r/macsysadmin 2h ago

New To Mac Administration Newly taking over Mosyle — How are you handling zero-touch deployment, FileVault, and Dock management?

2 Upvotes

Hello r/macsysadmin ,

I recently inherited our company’s MDM after working under our previous Mac admin for about 2 years. My boss has tasked me with re-vamping our Mac deployment to be as close to "true" Zero-Touch as possible, but I’m running into a few friction points in our current workflow and want to see how other admins handle this.

Here’s where we are at and what’s tripping me up:

1. FileVault & Bootstrap Tokens

Currently, our ADE profile creates an IT admin account, and we create the local user account during Setup Assistant after enrollment.

  • The Problem: Because the IT Admin is created via ADE before any user logs in, it doesn't automatically get a SecureToken (FileVault unlock rights).
  • Why it breaks Zero-Touch: To ensure our local IT Admin can actually unlock FileVault down the road, I've been manually logging into that Admin account at least once during setup before I enable FileVault. (We escrow the file vault key in Mosyle so we wont get locked out completely its just better if our IT admin account can unlock FileVault )
  • The Question: How are you ensuring your local IT Admin account gets FileVault unlock rights / SecureTokens on a fresh Mac without someone from IT physically logging in? Are you relying on the end-user's initial login session to pass tokens, using Mosyle Embark, or something else?

2. Dock Customization & App Deployment Delay

Right now, I run a custom command/script to wipe the default Dock and populate our company’s default apps (Chrome, Zoom, etc.).

  • The issue: Mosyle’s app installation for some apps like Chrome and Zoom have been taking up to 20 minutes lately during initial setup. Because the Dock script runs before the apps actually land on disk, the apps end up missing form the dock unless I manually wait.
  • I’m looking into modifying the script to loop and check for app existence before editing the dock, but it still feels clunky.
  • Question: How do you set a default initial Dock layout for new users without breaking user customization later? Are you using tools like dockutil, Mosyle’s native tools, or something else?

3. Moving to SSO / IdP Login (Okta)

We currently use Okta across the company. My boss wants us to explore moving to an Identity Provider / SSO login screen for setup/login on macOS.

Question: For those using Okta + Mosyle for macOS setup, did it genuinely improve your Zero-Touch experience, or did it add more friction to account creation and FileVault token handoffs? Is it worth restructuring our whole workflow around?

4. General Recommendations & Resources

Since I’m stepping into the Lead Mac Admin role now, I really want to modernize and optimize our fleet management.

If you have workflow blueprints, recommended scripts, or learning resources (blogs, MacAdmins Slack channels, books) that helped you master macOS deployment and Mosyle specifically, I’d be super grateful!

Thanks in advance for any insights!


r/macsysadmin 12h ago

New To Mac Administration MacOS VM inside MacOS

13 Upvotes

Hi, I'm new to macOS and I'm looking for a way to run a macOS virtual machine on my MacBook M5 to test applications in an isolated environment. On Windows, I used Windows Sandbox because it was quick, lightweight, and isolated. Since switching to macOS, I'm looking for a similar solution.

I'm looking for a free option that lets me quickly create a macOS VM with full CPU and GPU support for good performance. What would you recommend?


r/macsysadmin 3h ago

Macbook Intune Cloud build - SSO issue

1 Upvotes

Hello Everyone,

I am trying to get our Macbooks off of our hybrid enrollment build and onto a strictly cloud based enrollement. After I enroll it and I log into the macbook as a test user and sign into Company Portal, I get the error that says "device is not registered". My configuration profile looks fine when I compare it to the guides I've found online when trouble shooting.

The Mac device is in Apple Business Manager and in Intune I'm able to assign the user affinity profile to the device.

When I look at the device in Intune after I've attempted to enroll it, it has all the informtation listed about it such as device name, primary user, enrolled by etc. It even has a green tick. In the hardware settings where it says Microsoft Entra Registered, however, it says unknown and my configuration profile for platform SSO is failing, getting the error code 10001.

Anyone have any ideas on how to get cloud builds working on Macs?


r/macsysadmin 6h ago

Strange Keyboard Problem with New M4 Mini

1 Upvotes

I've stumbled over a strange problem: a coworker added a brand new MacMini M4 to our ASM and handed the device to me so I can run it through setup and restore from a time machine backup. The device boots and instantly prompts to enable pairing mode on the keyboard. Only problem: there's an USB keyboard and mouse attached (via docking station) which doesn't seem to work.

I've tried to use my Lenovo USB keyboard but the system doesen't respond to it at all ...

Amy idea what went wrong and how to fix it?


r/macsysadmin 8h ago

Allowing users to log out of their managed apple account in the iOS app store

1 Upvotes

We have recently run into the following problem: We have always allowed our employees to use our iPhones for private use (within reason of course).

