r/macsysadmin

▲ 19 r/macsysadmin+1 crossposts

Coming from Intune, how hard is it to ramp up on Jamf?

My current environment is Windows only and managed in Intune. Leadership wants to start supporting MacBooks and is planning to use Jamf. I have experience bringing Macs into Intune, but I have never used Jamf. They also mentioned possibly Kandji. How hard is it to ramp up on Jamf Pro if you are already coming from an Intune background?

reddit.com
u/SeanTechGuy — 1 day ago

Disabled network access remotely

Hey all,

I’m a desktop engineering manager for a large university. We’ve got about a thousand Macs. Before I arrived on the scene, our enforcement of macOS minor and major updates was at best a suggestion. We’re got several hundred Macs that are on OS’s that no longer receive security updates (and even more that are going to lose them once Sonoma goes end of life). We’re getting aggressive now, and have notified users of Macs on Ventura and below that they either need to upgrade to a supported OS or replace their Mac this fall. If they fail to do so they will lose access to the University network.

This is all good and well…except I’m wondering how we’re going to implement this. On the Windows side we’re going to use Group Policy to basically force Windows Firewall to block all traffic, in and out. I’m not sure how we’re going to implement this on the Mac side and am looking for suggestions.

My first thought was simply to create a configuration profile in Jamf to turn on Firewall and block all traffic…but it looks like I can only do that for incoming traffic. While this will break some things for users, it won’t actually stop outgoing traffic.

My next thought was to write a script to disable all network cards. This will certainly work…but I’m not so sure we’ll be able to prevent a crafty user from re-enabling them. Our users don’t have admin rights, but we do use Cyberark, which will just temporarily grant them elevated rights to re-enable their network cards.

Could also block MAC addresses at the switch….but all they’d need to do is use someone else’s dock, or a USB Ethernet/wifi adapter.

Any suggestions are greatly appreciated.

reddit.com
u/DTDude — 1 day ago
▲ 30 r/macsysadmin+2 crossposts

Jamf vs Mosyle vs Intune-only for a 28-Mac consulting firm — genuinely stuck, would love real-world input

We're a small ERP/SAP consulting firm — 43 total devices (28 Mac, 15 Windows). All Apple Silicon (M1 through M5), all running macOS 26.5.2. Microsoft 365 Business Premium with Intune. Entra ID joined, Conditional Access enforced with MFA. Leadership is leaning toward Windows standardization long-term, but no final decision has been made on the Mac fleet We're committing to roughly a 1-year Mac MDM investment while we evaluate the long-term direction. No new Mac purchases in the interim, but we're not forcing replacements either.

I've spent the last several weeks doing a genuine hands-on evaluation of all three options — not just demos, actually building out each platform and hitting real walls. Here's what I found.

What's working fine in Intune for Mac:

  • ADE/zero-touch enrollment
  • PPPC profiles, Defender, compliance policies
  • Conditional Access feeding correctly from Intune compliance status
  • FileVault key escrow
  • Await final configuration

The real problems I hit with Intune on Mac — all firsthand, not theoretical:

1. Platform SSO / one-password login is broken under MFA Password mode completely fails when MFA is enforced — which it is in our environment. Tested this extensively across multiple wipes. Secure Enclave mode works with MFA but gives you Touch ID-first, not "type your Microsoft password." Users end up with two passwords that drift out of sync. When the M365 password changes, the Mac local password doesn't update reliably.

2. Local admin password (LAPS) desync on Apple Silicon The admin password Intune shows and the password actually on the device go out of sync randomly. This has happened on multiple machines. Root cause appears to be the Secure Token limitation, Intune's managed admin account doesn't hold a Secure Token, so password rotation can break. Causes "admin password not working" support tickets that take real time to resolve.

3. No automatic third-party app patching Chrome, Claude Desktop, and any non-Microsoft app requires manual repackaging to update. Users get admin prompts for updates and call IT. This was the original trigger for the whole evaluation.

4. No privilege elevation on Mac EPM is Windows-only. Confirmed with Microsoft documentation, the June 2026 EPM updates did NOT add macOS support despite what some sources claim. Standard users needing to install or update certain apps require IT involvement every time.

