With macOS, administrators can deliver a Device Setting (aka payload) that can change settings for just a single user or the whole device. This article will cover what to consider when using user channels for settings management in macOS as well as the payloads supported by this.
User Channel Considerations - Managed Users
The first user created on the device (or the user currently logged in during enrollment) generates a unique token to allow for communication over the user channel. This token is then received by Addigy and stored for delivery of the payload to that specific user. It is important to note that a user must have this token generated and uploaded to Addigy in order for the account to work properly during deployment.
For devices that are bound to a directory service, like Active Directory, all network and mobile users are enabled for user channel payloads.
For devices that are 10.12 or newer and not bound to a directory service, there can only be one managed user that can have this user-based token. Changes to which account has user channel enabled will disable the previously working user account. Changing which user has this token requires the removal and reinstallation of the payload on the device.
Device Settings That Support User-Based Deployment
For the most up-to-date information on these and other payloads, Apple has documented each settings payload here. Simply search for the name of the payload, such as 'SCEP', and view the "Profile Availability" section of the page to see if the payload can be deployed via User Channel.
Deploying User Channel Payloads to Devices
For steps on how to deploy an eligible Device Setting via User Channel, please reference our other article. How to Deploy User Channel Device Settings on an Individual Device