4 ms·
I'm currently in that hellish process too... I don't know how to get out of it. Did you know that your employees will be forbidden from downloading from the App
by cocoflunchy 6mo ago
I'm currently in that hellish process too... I don't know how to get out of it. Did you know that your employees will be forbidden from downloading from the App store once you launched that migration? It's a nightmare
- FireBeyond 6mo agoApple and MDM has always been a shit show. In the days as recently as Ventura (last time I tried it), MDM bypass was as simple as "null route 4 DNS entries during install process, remove null routing after install complete, and never be bothered by it again". This is on Apple Silicon. With no workarounds or anything, upgrades work all the way up to Tahoe. Like really Apple, that's your device "locking"? I could test activate my work Mac with my personal Apple ID while doing this, no alarm bells, nothing, effectively "It's your laptop now".
- IrishTechie 6mo agoThe baffling thing is that iOS+MDM has been fantastic over the years. macOS is a completely different beast though.
- jamiecurle 6mo agoMacOS used to be excellent for a short period of time when Fleetsmith existed. Then Apple purchased Fleetsmith around 2020 and killed the product not long after. Fortunately around the same time, JamF ended the practice of the mandatory Jamf JumpStart (£5K fee), which finally made Jamf a feasible option for the company I was in at the time.
- wolvoleo 6mo agoTrue, I remember looking at jamf at one point and the mandatory consulting was so annoying because we already had it dialled in on the free trial. In the end we just made do with intune. It's a lot less capable for Mac but these days you can get by with it.
- bzmrgonz 6mo agohopefully there's no kill switch for macs on intune, if not, the threat of wiping machines with one click is real, just ask stryker; https://www.cybersecuritydive.com/news/stryker-attack-device-management-microsoft-iran/814816/ https://www.cybersecuritydive.com/news/stryker-attack-device...
- wolvoleo 6mo agoOf course there is a kill switch. This is one of the key features of an MDM/endpoint manager. You won't be able to sell one without it. It's also built in to apple's management protocol (which most endpoint management systems leverage) and in activesync. You just have to secure it properly. Have limits to how many one admin can wipe etc. But trust me every company with managed IT assets has this capability. Often even in BOYD scenarios! Stryker just failed to secure access to it properly and to set sensible limits. However, the feature isn't very effective in the field. It's very unlikely for an attacker to be smart enough to bypass the password on a stolen Mac which is needed to connect it to WiFi, yet at the same time be dumb enough to connect it to the unfiltered internet so it can receive the wipe command. The overlap between these sets of people is almost zero. We do fire a wipe at every stolen computer but I doubt it ever actually happens. If it ever happens it'll be a total end user fail (like writing the password on a post-it with the laptop) Either you will lose it to a common thief who won't be able to breach the login (99% of cases), or to a really targeted adversary who has cellebrite or something similar and won't connect it to the internet ever again. This is still the most risky scenario because if someone like that steals it, there's bound to be something really valuable on it. In practice this is something more suited to mobile devices.
- wpm 6mo agoWell yeah, the idea is that if you have ABM, you have an MDM you can use to purchase licenses for them and install the apps with the MDM.
- IrishTechie 6mo agoIt can be done that way, but it is definitely not the norm. Businesses will generally “purchase” (many for €0) apps in ABM that are to be used for business purposes and push those to devices, the user can then use an Apple ID to download any other apps they want for personal use.
- ndespres 6mo agoIf they’re using Managed Apple IDs they will have no access at all to the app store and won’t be able to download their own apps anymore. IT department will have to buy and assign any apps that anyone needs, even the $0 ones that only 1 person needs.
- lynx97 6mo agoIf my employer did that to me, I would seriously consider sueing them.
- jazzyjackson 6mo agoYou’ve never been issued a work computer that’s not yours to fuck around with?
- deleted 6mo ago[deleted]
- ghaff 6mo agoI haven’t. Did have issued laptops that were company managed but I basically didn’t use and, in any case, I like many others reinstalled a clean operating system image and did my own support.
- geoffharcourt 6mo agoI did not. If I had known what would happen when we tried this we would have skipped the process entirely. Our staff (roughly 125) was so confused and it wasted a lot of time communicating about it, then trying to roll it back, etc.
- TheNewsIsHere 6mo agoThe Domain Capture process cannot be canceled once it’s started. It’s also not required, unless by your company policy. The point is to make sure there’s not a mess on the other end when you enforce SSO for MAIDs. Apple’s documentation for ABM and ABE is atrocious, but they do manage to document a bunch of footguns, just poorly and in seemingly bizarre places. For example, ABE doesn’t support MDM migration (either as source or destination), despite the fact that the feature launched with macOS/iOS/iPadOS 26 and is supported by other MDM solutions. And you cannot push custom config profiles with ABE which declare a non-Apple preference domain. Utter nonsense. If you’re using the full ABM-with-ADE and MDM stack, it’s expected that you push apps to employees. You can also use Munki to make apps available to users. You can just push only Munki via MDM if you want, and let it manage app installs and self service installs for you. There are caveats.