5. No scheduled recurring restarts No native UI, requires custom shell scripts checking uptime. Manageable but not clean.

Given what I have had issues with thusfar, which MDM would you recommend. Ive stood up instances on quite a few platforms, Mosyle, Jamf, Intune and IRU. Iru is out of budget for 30 Mac devices with EDR and Vulnerability protections since they have a 50 device minimum (although it was my pick). What would you recommend I chose?

My specific questions for the community:

  1. For those running Jamf or Mosyle alongside Intune for a mixed fleet: is the operational overhead of two MDMs actually a problem at this scale, or is it manageable?
  2. Has anyone gotten Platform SSO with Microsoft Entra to work reliably on Apple Silicon with MFA enforced? Which authentication method and which MDM? This is my biggest unsolved problem.
  3. Anyone using Mosyle specifically, does their App Catalog actually solve the third-party patching problem cleanly, or does it still require manual intervention?
  4. Has the LAPS/Secure Token desync issue on Apple Silicon been resolved in any MDM, or is it a fundamental Apple limitation regardless of platform?
  5. For those with compliance obligations (SOC2 specifically) how are you handling vulnerability management and EDR on Mac? Is anyone using Jamf Protect or Mosyle Fuse for this and how does it compare to Defender for Endpoint on Windows in terms of visibility and remediation depth?

Happy to answer any questions about our setup. Genuinely trying to make the right call here rather than just go with the vendor who showed up most persistently.

reddit.com
u/jaylenabc — 2 days ago

How do you manage lab machines in Intune? Groups, naming, tracking

I was talking with my team yesterday and they think i may be overthinking this. I am working on setting up a macOS lab and it has gotten me to thinking. How do you track your non user affinity shared work stations in Intune. How do you know where they sit? If information security wants to track that mac, how do you manage that inside of Intune?

With user affinity we can track that to a user. With shared labs, its not that easy. I setup a device enrollment profile, then went ahead and then created a dynamic group that is based off that. The one person i work with said that would be to much work to scale. Another said to rename it it, which is another idea. I Just want to automate this and have it automatically pull in everything it needs. Am i over thinking this?

I just want to understand ways of doing this that other have implemented.

reddit.com
u/GromWYou — 1 day ago
▲ 37 r/macsysadmin+2 crossposts

Thank you guys.

I just want to thank this subreddit for the people in here who have used Mactoy as a way to create Ventoy disks on MacOS. Special thanks to those who have submitted Github issues for the issues that my first couple releases had. I think my one post here is a large portion of the 40+ stars on github my tool now has, and it's by far my most popular repo at this point. As a newer developer, having people actually use my stuff for real work warms my heart.

As I've gotten older, I've begun to realize that probably my greatest joy and fulfillment comes from feeling helpful and useful. Thank you guys for making me feel that way.

github.com
u/cashy57 — 2 days ago
▲ 4 r/macsysadmin+1 crossposts

Windows Client for VNC to macOS, what do we like these days?

I have been using RealVNC, but their newer versions are junk so I'm looking for something to replace it.

I want to keep using VNC as the protocol of course since it's already built into my lab Macs, so I'm looking for recommendations for a new VNC client for my company issued Windows laptop.

Free and open source are preferred, but not strictly necessary. Bonus points if your recommendation only needs the Mac user ID and password to login as I prefer to not add a VNC password to all my machines.

reddit.com
u/Paul-E-L — 2 days ago

Anyone have any experience with enabling "Accessibility" permissions for a MacOS app, using DDM in Intune?

I'm testing a new MacOS Configuration Policy using Declarative Device Management to control an app's "Accessibility" permission, as it seems that the previous Accessibility control in the Settings Catalog, in PrivacyPrivacy Preferences Policy Control (often abbreviated as PPPC) has been deprecated, and will not work in new versions of MacOS going forward.

Because this setting is so new, I haven't been able to find any guides with examples online.

I'm trying to set up a test for a user using the app "BetterDisplay Pro", which requires "Accessibility" permissions to function.

