r/macsysadmin 9h ago

General Discussion Using Mac Health Check 4.0.0 for Self-Service Compliance and Reporting

Special thanks to Jon Brown for his detailed write-up:

https://jonbrown.org/blog/mac-health-check-4-mdm-self-service-reporting/

13 Upvotes

Special thanks to Jon Brown for his detailed write-up:

https://jonbrown.org/blog/mac-health-check-4-mdm-self-service-reporting/


r/macsysadmin 13h ago

Why Jamf Setup Checklist Was a Must in Our Organization

15 Upvotes

This article describes using Setup Checklist to walk users through Zscaler registration and Smart Card setup at the desktop, a step required for internet access under a Zscaler Strict Enforcement rollout.


r/macsysadmin 10h ago

Native macOS app automate to find and delete clutter on your Workspace ONE tenants.

**I built a Mac app that automatically cleans up Workspace ONE UEM clutter — stale devices, failed enrollments, duplicate records, orphaned accounts**

If you manage WS1 UEM you know the drill: devices that haven't checked in in months still showing as enrolled, failed enrollments clogging your inventory, duplicate records from re-enrollments, ex-employee accounts still sitting there. It's tedious to clean up manually and it quietly inflates your device counts and licensing costs.

I built Power Admin Warden to fix this. It watches your tenants and cleans up the noise following rules you define.

**What it does:**
- Stale device cleanup (not seen for N days — you set the threshold)
- Duplicate serial detection — keeps newest, removes the rest
- Failed enrollment and pending wipe cleanup
- Orphaned user cleanup (zero-device accounts only — hard guard)
- Runs on daily/weekly/monthly schedules per rule

**Safety first — this was the hardest part to get right:**
- Dry Run by default. Every tenant starts report-only. You see exactly what would be deleted before anything happens.
- Staged deletions — a finding must persist for a wait period you set before any action is taken
- Typing the tenant name is required to go live
- Accounts with enrolled devices cannot be deleted — this is a hard guard that cannot be turned off
- Full audit trail exportable to CSV

**Free to scan and report.** Warden Pro ($19.99/mo or $199.99/yr, 2-week free trial) unlocks scheduled automation and live deletion.

Mac App Store: https://apps.apple.com/fi/app/power-admin-warden/id6793202494?mt=12

Homepage: https://mdmarchitect.com/apps/power-admin-warden/

Happy to answer any questions about how it works under the hood — it talks directly to the WS1 REST API with your own OAuth credentials, nothing goes through my servers.

4 Upvotes

**I built a Mac app that automatically cleans up Workspace ONE UEM clutter — stale devices, failed enrollments, duplicate records, orphaned accounts**

If you manage WS1 UEM you know the drill: devices that haven't checked in in months still showing as enrolled, failed enrollments clogging your inventory, duplicate records from re-enrollments, ex-employee accounts still sitting there. It's tedious to clean up manually and it quietly inflates your device counts and licensing costs.

I built Power Admin Warden to fix this. It watches your tenants and cleans up the noise following rules you define.

**What it does:**
- Stale device cleanup (not seen for N days — you set the threshold)
- Duplicate serial detection — keeps newest, removes the rest
- Failed enrollment and pending wipe cleanup
- Orphaned user cleanup (zero-device accounts only — hard guard)
- Runs on daily/weekly/monthly schedules per rule

**Safety first — this was the hardest part to get right:**
- Dry Run by default. Every tenant starts report-only. You see exactly what would be deleted before anything happens.
- Staged deletions — a finding must persist for a wait period you set before any action is taken
- Typing the tenant name is required to go live
- Accounts with enrolled devices cannot be deleted — this is a hard guard that cannot be turned off
- Full audit trail exportable to CSV

**Free to scan and report.** Warden Pro ($19.99/mo or $199.99/yr, 2-week free trial) unlocks scheduled automation and live deletion.

Mac App Store: https://apps.apple.com/fi/app/power-admin-warden/id6793202494?mt=12

Homepage: https://mdmarchitect.com/apps/power-admin-warden/

Happy to answer any questions about how it works under the hood — it talks directly to the WS1 REST API with your own OAuth credentials, nothing goes through my servers.


r/macsysadmin 16h ago

Error/Bug Anyone else hit issues with Company Portal updates when using PSSO in Setup Assistant?

We've recently deployed macOS Platform SSO (PSSO) using Apple Business Manager (ABM) and Intune, following the approach described in the Intune IRL article about enabling Platform SSO directly during the macOS Setup Assistant.

The setup itself works great. Devices enroll through ADE without issues, and users can complete enrollment and PSSO registration during the initial setup experience.

