3 ms·
I don't think that no approvals, no CI, webpage text box to fleet-wide root is a core tenet. Maybe a commonality though.
by computerfriend 3y ago
I don't think that no approvals, no CI, webpage text box to fleet-wide root is a core tenet. Maybe a commonality though.
- angulardragon03 3y agoNo approvals and no CI with clickops is indeed not a core tenet, but these are things you can implement on top of a solution like Jamf. However, the market wasn’t always asking for it. Most Mac management is done by a sole individual at the org, usually not a large team where everyone can review everyone’s changes. This is steadily changing, but there are still tons of people who do clickops in Jamf because it’s what they understand and have the bandwidth to do.
- wkat4242 3y agoWe have almost a hundred thousand users and we don't have an approval process for macs either. Because we only have a few hundred :) I think the windows guys have everything more proceduralised. But the Mac work is more of a one man show. I still don't think they have an approvals process though. They mainly still use SCCM and I don't think that has approvals built in. And yeah things get tested in a separate environment before they're deployed in live. But as there's just one person doing both on Mac there's not much point to an approvals process. Which is also the person that gets to deal with any mistakes so there generally aren't any :) And it's not a bad thing either, the Mac side is usually much quicker to adopt new features. Both because there's not that many and because Mac users are always interested in new OS versions whereas Windows users generally prefer to stay on what they know.
- w0de0 3y agoI recently implemented Terraform for a Jamf instance. In my experience macadmins are often much better at code driven workflows than Windows admins. MacOS is, after all, a real Unix. And Apple’s MDM protocol documentation is far superior (that’s why features are implemented quickly). Jamf’s script feature is agent based, just like Airwatch’s, not an implementation of the MDM protocol.
- wkat4242 3y ago> And Apple’s MDM protocol documentation is far superior (that’s why features are implemented quickly). In terms of the overal tooling I have to disagree. SCCM is way more powerful than anythng Apple has to offer. In terms of actual MDM "Modern Management" for Windows (Intune), yes that's only in its infancy but it's because most of their customers still use SCCM for most tasks. It's a bit chicken-and-egg. But Apple's MDM is not great. The password profile is extremely simplified, not able to handle any complexity (example: In our AD passwords must contain special characters and numbers if they are shorter than 10 characters but don't need to when longer because we want to stimulate passphrases). Also, as far as I know (I don't work in this scope anymore) it still has no MDM profile to mandate the user installing updates in a timely manner. You can delay them but not force the user to install them. This stuff must be handled with scripting. The MDM app deployment is also very hit and miss which is why most MDMs do it through their own agent. It works fine when using the mac app store but most apps are not on there and usually there is a need for a customised package anyway. And on the topic of customised packages, having to go through Apple's notarisation is really annoying. We should be able to just deploy our own signing keys to the machines that we own, and deploy to those machines whatever we want that's signed with our internal key without having to get Apple's OK on it. Sometimes the notarisation service refuses to work for some reason (happens especially with package installers combining code and signing keys from 2 different vendors) and I need to obfuscate the embedded packages to make it work. So no, in terms of MDM I think Apple is not great for enterprise usecases. If you're a small all-apple shop and you can align everything with Apple's requirements then you may fare better but we don't. Less than a percent of our systems are macs. > are often much better at code driven workflows than Windows admins. Yes but Apple does shoot us in the foot sometimes by changing stuff around. I have to say that PowerShell is much more consistent in this manner. I still prefer Mac but I have to say the enterprise management tooling is just way better on Windows. Apple doesn't really seem to care about enterprise users at all. Another point is that terrible federated apple ID system that to this day still requires the UPN to be equal to the email address. In our environment this is different for a reason and there is no way it's going to get changed just to satisfy an Apple requirement.