I'm trying to follow the instructions in Intune itself, but I'm not 100% sure I'm formatting it correctly.

Under DevicesMacOS DevicesManage DevicesConfiguration, I am creating a new Policy, with a Setting Catalog Profile Type.

Under Configuration SettingsDeclarative Device ManagementApp SettingsPrivacyPermission Defaults,

I have set the following settings:

Accessibility : Allow
Organization Justification : [Because it's required]
Permission Defaults : "pro.betterdisplay.BetterDisplay {anchor apple generic and identifier "pro.betterdisplay.BetterDisplay" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "299YSU96J7")}"

In that complicated Permission Defaults field, I'm told by the Intune help text that the data should be in the format:

"Bundle-ID {Designated Requirement}"

I've sourced the information for Bundle-ID from the CFBundleIdentifier Key in the app's Info.plist file in the Package Contents of , and I've sourced the {Designated Requirement} from the output of the Terminal command codesign --display -r - /Applications/BetterDisplay.app, which returns:

>Executable=/Applications/BetterDisplay.app/Contents/MacOS/BetterDisplay
>designated => anchor apple generic and identifier "pro.betterdisplay.BetterDisplay" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "299YSU96J7")

Is my understanding, approach, and formatting correct?

I'm not sure if the Permission Defaults field should have the double quotes or if the double quotes are just to clarify the Microsoft help text, but I've tried both ways and have achieved the same results.

If I view the Report for the Configuration in Intune, I get the following:

Succeeded: 0
Error: 0
Conflict: 0
N/A: 0
In Progress: 0

The one user in the Assigned group shows:

Check-in status: Unknown

Meanwhile, I also created a DDM policy for MacOS updates around the samr time for the same user, and it applied almost immediately, and I see it has "Succeeded".

It's also been more than 72 hours since I first created the policy.

reddit.com
u/ZippyDan — 3 days ago

Former employer never collected my M1 MacBook after 2.5 years — what can I actually do with it?

Hey guys, bit of a weird situation.

Around 2.5 years ago I worked indirectly for one of the FAANG/MAANG companies through another company. I was there for only around 50 days and was issued an M1 MacBook for work.

When I left, I asked them multiple times to arrange pickup of the laptop, but for whatever reason it never happened. Nobody followed up afterwards either. The MacBook has basically been sitting unused at my home ever since.

I don't want to sell it or make money from it. At this point I'd just like to either finally return it or, if they've written the asset off and are okay with me keeping it, use it myself.

I've contacted the company again asking them to either collect it or confirm whether it has been written off/released.

My technical question is: what security layers could still be present on an M1 corporate Mac after this long? MDM, Apple Business Manager/DEP, Activation Lock, FileVault, Recovery Lock, etc.?

Is there a safe way to check what it's currently enrolled/locked with before erasing anything? And if the company formally releases the laptop to me, what would they need to remove on their end so I can completely erase it, reinstall macOS and set it up as a normal personal Mac?

Also curious whether anyone here has dealt with a similar forgotten company asset after leaving a job.

reddit.com
u/_Rohil__ — 5 days ago

Macbook Air only boots to Macintosh HD/Options screen.

Hey all, I'm not entirely new to Mac stuff, but I'm also not great with it. I do tech support at a University and I've got a Macbook Air here that will only boot to the Macintosh HD / Options screen. Selecting Macintosh HD only reboots and comes back to this screen. Holding shift to boot into Safe mode does absolutely nothing when I click the button. I've tried reinstalling Sequoia a couple of times and that hasn't made a difference either. It's like it's not being told to boot from the hard drive.

What other options can I try? Thanks.

reddit.com
u/Durghan — 5 days ago

Enrolling an Apple TV to ABM

Hi all,

My company just purchased some Apple TVs from Costco under the assumption that we could enrol the devices into our Org on ABM using Apple Configurator on a Mac.

This is the 4K Ethernet model which does say on their website that it is able to be enrolled.