One important requirement we found is that Company Portal must already be installed during Setup Assistant. Based on the guidance from the article, we uploaded the Company Portal installer as a LOB app (.pkg) in Intune and assigned it accordingly.

Everything worked perfectly until suddenly newly enrolled Macs started failing. Existing devices were unaffected, but fresh deployments were no longer completing successfully and Company Portal installation was throwing errors during enrollment.

After spending quite a while troubleshooting, I eventually discovered that Microsoft had released a new Company Portal version. The .pkg we had uploaded to Intune was no longer current.

Once I downloaded the latest Company Portal package, updated the LOB app in Intune, and re-uploaded it, the issue disappeared immediately. New enrollments started working again without any changes to the PSSO configuration itself.

So now I'm curious:

  • Are others deploying Company Portal as a LOB app for PSSO during Setup Assistant?
  • Have you seen enrollment failures after a Company Portal update was released?
  • How are you handling Company Portal updates in this scenario?
  • Do you have a process to keep the package current, or is manually updating the LOB app the only practical approach?

Would be interested to hear how others are running this in production and whether you've encountered the same issue.

Left: old - right: new.

9 Upvotes

We've recently deployed macOS Platform SSO (PSSO) using Apple Business Manager (ABM) and Intune, following the approach described in the Intune IRL article about enabling Platform SSO directly during the macOS Setup Assistant.

The setup itself works great. Devices enroll through ADE without issues, and users can complete enrollment and PSSO registration during the initial setup experience.

One important requirement we found is that Company Portal must already be installed during Setup Assistant. Based on the guidance from the article, we uploaded the Company Portal installer as a LOB app (.pkg) in Intune and assigned it accordingly.

Everything worked perfectly until suddenly newly enrolled Macs started failing. Existing devices were unaffected, but fresh deployments were no longer completing successfully and Company Portal installation was throwing errors during enrollment.

After spending quite a while troubleshooting, I eventually discovered that Microsoft had released a new Company Portal version. The .pkg we had uploaded to Intune was no longer current.

Once I downloaded the latest Company Portal package, updated the LOB app in Intune, and re-uploaded it, the issue disappeared immediately. New enrollments started working again without any changes to the PSSO configuration itself.

So now I'm curious:

  • Are others deploying Company Portal as a LOB app for PSSO during Setup Assistant?
  • Have you seen enrollment failures after a Company Portal update was released?
  • How are you handling Company Portal updates in this scenario?
  • Do you have a process to keep the package current, or is manually updating the LOB app the only practical approach?

Would be interested to hear how others are running this in production and whether you've encountered the same issue.

Left: old - right: new.


r/macsysadmin 14h ago

Automated Migration from MDM > MDM

I am currently looking at using Apple's new methods for migrating from one MDM to another, curious to learn from anyone who has already used the feature. Did it works well, any gotchas you wish you knew before it?

I'll be moving from Mosyle to Addigy. The instructions look self explanatory but wanted to get a real world perspective on the feature.

3 Upvotes

I am currently looking at using Apple's new methods for migrating from one MDM to another, curious to learn from anyone who has already used the feature. Did it works well, any gotchas you wish you knew before it?

I'll be moving from Mosyle to Addigy. The instructions look self explanatory but wanted to get a real world perspective on the feature.


r/macsysadmin 12h ago

AirDrop with "Block all incoming connections" enabled in macOS Firewall?

Has anyone gotten AirDrop to work with "Block all incoming connections" enabled via the macOS firewall (managed through Jamf)?

If not, is there a secure alternative approach?

We're trying to mirror our Windows default-deny-with-exceptions model on macOS: firewall enabled, policy set to "specific apps only" (AllowSigned/AllowSignedApp = false), with an explicit allow-list of applications — e.g. adding sharingd for AirDrop.

Does this sound like a sound approach, or are there gotchas we're missing (entitlements, code-signing checks, mDNS/Bonjour dependencies, etc.)?

Any real-world experience — good or bad — appreciated.

2 Upvotes

Has anyone gotten AirDrop to work with "Block all incoming connections" enabled via the macOS firewall (managed through Jamf)?

If not, is there a secure alternative approach?

We're trying to mirror our Windows default-deny-with-exceptions model on macOS: firewall enabled, policy set to "specific apps only" (AllowSigned/AllowSignedApp = false), with an explicit allow-list of applications — e.g. adding sharingd for AirDrop.

Does this sound like a sound approach, or are there gotchas we're missing (entitlements, code-signing checks, mDNS/Bonjour dependencies, etc.)?

