the same day, right?  In that case, get the passcode from the phone's actual owner, or use recovery mode.

  • I am locked out of my internal hard drives.

    Sorry if I am breaking protocol. This question is for V.K. Ihad been locked out of my internal drives with the exception of my start updrive. All the drives icons had a small lock on them. You had posted how tounlock them.
    run the following commands in terminal
    sudo chflags 0 /Volumes/*
    sudo chmod a+x /Volumes/*
    you'll have to enter your admin password (which you won't see)after the first command. that's normal. this should unlock the drives.
    I tried it and now I am locked out of all my drives. I nolonger have drive icons, I have folder icons with a red dot with a slashthrough it in the bottom right.
    Very scared and very desperate. Please help

    Thank you V.K. and ignore the question. When I posted my question, similar asked questions popped up. You had already answered it and it worked. That was the end of a very long and frustrating weekend. Thank you.

  • My daughters IPod Touch is disabled.  How do I get it back to working? She did forget her passcode and was locked out

    My daughter made up passcodes and kept changing them and then forgot what her last one was so she was locked out. Her IPod now says "IPod is disabled" - how do we get it started up again?

    This is asked and answered many times every day.
    The forums search bar and More Like This section are on the right side of this page.
    Put it in recovery mode - described here:
    iOS: Unable to update or restore

  • Locked out of mail have to unlock every time I try to access it.

    I have been using my mac (mini) for a couple years and have always had macs, so I;m not an idiot (meh)…Just recently I have been locked out of my mail every time I try to use it, with either "disabled for security reasons" or "unable to connect to iCloud.." This is a personal computer…no network to deal with, just me, my iPad and iPhone. It is really really annoying. I have reset password, checked iCloud preferences to make sure my primary email address is the right one, and still have to unlock every time on every device. I have 3 accounts as I am old and have been through the @mac, @me and @icloud. I know I am missing something that is probably simple, but for the life of me I can't figure out what. When I go to unlock it everything works fine, but I have to do this constantly. I have never been asked to do this before the last 2 weeks, now it is ever-present. @mac has always been my primary email…it has never been changed (by me). I am lost,
    please advise
    Thanks

    This is on my iPad

  • I have been locked out of my iTunes account. How do I unlock it?

    Upon purchasing an album on iTunes, security questions were asked. I could not remember one of the questions and tried multiple times to get it right. I never did. Then, I was locked out of my iTunes account and cannot purchase anything. I remember the answer to the question now but it won't let me try to answer it anymore.

    Contact iTunes Customer Service and request assistance
    Use this Link  >  Apple  Support  iTunes Store  Contact

  • I am locked out of my ipod touch and forgot the password.  How can i get into it without restoring it?

    I have gotten locked out of my ipod touch and do not know the password, but my computer cannot restore it, so I need to know how to get in without restoring it.

    PC WAY
    1.Plug the iPod in computer.
    2.Go to "My Computer" And click the apporiate drive your your iPod.
    3.Change the folder option to "View all hidden files and folders"
    4.Navigate to ipod_control
    5.Then go to Device
    6.Then there is a file there named"_Unlocked"
    7.Open that up with a text editor (Notepad) and viola the passcode is right there.

  • Why is my Mac locked out of iTunes Match?

    I spent the $25 to purchase iTunes Match on my family's shared media iTunes account and the day the service went live. I then set it up with our Mac Mini, the computer that serves as our family's media system. The iTunes account in question is relatively new, only a few months old. Prior to that, my wife and I were using our individual personal iTunes account to purchase apps and media. It wasn't until I realized we were going to need an account we could all share that I decided to create a family account. The Friday after Thanksgiving, I wanted to show my kids "The Grinch Who Stole Christmas" while the adults continued their after dinner discussions. A year ago, I bought that television program from iTunes on my personal account and knew that I could now download it through iTunes. But when I switched over to that account to download it, the computer automatically become un-"associated" with my shared account account and "associated" itself with the old account. And now, I cannot use the account that was used to set up iTunes Match, on the computer for which Match was purchased in the first place. As of right now, I apparently cannot re-connect that machine to Match for another ninety days, which is nearly one quarter of the year for which I purchased the Match service.
    I find it troubling that Apple is punishing me for accessing media I have purchased in the past by locking me out of a service for which I have paid. Both accounts are associated with my name, both accounts are associated with the same credit card information, the only thing that differs is that they associated with different email addresses. This all seems very esoteric and not very customer service oriented, and this is coming from an owner of numerous OS X and iOS devices. This is an issue that is going to come up more and more for Apple's customers as more people buy in to the iTunes/iOS/OS X ecosystem and try to make the best possible use and sense out of it all. My attempt to get resolution to my problem through Apple Support was met with a very flowery, "tough ****," from a customer support representative. Neither the choice, nor the response are suitable. What efforts, if any, are being made to try to make this more workable for people like me, trying to make the best decisions while moving ahead in the iTunes ecosystem?
    Is there a fix for this, or am I just going to have to eat it and not use the service I bought, on the computer for which I bought it, for a quarter of the time I paid for?

