Tag: MDM

MDM migration with macOS Sonoma at MacDevOps:YVR

Last month I had the privilege to speak at the MacDevOps:YVR conference in Vancouver about an MDM migration I led late last year.

We utilized a new featured Apple added in macOS 14 Sonoma to drive our user experience and had great overall results.

I had a fantastic time meeting so many fellow MacAdmins in person, sharing my experiences and learning from the other amazing speakers.

Read on for my slide deck, a link to the video and an example script…

Continue reading

Changes to launchctl kickstart in macOS 14.4

macOS Sonoma logomacOS 14.4 includes a change that has the potential to impact a number of MacAdmins.

For the past couple years, launchctl kickstart has been widely used in an attempt to fix stuck macOS processes.

This first use came to prominence in relation to softwareupdate but more recently has been used for mdmclient as well.

MDM vendor Addigy even released a free tool, MDM Watchdog that uses kickstart to attempt to automatically remediate these issues.

Read on for details on why this might not work going forward.

Continue reading

Granting Munki Full Disk Access

MunkiMunki has been a staple management tool for many MacAdmins for a decade.

However in recent releases of macOS, Munki needs to be granted Privacy Preferences Policy Control permissions to access certain disk locations or update some apps.

Thankfully this has become very easy in the past year thanks to the MacAdmins community.

Read on for details and an example configuration profile.

Continue reading

Retroactive Automated Device Enrollment in macOS Sonoma

Apple released macOS 14 Sonoma this week, and on top of the numerous consumer facing features, there are also a number of interest to MacAdmins.

What’s new for enterprise in macOS Sonoma

While there are many improvements to features like Declarative Device Management (DDM) and MDM, one of the most interesting to me only got a short mention with no details.

Automated Device Enrollment can be enforced after Setup Assistant.

This feature, which I’m calling Retroactive Automated Device Enrollment, was announced during WWDC and I extensively tested it during the beta cycles.

I think there is some amazing potential here. Read on for details…

Continue reading

This Mac is Locked. Try again in 24,284,826 minutes

My team recently had an unusual MDM lock ticket escalated to us. The user had already been provided with the PIN from our MDM, however the lock screen said they needed to wait 24,284,826 minutes (over 46 years!) before they could enter the PIN.

This was a new one for me so I immediately jumped on the MacAdmins Slack to see if anyone had dealt with this problem before. The fix turned out to be relatively simple, read on for the details.

Continue reading