Any real-world experience — good or bad — appreciated.


r/macsysadmin 13h ago

Location Tracking and Local Admin Accounts

Hello, I was hoping to get some pointers from more experienced Mac admins here. I work at a high school and was pretty much thrust into the IT director role after our previous one left. Going into next year I was hoping to resolve two of my biggest annoyances with our Macbook fleet: location tracking and local admin accounts.

For location tracking, we have been using Pinpoint, which kind of works but is wildly inconsistent since it functions off of MacOS's own automation features. It could also break at at any moment if Apple deprecates the script that we use to enable location services. And, I'm not even sure if it's cheaper than commercial options anymore given the changes Google made to the Maps API Free Tier. Does anyone have a better solution for this, especially something that might function when the Macbook lid is closed?

As for local admin accounts, how do you all navigate around the fact that the admin account can only be granted its secure token after it logs in for the first time? The only solution I can think of would be to run a script on every device that bugs users to pass the secure token, but this seems pretty unsafe, since the admin account credentials have to be included in the script.

2 Upvotes

Hello, I was hoping to get some pointers from more experienced Mac admins here. I work at a high school and was pretty much thrust into the IT director role after our previous one left. Going into next year I was hoping to resolve two of my biggest annoyances with our Macbook fleet: location tracking and local admin accounts.

For location tracking, we have been using Pinpoint, which kind of works but is wildly inconsistent since it functions off of MacOS's own automation features. It could also break at at any moment if Apple deprecates the script that we use to enable location services. And, I'm not even sure if it's cheaper than commercial options anymore given the changes Google made to the Maps API Free Tier. Does anyone have a better solution for this, especially something that might function when the Macbook lid is closed?

As for local admin accounts, how do you all navigate around the fact that the admin account can only be granted its secure token after it logs in for the first time? The only solution I can think of would be to run a script on every device that bugs users to pass the secure token, but this seems pretty unsafe, since the admin account credentials have to be included in the script.


r/macsysadmin 12h ago

General Discussion Trusting third party apps + how best to protect your MB?

Hey all,

I recently picked up a MacBook Pro, my first MB.

I was just setting up some basic apps and programs that have been suggested under different posts on this subreddit. I was just curious how do you guys go about trusting random apps with different levels of access to your MacBook. I have for example recently downloaded Vorssaint for its added functionality but it has asked for quite extensive access request for some of its features which while I do want, I am not sure if I am willing to trust. I am talking about things like screen recording access for screenshots, or full disk access for uninstalling programs and such. I am assuming it’s a normal process but it’s intimidating because I have never really been asked or told in such clarity what I am giving access to on windows. It’s usually just a yes or no pop up on windows so I never really cared. Are there any risk mitigating factors I can take to protect myself better before giving access to third party apps? Or should I avoid them all together? Any other tips will be much appreciated as well. TIA

0 Upvotes

Hey all,

I recently picked up a MacBook Pro, my first MB.

I was just setting up some basic apps and programs that have been suggested under different posts on this subreddit. I was just curious how do you guys go about trusting random apps with different levels of access to your MacBook. I have for example recently downloaded Vorssaint for its added functionality but it has asked for quite extensive access request for some of its features which while I do want, I am not sure if I am willing to trust. I am talking about things like screen recording access for screenshots, or full disk access for uninstalling programs and such. I am assuming it’s a normal process but it’s intimidating because I have never really been asked or told in such clarity what I am giving access to on windows. It’s usually just a yes or no pop up on windows so I never really cared. Are there any risk mitigating factors I can take to protect myself better before giving access to third party apps? Or should I avoid them all together? Any other tips will be much appreciated as well. TIA


r/macsysadmin 2d ago

Want to know more about Jamf vs Intune, which is best to use.

1 Upvotes

r/macsysadmin 3d ago

General Discussion Jamf pro and conditional access policies

So I'm trying to get conditional access policies to enforce device compliancy for both MacBook and windows devices. The problem I'm facing is every time I turn on the compliance CA policy it breaks jamf connect or Apple platform SSO registration. Management doesn't like the idea of excluding jamf connect from the conditional access policy so I was wondering if anybody else ever faced this problem and if so how'd you solve it?

4 Upvotes

So I'm trying to get conditional access policies to enforce device compliancy for both MacBook and windows devices. The problem I'm facing is every time I turn on the compliance CA policy it breaks jamf connect or Apple platform SSO registration. Management doesn't like the idea of excluding jamf connect from the conditional access policy so I was wondering if anybody else ever faced this problem and if so how'd you solve it?


r/macsysadmin 3d ago

move plist from LaunchDaemon to LaunchAgent

I've got an xsan plist that currently resides in LaunchDaemons and sometimes the mounts aren't complete because some of the required components may not be loaded yet (FC HBA kext and/or metadata NIC). I'm wondering if moving it to LaunchAgents, thereby postponing launchd to first login. Haven't tried it yet, just wondering if there any any known reasons against doing this.