What I’ve been doing:
I plug the Apple TV in to HDMI, power, and Ethernet. I plug my Ethernet into my MacBook. And then open Configurator. Nothing shows up and then when I go to paired devices, once again nothing shows up. At one point during troubleshooting the Apple TV showed up very briefly under paired devices as being able to be connected to and it gave me the verification PIN. After inputting the code, verification failed and I was put back to square one.

I am monitoring through my terminal the mobdev protocol, I can request the DNS information on the Apple TV and get its IP, Hostname and some other info. But mobdev has never shown me any results except for the one time the Apple TV decided to show itself.

Lastly, I tried doing this on both a managed and unmanaged network and I think I’m losing my mind. I called Apple Business Support and they were exactly 0 help.

Any ideas or thoughts?

reddit.com
u/Limp_Substance4433 — 6 days ago

Removing EFI password from recycled A1708 macbooks.

Hello,

I have a bunch of recycled laptops from a school. I heard there is a way to remove the back plate, connect a device and flash the motherboard to completely remove the EFI lock WITHOUT needing to replace/solder anything.

Is this true? Or is chatgpt lying again.

Here is something I think I found.

https://ebay.io/m/IgKUj0

Also, it is removable, what about the MDM lock?

Thank you!

reddit.com
u/shatteringreality2 — 5 days ago

help with downloading with terminal

I just tried downloading an app with terminal and after I load the code it beeps few times and nothing after. Blank. I even tried enabling all the encoding and tried it again. Nothing is happening. Do I have to open the terminal with administrator like I used to do in windows or what?

Thanks

reddit.com
u/Orange-Psychological — 7 days ago

ClickFix on macOS after the Terminal paste-block: what actually changed and what it doesn't cover

No product pitch here — posting because we keep seeing this in the wild and the fleet-side mitigations aren't obvious.

Short version of where things stand:

  • Apple added a mitigation in macOS that blocks commands pasted into Terminal from being executed straight away. It kills the most common ClickFix flow (fake CAPTCHA → "press ⌘V then Enter").
  • It does not cover variants that avoid Terminal entirely. We've seen the applescript:// route used specifically to sidestep it.
  • The payload in most of the cases we've looked at is an AMOS-family stealer. Keychain, browser cookies, crypto wallets. On a managed fleet the interesting part isn't the theft, it's that some builds now ship a backdoor component, so it's persistence, not smash-and-grab.

What we'd suggest checking on your side:

  • Alert on osascript spawned from a browser process
  • Watch ~/Library/LaunchAgents and /Library/LaunchDaemons for new plists written outside your deployment window
  • Curl/wget to raw IPs from user context is still one of the higher-signal, low-noise detections here
  • User comms: the "paste this to fix your browser" pattern is worth putting in your next security note. It reads as legitimate troubleshooting to non-technical staff

Happy to share hashes/IOCs from the samples we've analysed if that's useful to anyone. What are you seeing on your fleets?

reddit.com
u/moonlock_security — 6 days ago

iOS mdm server certificate invalid error

iPads still running iOS 17.x have recently started seeing the following error during initial setup:

>“The configuration for your iPad could not be downloaded from xyz. The MDM server certificate for https://url/zdm/ios/otae/dobulkenrollment is invalid.”

Interestingly, both newer and older iPads running iOS 17.x are experiencing the issue after a wipe, whether the wipe is performed through MDM or via an iTunes restore.
All other iOS devices running iOS 18 and iOS 26 are enrolling successfully after a wipe.

The DEP token is valid, and these devices are enrolled through ADE. Has anyone seen this behavior? Any thoughts or suggestions on what else we should check?

https://preview.redd.it/e501uls5r0jh1.jpg?width=2018&format=pjpg&auto=webp&s=80790b7037d7160ae3820943a05e0d87728e3bfb

reddit.com
u/vellostha — 7 days ago

Are there any reliable options for Find My-style tracking while using an MDM?

Hi all,

New-ish Mac sysadmin here. I work for a company that supports field staff who work in potentially dangerous roles. They use iPads, and before I arrived, a Find My system using individual Apple accounts had been loosely set up so that operations could track the location of all field staff from a single Find My map.

For obvious reasons, I wanted to move all the iPads onto an MDM, and Mosyle was chosen. The big problem is that you can’t use Find My with Managed Apple Accounts.