    I did contact them. I put in a ticket immediately after discovering that I was locked out. I asked for help or in lieu of that, a refund. Two days later a customer support representative contacted me via email to offer nothing in the way of help and to tell me that a refund was not an option per the iTunes EULA.
    I am very disappointed by how this has been handled thus far. iTunes Match seemed like a wonderful service, but being punished for reasons that are entirely unclear, has really soured my opinions about it.

  • HT1212 im locked out of my ipod, and the screen isnt responding when i go to swipe to unlock it or when i swipe to turn it off. But, in the top left hand corner, there is an outline of a box. how do i fix this

    im locked out of my ipod, and the screen isnt responding when i go to swipe to unlock it or when i swipe to turn it off. All of my notifications are there but i cant reply to any of them. My screen is completly unresponsive. But, in the top left hand corner, there is an outline of a box. how do i fix this?

    First, try a system reset.  It cures many ills and it's quick, easy and harmless...
    Hold down the on/off switch and the Home button simultaneously until you see the Apple logo.  Ignore the "Slide to power off" text if it appears.  You will not lose any apps, data, music, movies, settings, etc.
    If the Reset doesn't work, try a Restore.  Note that it's nowhere near as quick as a Reset.  It could take well over an hour!  Connect via cable to the computer that you use for sync.  From iTunes, select the iPad/iPod and then select the Summary tab.  Follow directions for Restore and be sure to say "yes" to the backup.  You will be warned that all data (apps, music, movies, etc.) will be erased but, as the Restore finishes, you will be asked if you wish the contents of the backup to be copied to the iPad/iPod.  Again, say "yes."
    At the end of the basic Restore, you will be asked if you wish to sync the iPad/iPod.  As before, say "yes."  Note that that sync selection will disappear and the Restore will end if you do not respond within a reasonable time.  If that happens, only the apps that are part of the IOS will appear on your device.  Corrective action is simple -  choose manual "Sync" from the bottom right of iTunes.
    If you're unable to do the Restore, go into Recovery Mode per the instructions here.

  • Ipod Touch - White Screen Lock Out - Apple response poor/process inflexible

    Hi
    I have 2 Touchs and one has the random white screen issue. Screens goes grey`white and there's nothing you can do, till what seems like it needs to be recharged. i haven't had this happen when at home and near the 'master dock' .
    I see thats its a prob that is more and more common, and have also seen on other forums that Apple are acknowledging it and in some cases have been providing freebies as sweeteners as well (allegedly).
    So first - does anyone have any 'fixes' - other than what I have seen which is a replacement?
    And secondly this is my 'Apple Service experience so far'
    I called Apple UK support on Thursday morning, and pressed the options for Ipod and then Touch.
    A woman answered and as soon as I told her my issue she advised she was IPHONE SUPPORT ONLY as that was section I had come through to and could not help me. I asked to be put through to relevant help section.
    On hold for a few mins then line went dead.
    Called back - making sure i pressed Ipod Touch options - in case it was user error first time - (it wasn't BTW) anyway got put through to IPHONE support again. This time the woman agreed to help, although i shall temper that by saying that my perception was that she started that day and had a script of 'if x do y' questions.
    I explained the issue and that I had carried out web research. She was very polite but asked me questions I had already answered in my pre amble - i.e. screen is locked out, no response from buttons etc - but I was still asked what happens when you press the power button. Anyway I stuck with it - she then asked what firmware I had, and i advised I just upgraded to 1.2.
    Ah thats the problem - you need to upgrade to LEOPARD (I have Tiger). That annoyed me as clearly thats rubbish and was really her ' ad libbing' I explained I had 2 touchs and other was fine.
    She consulted a colleague and suggested I either send it in or make an appt at my local Apple store. Thats when it really went down hill...
    More disappointed at the process, I called my local store (Regent Street - London) and was advised that the Touch would be replaced under warranty - but that I needed to make an appt to have that done, and no they couldn't make an appt on line (you are warned that up front in the recorded message before you get to speak to anyone). This I find odd - two people from Apple advise I can get a replacement under warranty, yet I have to make an appt - thats not good service.
    As i am nearby, I decide to go to the Apple store anyway. I get same story and ask to speak to the manager. He is very well trained. He says all the diplomatic things, he agrees unit will be replaced under warranty, but says I have to see a technician - but I cant until tomorrow at earliest.
    What then follows is a discussion about the process - his argument is that it allows the customer to attend at a time that suits them (but it suited me NOW - I was nearby). In reality the converse is true you can only chose a slot that suits apple.
    The manager, stated that there are two diff stocks of goods. Items for sales and items for replacement. I suggested that he went to the replacement pile and provided one from that. NBo go - the technical dept could only do that.
    I agree that booking for TECH SUPPORT is a great idea, but for a product replacement under warranty - especially when 3 people (and user forums) had advised this would be the case - this is not good service at all. The manager looked at me and uttered platitudes along the lines of ' thats your opinion', ' you are entitled to think that' - all of them verging on patronising. he even went as far to say that customers like being able to book a slot - erm - they have no choice!
    He advised he 'would take my views on board' and would 'pass them on to the manager' - he was in fact the deputy manager. I left my details and explicitly asked for her comments - needless to say I am still waiting.
    So i feel like I have fallen out with a close friend. I have been an Apple convert for 2 years now and this is our first major falling out. I am annoyed, as a customer, at being treated like this and forced into such a rigid system, and bitterly disappointed that a company that has such a a wonderful end user experience in terms of the products themselves and the sales side should treat loyal customers (in fact any customers) this way when trying to dal with faulty goods!
    So, anyone have any thoughts - agree/disagree - who can I voice this to in Apple - the store doesn't seem to care past lip service!
    I will also try to repost this on the general area if there is one
    Rgds
    Michael