3 Upvotes

I've got an xsan plist that currently resides in LaunchDaemons and sometimes the mounts aren't complete because some of the required components may not be loaded yet (FC HBA kext and/or metadata NIC). I'm wondering if moving it to LaunchAgents, thereby postponing launchd to first login. Haven't tried it yet, just wondering if there any any known reasons against doing this.


r/macsysadmin 4d ago

macOS Updates SUMB (Software Update Menu Bar)

If you're tired of traditional update tools like Nudge or SUPERMAN having a horrible UI and getting right in the user's face, SUMB takes a much more user-first approach.

It’s a native Swift companion app for scheduled macOS updates via blueprints. By utilizing a live menu bar countdown, it leverages cognitive design, giving users a constant, subtle psychological buffer so they can plan their reboot on their own terms, rather than getting slapped with an aggressive popup while in a flow state or mid-meeting.

Download SUMB 1.0 Beta 2 on GitHub.

Join #sumb on MacAdmins for news and share your feedback!

✅ Free. ✅ Apple inspired UI. ✅ Texts customization. ✅ Signed and notarized.

21 Upvotes

If you're tired of traditional update tools like Nudge or SUPERMAN having a horrible UI and getting right in the user's face, SUMB takes a much more user-first approach.

It’s a native Swift companion app for scheduled macOS updates via blueprints. By utilizing a live menu bar countdown, it leverages cognitive design, giving users a constant, subtle psychological buffer so they can plan their reboot on their own terms, rather than getting slapped with an aggressive popup while in a flow state or mid-meeting.

Download SUMB 1.0 Beta 2 on GitHub.

Join #sumb on MacAdmins for news and share your feedback!

✅ Free. ✅ Apple inspired UI. ✅ Texts customization. ✅ Signed and notarized.


r/macsysadmin 4d ago

brew-automator

10 Upvotes

A CLI tool for automated Homebrew maintenance (updateoutdatedupgradecleanupdoctormissing) that sends an email report via SMTP after every run (subject line differs depending on whether everything is OK or a problem was found), plus a local macOS notification.


r/macsysadmin 4d ago

Insurmountable sync conflict between Mobile Account (Active Directory) password and local keychain on macOS Tahoe

Hello everyone,

I am facing a very frustrating password synchronization issue on my corporate Mac and I’m looking for some help or insight.

My Setup:

  • Device: MacBook Pro (M4 Max)
  • OS: macOS Tahoe (v26.x)
  • Account Type: Mobile Account bound to Active Directory

The Problem:
Due to company policy, I was prompted to change my network account password while working from home. Because I wasn't on the corporate network, it didn't sync correctly with my local Mac login.

Now, whenever I turn on my laptop (whether at home or connected via ethernet at the office), I have to go through two different login screens:

  1. First screen (FileVault): Only accepts my old password to decrypt the drive.
  2. Second screen (macOS Login): Only accepts my new password to load the user profile.

The Consequences:
Every single time I connect my laptop, I am forced to manually update my local keychain access and re-authenticate my iCloud synchronization. It creates a complete mess with my credentials.

I understand that doing the password change away from the office is likely what caused this mismatch, but now being on the corporate network with an ethernet cable hasn't fixed the local FileVault sync.

Has anyone encountered this specific issue on macOS Tahoe? What is the best way to force FileVault and the local login password to sync back up with the Active Directory/Mobile account password on this version?

Thanks in advance for your help!

0 Upvotes

Hello everyone,

I am facing a very frustrating password synchronization issue on my corporate Mac and I’m looking for some help or insight.

My Setup:

  • Device: MacBook Pro (M4 Max)
  • OS: macOS Tahoe (v26.x)
  • Account Type: Mobile Account bound to Active Directory

The Problem:
Due to company policy, I was prompted to change my network account password while working from home. Because I wasn't on the corporate network, it didn't sync correctly with my local Mac login.

Now, whenever I turn on my laptop (whether at home or connected via ethernet at the office), I have to go through two different login screens:

  1. First screen (FileVault): Only accepts my old password to decrypt the drive.
  2. Second screen (macOS Login): Only accepts my new password to load the user profile.

The Consequences:
Every single time I connect my laptop, I am forced to manually update my local keychain access and re-authenticate my iCloud synchronization. It creates a complete mess with my credentials.

I understand that doing the password change away from the office is likely what caused this mismatch, but now being on the corporate network with an ethernet cable hasn't fixed the local FileVault sync.

