Network users set as Administrators cannot allow OS updates
I have (now) multiple users reporting this issue.
We have an Active Directory domain that I set the users to log on with Network accounts (set to mobile accounts, because we had trouble with issues like this in Catalina, too).
I set the users to be part of a specific group allowed to be admins on the mac during the AD setup, I also set Domain Admins to be allowed to administer the computer.
This works for everything but system updates. They can unlock everything in System Preferences, authorize other things like installing software, etc, but when asked to authenticate for system updates it doesn't accept their username or password, nor an AD Domain Admins username and password, we have to come log on with the initial (local) Admin account's password.
Instead they get an 'Authentication is disabled' note in the login prompt and 'ok' is grayed out.
I'd hoped this was a bug in Big Sur that would be fixed, but it's persisting.
This may be specific to M1 Macs, since those are the only Macs running Big Sur in our organization right now that are joined to the domain.
Mac mini 2018 or later