I also wanted to avoid using non-managed Apple accounts, as each one requires a unique phone number.

Is there ANY solution for free, near realtime location tracking with this configuration?

I’ve tried Google Maps, but it seems to lose the location sharing for each iPad after a while, even when set to share indefinitely. It also requires a Google account for each device, which again requires a unique phone number.

Surely there must be some way to do this without paying for a dedicated tracking service or having to create a bunch of personal/non-managed accounts?

reddit.com
u/Delicious-Leg1641 — 7 days ago

Is there a way to prevent a user from unenrolling from the MDM profile?

We are a relatively small company and have been trying to move all our devices into ABM so that we have more control over the device. We have been making an admin account, then making the user account, then downloading the MDM profile from ABM. The issue we are having is that then the user needs the admin password for every little thing, even changing the sleep timer in settings, or downloading apps from the internet (this one I understand more than the settings)

If we add the device with Apple Configurator, the user can simply unenroll from the MDM profile.

I read on a post from 3 years ago that this is only possible for the first 30 days, and after that it can only be removed from ABM, is this still the case? We can’t test it because all previous devices have been added via the first method I mentioned.

We are about to upgrade devices and will be doing this 40+ times, so we want to make sure we do this in a way that doesn’t cause headaches for our employees but also secures the device.

Any help would be appreciated!

reddit.com
u/Daniel_Boomin — 10 days ago

Mac registration, intune registered but non-compliant in Entra (Error 530003)

Hi everyone,

I currently have two Macs, appearing both with the same kind of issue within the last few weeks.

Current status

The first Mac with that kind of issue appeared Mid July, the second one today Mid August
Both Macs are:
- enrolled in Intune (User Approved MDM)
- visible in Entra ID
- Marked as Compliant
- Visible under My Sign-Ins with a Device ID
- Company Portal is installed and working
Only one is DEP enrolled, the other one is not (only added into Intune)

When the user signs in into a specific m365 App (on one Mac it’s only Teams; on the other one it’s only OneDrive), he needs to login with his credentials and afterwards gets a notification to setup devices and get redirected to
portal.manage.microsoft.com/EnrollmentRedirect.aspx

Entra says 530003 - Your device is required to be managed
and the same login shows:
- Device ID: empty
- Managed: No
- Compliant: No
- Device: Unknown

Things I've already checked:
- Device exists in Entra ID and in Intune
- Intune Compliance is Yes
- Company Portal works and checks in
- MDM status is User Approved
- No enrollment errors

We currently don’t use PSSO for macOS but I also checked for some configurations just in case and found nothing obvious.

Very strange is that all the other Office apps are working fine, for example Excel and Outlook sign in fine without any issues.

The issue appeared on macOS 26.2 in July and also on 26.5.1 today.

CA

Only the Compliant Device Conditional Access Policy applies to that registration, nothing else. Since the device doesn’t report a compliant device back to Entra, access is denied for these specific apps.

Thoughts

Has anyone seen something similar on macOS recently?
Something with Device claim issues, Broker / OneAuth problems, Teams or OneDrive authentication bugs…

Of course deleted different caches, re-enrolled, restarted an updated, check certificates in keychain,… nothing helped yet (maybe you will say I should try it again, then I’ll do ;))

Any ideas would be very appreciated. Thanks all for thoughts and help! May start a discussion too!
Chris

reddit.com
u/OkLibrary4339 — 9 days ago

The adobe tax is finally breaking my spirit

Deploying acrobat in our mac environment is literal hell. I spend half my week troubleshooting creative cloud login loops or dealing with finance users who think they absolutely need a massive enterprise license just to combine two damn invoices

Management finally agreed to slash the software budget. Ended up dropping Xodo onto the finance fleet via Kandji yesterday. Honestly just relieved the silent install didn't fight me and there's no 2gb background updater eating the cpu

of course, one of the directors is already submitting tickets because the buttons are in different places than her 2019 acrobat install. Im just leaving it on read until monday. I don't get paid enough to be a pdf tour guide.

u/nibbainmybuttholr — 13 days ago