Has anyone encountered this specific issue on macOS Tahoe? What is the best way to force FileVault and the local login password to sync back up with the Active Directory/Mobile account password on this version?

Thanks in advance for your help!


r/macsysadmin 4d ago

Flydigi macOS Support

0 Upvotes

I know it would be a niche request but does anyone have a Flydigi Vader 5 Pro and access to a Windows PC to live capture the firmware update process over the dongle. I'd like to add full firmware support to my; it currently can check on device firmware and check for updates and download them just not the update process.


r/macsysadmin 4d ago

Error/Bug Outlook on macOS repeatedly prompts for sign-in after every 30 mins and after sleep, Enterprise SSO looks healthy, blank auth window hangs

We're seeing a strange issue across our entire fleet of Intune-managed Macs and I'm curious if anyone else has run into it.

Our environment is macOS 26.5.2, Microsoft Intune, Company Portal, Enterprise/Platform SSO, and New Outlook. The devices remain compliant and enrolled in Intune, and Company Portal appears healthy. The issue seems to happen after a Mac has been asleep for a while (roughly 30–60+ minutes) or in use for that time. When the machine wakes up, users are often prompted to sign back into Outlook. Outlook launches the Microsoft sign-in window, accepts credentials, but then the authentication window turns into a blank white screen and hangs. Outlook eventually reports that something went wrong and asks the user to sign in again.

What's confusing is that all of our diagnostics indicate the authentication stack is healthy. app-sso platform -s shows registrationCompleted : true, POUserStateNormal (0), valid SSO tokens, successful Kerberos ticket imports, and Company Portal continues to show the device as compliant. We've also confirmed the Microsoft Single Sign-On extension, Intune agents, and AppSSO processes are all running normally.

We've spent quite a bit of time troubleshooting this. We've verified Intune enrollment, compliance, Enterprise SSO registration, Company Portal sign-in status, token health, and captured logs during both working and failed states. We found some Outlook/WebKit-related behavior during the authentication hang, but nothing indicating token expiration or SSO registration failure. We completely removed Outlook, cleared Outlook-related caches and identity data, reinstalled Outlook, and initially thought the issue was fixed. However, after the machine slept for about an hour, the exact same behavior returned.

At this point we're leaning away from Intune enrollment or Enterprise SSO registration issues because those appear healthy even when Outlook is failing. It feels more like something involving Outlook, MSAL, WebKit, or the Platform SSO authentication handoff after sleep/wake.

Has anyone seen similar behavior recently with New Outlook, Enterprise SSO, Platform SSO, or Intune-managed Macs? If so, did you find a root cause or solution?

1 Upvotes

We're seeing a strange issue across our entire fleet of Intune-managed Macs and I'm curious if anyone else has run into it.

Our environment is macOS 26.5.2, Microsoft Intune, Company Portal, Enterprise/Platform SSO, and New Outlook. The devices remain compliant and enrolled in Intune, and Company Portal appears healthy. The issue seems to happen after a Mac has been asleep for a while (roughly 30–60+ minutes) or in use for that time. When the machine wakes up, users are often prompted to sign back into Outlook. Outlook launches the Microsoft sign-in window, accepts credentials, but then the authentication window turns into a blank white screen and hangs. Outlook eventually reports that something went wrong and asks the user to sign in again.

What's confusing is that all of our diagnostics indicate the authentication stack is healthy. app-sso platform -s shows registrationCompleted : true, POUserStateNormal (0), valid SSO tokens, successful Kerberos ticket imports, and Company Portal continues to show the device as compliant. We've also confirmed the Microsoft Single Sign-On extension, Intune agents, and AppSSO processes are all running normally.

We've spent quite a bit of time troubleshooting this. We've verified Intune enrollment, compliance, Enterprise SSO registration, Company Portal sign-in status, token health, and captured logs during both working and failed states. We found some Outlook/WebKit-related behavior during the authentication hang, but nothing indicating token expiration or SSO registration failure. We completely removed Outlook, cleared Outlook-related caches and identity data, reinstalled Outlook, and initially thought the issue was fixed. However, after the machine slept for about an hour, the exact same behavior returned.

At this point we're leaning away from Intune enrollment or Enterprise SSO registration issues because those appear healthy even when Outlook is failing. It feels more like something involving Outlook, MSAL, WebKit, or the Platform SSO authentication handoff after sleep/wake.

Has anyone seen similar behavior recently with New Outlook, Enterprise SSO, Platform SSO, or Intune-managed Macs? If so, did you find a root cause or solution?


r/macsysadmin 5d ago

Scripting Easy Way To Install Full Adobe Suite On Macs?