    Hi,
    I used to work at an Apple Store so I have 2 summers of customer service experience under my belt. Let me just say that, yes, I empathize. Some of the store policies are ridiculous, which is partly why I left the company. Well, ok no, I just like to say that that's why I left. I'm actually a student.
    Anyways, whoever told you that you can't make an appointment at the Genius Bar was WRONG. Shame on them. Go to this website (it's just apple.com/uk/retail (and Regent Street's site specifically) and on the right hand side there's a column for you to click Genius Bar Reserve.
    http://www.apple.com/uk/retail/regentstreet/week/20071118.html
    Here's the entire gist of the store policy. The store is obligated to give you a new iPod Touch if there's a manufacturer defect within 2 weeks of your original purchase. You'll still need a Genius Bar appointment, but all they do is take a look at it, confirm that it's a defect, and they'll return it for you (& they'll label it as DOA - Dead on arrival), and give you a new one. Easy.
    I'm guessing you are outside of the 14 day period which is causing you all the trouble. So now we're talking about the year warranty. So you got your replacement iPod touch. Should there still be a defect in your replacement, you still have 14 days from the day you received THAT iPod touch to get a new one. There's a chance that if you talk to the manager (a different one and there are several), he'll hook you up with a brand new iPod touch, without having to go through replacement protocol.
    The manager you talked with sounds like a jerk to me, and believe me, I hate it when Apple employees try to think theyre "all that." We student employees used to laugh at how seriously some employees took it. But really, those guys are there to help you and give you solutions, at least that's the company line. With that in mind, demand them to do what's right. I wish I could actually help you. I used to take care of people in situations like these all the time.
    Good luck.

  • HT5312 I can no longer access my rescue email address.  I have forgotten my security questions so am locked out.  Is there a way round this?

    I have an Apple ID which I use for itunes.  I cannot now access the rescue email account I gave when registering.  I have forgotten my security questions and they keep sending emails to the email address I can't access and now I am locked out. 

    If you don't have accessto your rescue email address (you won't be able to change it until you can answer 2 of your questions) then see if this user tip helps : https://discussions.apple.com/docs/DOC-4551
    e.g. you can try contacting iTunes Support : http://www.apple.com/support/itunes/contact/ - click on Contact iTunes Store Support on the right-hand side of the page, then Account Management , and then try Apple ID Account Security
    or try ringing Apple in your country and ask to talk to the Accounts Security Team : http://support.apple.com/kb/HE57

  • ActiveSync mail/contacts/calendars removed after Active Directory account is locked out?

    Hey guys,
    Wondering if anybody has seen an issue like this.  This is a new Exchange 2010 deployment (8+ CAS servers) and the devices are all iPhones/iPads running the latest version of iOS (7.1.2).  The CAS servers are behind a load-balancer.
    Basically when a users' Active Directory account is Locked in AD (either manually or by entering the wrong password) their ActiveSync Contacts, Calendars and all Mail folders (except the Inbox strangely!) will be removed from the iOS device within a few hours.  So an account might get locked out at say 6pm, if left locked out by the next morning the ActiveSync account will still be setup on the device as normal, but everything is gone except the mail in the Inbox.  If a user has an iPad and iPhone both will be blanked.
    The behaviour is similar to what is documented here - iOS: How to mitigate a full sync or reload of Exchange account data - however the Exchange servers are not issuing HTTP500 errors as we have captured logging during the window where the device blanks itself.
    Any thoughts would be appreciated!
    Thanks!

    Hello,
    which event ids are shown in the event viewer from the DCs? Or maybe locally also some errors are locked that give some more details.
    If this happens it sounds personally for me that Java is the problem. Have you already opened a call at
    https://community.oracle.com/welcome ?
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://msmvps.com/blogs/mweber/
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.

Maybe you are looking for