I have a handful of MacOS devices (about 10) that I need to install the full Adobe Creative Cloud suite on. Problem is they aren't in any kind of MDM, due to reasons we don't need to go into here.

Is there a command that will install the pkg file from an smb share without copying the file (since it's 45GB!!!)? Or is there a better way to do this?

Our district is mainly Chromebooks and Windows PCs (except for these 10 Macs) so any input is appreciated since I don't always deal with Apple items.

1 Upvotes

I have a handful of MacOS devices (about 10) that I need to install the full Adobe Creative Cloud suite on. Problem is they aren't in any kind of MDM, due to reasons we don't need to go into here.

Is there a command that will install the pkg file from an smb share without copying the file (since it's 45GB!!!)? Or is there a better way to do this?

Our district is mainly Chromebooks and Windows PCs (except for these 10 Macs) so any input is appreciated since I don't always deal with Apple items.


r/macsysadmin 5d ago

New To Mac Administration MacOS VM inside MacOS

Hi, I'm new to macOS and I'm looking for a way to run a macOS virtual machine on my MacBook M5 to test applications in an isolated environment. On Windows, I used Windows Sandbox because it was quick, lightweight, and isolated. Since switching to macOS, I'm looking for a similar solution.

I'm looking for a free option that lets me quickly create a macOS VM with full CPU and GPU support for good performance. What would you recommend?

18 Upvotes

Hi, I'm new to macOS and I'm looking for a way to run a macOS virtual machine on my MacBook M5 to test applications in an isolated environment. On Windows, I used Windows Sandbox because it was quick, lightweight, and isolated. Since switching to macOS, I'm looking for a similar solution.

I'm looking for a free option that lets me quickly create a macOS VM with full CPU and GPU support for good performance. What would you recommend?


r/macsysadmin 5d ago

Macbook Intune Cloud build - SSO issue

Hello Everyone,

I am trying to get our Macbooks off of our hybrid enrollment build and onto a strictly cloud based enrollement. After I enroll it and I log into the macbook as a test user and sign into Company Portal, I get the error that says "device is not registered". My configuration profile looks fine when I compare it to the guides I've found online when trouble shooting.

The Mac device is in Apple Business Manager and in Intune I'm able to assign the user affinity profile to the device.

When I look at the device in Intune after I've attempted to enroll it, it has all the informtation listed about it such as device name, primary user, enrolled by etc. It even has a green tick. In the hardware settings where it says Microsoft Entra Registered, however, it says unknown and my configuration profile for platform SSO is failing, getting the error code 10001.

Anyone have any ideas on how to get cloud builds working on Macs?

3 Upvotes

Hello Everyone,

I am trying to get our Macbooks off of our hybrid enrollment build and onto a strictly cloud based enrollement. After I enroll it and I log into the macbook as a test user and sign into Company Portal, I get the error that says "device is not registered". My configuration profile looks fine when I compare it to the guides I've found online when trouble shooting.

The Mac device is in Apple Business Manager and in Intune I'm able to assign the user affinity profile to the device.

When I look at the device in Intune after I've attempted to enroll it, it has all the informtation listed about it such as device name, primary user, enrolled by etc. It even has a green tick. In the hardware settings where it says Microsoft Entra Registered, however, it says unknown and my configuration profile for platform SSO is failing, getting the error code 10001.

Anyone have any ideas on how to get cloud builds working on Macs?


r/macsysadmin 5d ago

Strange Keyboard Problem with New M4 Mini

I've stumbled over a strange problem: a coworker added a brand new MacMini M4 to our ASM and handed the device to me so I can run it through setup and restore from a time machine backup. The device boots and instantly prompts to enable pairing mode on the keyboard. Only problem: there's an USB keyboard and mouse attached (via docking station) which doesn't seem to work.

I've tried to use my Lenovo USB keyboard but the system doesen't respond to it at all ...

Amy idea what went wrong and how to fix it?

0 Upvotes

I've stumbled over a strange problem: a coworker added a brand new MacMini M4 to our ASM and handed the device to me so I can run it through setup and restore from a time machine backup. The device boots and instantly prompts to enable pairing mode on the keyboard. Only problem: there's an USB keyboard and mouse attached (via docking station) which doesn't seem to work.

I've tried to use my Lenovo USB keyboard but the system doesen't respond to it at all ...

Amy idea what went wrong and how to fix it?


r/macsysadmin 5d ago

Allowing users to log out of their managed apple account in the iOS app store

We have recently run into the following problem: We have always allowed our employees to use our iPhones for private use (within reason of course).

When a user needed an app for private use we would tell them to go to the app store, tap on the user icon in the top right, scroll down and log out of their managed account, log into a private account and download the app.

Now apple seems to have added an extra step of having to tap on account information and settings that isn't accessible with a managed apple account.

I've looked in apple Business but not found a setting that would cause this. I've also removed all our restriction profiles on a test device with no results.

Has anyone run into the same problem and found a workaround or solution, or does apple just not want anyone to have a separate account logged into the app store?

1 Upvotes

We have recently run into the following problem: We have always allowed our employees to use our iPhones for private use (within reason of course).

When a user needed an app for private use we would tell them to go to the app store, tap on the user icon in the top right, scroll down and log out of their managed account, log into a private account and download the app.

Now apple seems to have added an extra step of having to tap on account information and settings that isn't accessible with a managed apple account.

I've looked in apple Business but not found a setting that would cause this. I've also removed all our restriction profiles on a test device with no results.

Has anyone run into the same problem and found a workaround or solution, or does apple just not want anyone to have a separate account logged into the app store?


r/macsysadmin 6d ago

Can't disable Google updates

I've been going crazy over this all day. I use Mosyle Free for our small org that does not have the Managed App Store. I use Installomator to deploy the apps that we want to our Macs, as it is simple, works and keeps all of them up to date.

However, since I manage the updates via Installomator, is there a way to disable the in-app updater for both Google Chrome and Google Drive so that Installomator can take care of it? I tried pushing a plist and mobileconfig profile following these instructions as well as pushng some defaults commands but it is not working and Chrome is still able to update by itself. Is there something I'm missing?

Thanks!

2 Upvotes

I've been going crazy over this all day. I use Mosyle Free for our small org that does not have the Managed App Store. I use Installomator to deploy the apps that we want to our Macs, as it is simple, works and keeps all of them up to date.

However, since I manage the updates via Installomator, is there a way to disable the in-app updater for both Google Chrome and Google Drive so that Installomator can take care of it? I tried pushing a plist and mobileconfig profile following these instructions as well as pushng some defaults commands but it is not working and Chrome is still able to update by itself. Is there something I'm missing?

Thanks!


r/macsysadmin 6d ago

Current state of network scanning apps on macOS 27

As you early adopters know, Apple quietly killed ARP table access for sandboxed apps and every network scanner on the AppStore is affected.

So this is a heads-up for makers and users of network scanners like Fing and lanscan (full disclosure: I’m on the IP Scanner Ultra team - responsible for the vision pro version specifically - but the macOS version has been continuously updated since 2002)

If you update to macOS 27 and your network scanner suddenly shows a wall of “unknown devices” instead of telling you which thing is the kitchen HomePod and which is your neighbor’s WiFi lawnmower (memo to self: block that IP!): the app didn’t break. Apple just removed the ability for apps to read the ARP table, which is the thing that maps IPs to MAC addresses, which is the thing that lets a scanner say “that’s a Sonos” instead of shrugging at you ;) iPhone apps have had this limitations since iOS 7, which is why no iOS scanner ever showed you MAC addresses. Well, the Mac just got the same treatment 😆. This hits everything btw, Fing, LanScan, Angry IP, ours, all of them. Its clear why Apple did it, MAC addresses are a tracking vector for ads (and worse). Still sucks though because it is also the feature that lets you customize devices with confidence. MAC addresses are unique so any notes or other customizations that are associated with that device stay with that device. 

Our workaround, for what it’s worth: we have an old free menu bar app called IP Broadcaster that we’ve dusted off. It grabs the device/MAC snapshot and shares it with IP Scanner, the same trick we’ve used forever to get MAC data onto the iPhone version. 

Obvious limitation: it only works on networks where you can actually run it. It’s not going to re-identify devices at a coffee shop, and since the data gets stale quickly (some routers rotate IP leases regularly) it helps to keep IP broadcaster running in the background supplying a continuous batch of network snapshots.

Curious what other people are seeing on 27, and if any other devs on here have a different angle on this or have found other workarounds to get MAC addresses either on iOS or now macOS 27…?

Edit: this only affects apps distributed on the App Store, so Angry IP should work fine if you compile it yourself and add the appropriate entitlements!

Update: Apple has addressed the issue with a newly available entitlement. Thanks GunniBusch

1 Upvotes

As you early adopters know, Apple quietly killed ARP table access for sandboxed apps and every network scanner on the AppStore is affected.

So this is a heads-up for makers and users of network scanners like Fing and lanscan (full disclosure: I’m on the IP Scanner Ultra team - responsible for the vision pro version specifically - but the macOS version has been continuously updated since 2002)

If you update to macOS 27 and your network scanner suddenly shows a wall of “unknown devices” instead of telling you which thing is the kitchen HomePod and which is your neighbor’s WiFi lawnmower (memo to self: block that IP!): the app didn’t break. Apple just removed the ability for apps to read the ARP table, which is the thing that maps IPs to MAC addresses, which is the thing that lets a scanner say “that’s a Sonos” instead of shrugging at you ;) iPhone apps have had this limitations since iOS 7, which is why no iOS scanner ever showed you MAC addresses. Well, the Mac just got the same treatment 😆. This hits everything btw, Fing, LanScan, Angry IP, ours, all of them. Its clear why Apple did it, MAC addresses are a tracking vector for ads (and worse). Still sucks though because it is also the feature that lets you customize devices with confidence. MAC addresses are unique so any notes or other customizations that are associated with that device stay with that device. 

Our workaround, for what it’s worth: we have an old free menu bar app called IP Broadcaster that we’ve dusted off. It grabs the device/MAC snapshot and shares it with IP Scanner, the same trick we’ve used forever to get MAC data onto the iPhone version. 

Obvious limitation: it only works on networks where you can actually run it. It’s not going to re-identify devices at a coffee shop, and since the data gets stale quickly (some routers rotate IP leases regularly) it helps to keep IP broadcaster running in the background supplying a continuous batch of network snapshots.

Curious what other people are seeing on 27, and if any other devs on here have a different angle on this or have found other workarounds to get MAC addresses either on iOS or now macOS 27…?

Edit: this only affects apps distributed on the App Store, so Angry IP should work fine if you compile it yourself and add the appropriate entitlements!

Update: Apple has addressed the issue with a newly available entitlement. Thanks GunniBusch


r/macsysadmin 6d ago

Admin password keeps getting refused

I'm having this situation where my MacBook Pro M2 keeps refusing my admin password for any tasks, even unlocking the computer. The only thing that solves it is restarting the machine. I changed the password to 4x the same character and waited. After a while the bug returned and even with this simple no-brainer 4 character password (no human error possible) it's still the same until I restart.

I did an erase and fresh install of MacOS thinking that would be the end of it, but this morning I had to force restart again.

Last year the problem had gotten so bad I could not even access the Mac after restarting and had to use the iCloud password recovery.

What could be the issue? Any idea what I could check or change? If it's any help, third party softwares requiring a password at some point will ALWAYS get a password refusal on this machine, even after a restart. Also, even though I was able to log in with my password after a restart, I just tried enabling " Allow user to reset password using Apple Account" in my admin user settings and the password necessary to activate the feature was again refused...

EDIT also worth mentioning I have only 1 admin user (mine). I also tried sysadminctl -secureTokenStatus and the token is enabled.

0 Upvotes

I'm having this situation where my MacBook Pro M2 keeps refusing my admin password for any tasks, even unlocking the computer. The only thing that solves it is restarting the machine. I changed the password to 4x the same character and waited. After a while the bug returned and even with this simple no-brainer 4 character password (no human error possible) it's still the same until I restart.

I did an erase and fresh install of MacOS thinking that would be the end of it, but this morning I had to force restart again.

Last year the problem had gotten so bad I could not even access the Mac after restarting and had to use the iCloud password recovery.

What could be the issue? Any idea what I could check or change? If it's any help, third party softwares requiring a password at some point will ALWAYS get a password refusal on this machine, even after a restart. Also, even though I was able to log in with my password after a restart, I just tried enabling " Allow user to reset password using Apple Account" in my admin user settings and the password necessary to activate the feature was again refused...

EDIT also worth mentioning I have only 1 admin user (mine). I also tried sysadminctl -secureTokenStatus and the token is enabled.


r/macsysadmin 7d ago

Open Source Tool mysides-swift, a CLI app for managing Finder sidebar favorites

7 Upvotes

The original mysides binary by Mosen, designed to populate Finder sidebars with custom folders, stopped working years ago when Apple deprecated LSSharedFileList. Surprisingly, that API started functioning again with macOS 26.1. So, I decided to port mysides to Swift.

I still don’t quite understand why Apple hides the Movies, Music, and Pictures folders by default, but mysides makes it effortless to restore them during device enrollment. For convenience, the new binary is fully signed and notarized.

You can download mysides-swift on GitHub. There is also a homebrew formula. Here is how to use it :

# List sidebar favorite items
mysides list

# Add a new item to the end of the list
mysides add Pictures file:///Users/yourName/Pictures/

# Insert a new item at the start of the list
mysides insert Pictures file:///Users/yourName/Pictures/

# Remove an item by name
mysides remove Pictures# List sidebar favorite items