When a user needed an app for private use we would tell them to go to the app store, tap on the user icon in the top right, scroll down and log out of their managed account, log into a private account and download the app.

Now apple seems to have added an extra step of having to tap on account information and settings that isn't accessible with a managed apple account.

I've looked in apple Business but not found a setting that would cause this. I've also removed all our restriction profiles on a test device with no results.

Has anyone run into the same problem and found a workaround or solution, or does apple just not want anyone to have a separate account logged into the app store?


r/macsysadmin 15h ago

Can't disable Google updates

2 Upvotes

I've been going crazy over this all day. I use Mosyle Free for our small org that does not have the Managed App Store. I use Installomator to deploy the apps that we want to our Macs, as it is simple, works and keeps all of them up to date.

However, since I manage the updates via Installomator, is there a way to disable the in-app updater for both Google Chrome and Google Drive so that Installomator can take care of it? I tried pushing a plist and mobileconfig profile following these instructions as well as pushng some defaults commands but it is not working and Chrome is still able to update by itself. Is there something I'm missing?

Thanks!


r/macsysadmin 17h ago

Current state of network scanning apps on macOS 27

Thumbnail
1 Upvotes

r/macsysadmin 1d ago

Admin password keeps getting refused

0 Upvotes

I'm having this situation where my MacBook Pro M2 keeps refusing my admin password for any tasks, even unlocking the computer. The only thing that solves it is restarting the machine. I changed the password to 4x the same character and waited. After a while the bug returned and even with this simple no-brainer 4 character password (no human error possible) it's still the same until I restart.

I did an erase and fresh install of MacOS thinking that would be the end of it, but this morning I had to force restart again.

Last year the problem had gotten so bad I could not even access the Mac after restarting and had to use the iCloud password recovery.

What could be the issue? Any idea what I could check or change? If it's any help, third party softwares requiring a password at some point will ALWAYS get a password refusal on this machine, even after a restart. Also, even though I was able to log in with my password after a restart, I just tried enabling " Allow user to reset password using Apple Account" in my admin user settings and the password necessary to activate the feature was again refused...

EDIT also worth mentioning I have only 1 admin user (mine). I also tried sysadminctl -secureTokenStatus and the token is enabled.


r/macsysadmin 1d ago

Open Source Tool mysides-swift, a CLI app for managing Finder sidebar favorites

Thumbnail github.com
7 Upvotes

The original mysides binary by Mosen, designed to populate Finder sidebars with custom folders, stopped working years ago when Apple deprecated LSSharedFileList. Surprisingly, that API started functioning again with macOS 26.1. So, I decided to port mysides to Swift.

I still don’t quite understand why Apple hides the Movies, Music, and Pictures folders by default, but mysides makes it effortless to restore them during device enrollment. For convenience, the new binary is fully signed and notarized.

You can download mysides-swift on GitHub. There is also a homebrew formula. Here is how to use it :

# List sidebar favorite items
mysides list

# Add a new item to the end of the list
mysides add Pictures file:///Users/yourName/Pictures/

# Insert a new item at the start of the list
mysides insert Pictures file:///Users/yourName/Pictures/

# Remove an item by name
mysides remove Pictures# List sidebar favorite items

r/macsysadmin 1d ago

Neo and ADE

5 Upvotes

We are having issues with a percentage of our Neos skipping ADE. They push the user through Apple's OOBE, drop the user to the desktop, THEN prompt for MDM enrollment. This ONLY seems to happen directly out of the box and ONLY on Neos. Our Pros and Airs are all fine. Once we wipe the machine in question, it operates as expected. Is anyone else seeing this?


r/macsysadmin 1d ago

Looking at Mosyle for iPad tracking

4 Upvotes

I'm pretty novice here, so I'm not sure if this type of post is allowed. My apologies if I break any rules. And if so, could you direct me to a more appropriate sub?

I am not a professional IT person. I'm just the "millenial aged designated psudo IT person" here at our company. Among many roles, I happen to be the person who purchases and oversees our iphones and ipads and other tech. I could use some guidance from you all. (We do have an IT guy, but he is an independent contractor that basically just manages our server and M365 accounts. Hes great, but for projects like this, I'm kind of on my own.)

We have very laxed oversight on our tech here. I basically just order up iPads from our cell carrier, and hand off to whichever foreman needs it. (we are in construction). I do create their apple IDs with their work email address, and then I basically hand it off for personal/work use. I also have iPads scattered throughout our fabrication shop for the guys to use/share to view drawings, and mounted iPads for time clocks.

In total, we have about 22 iPads for various use cases. Some wifi only, some with cell plans. I have virtually no control over these devices. Surprisingly, its worked pretty well the last 7-8 years. We've never had a stolen/lost device. But I feel compelled to tighten the reins on this. I would really like to control the usage of the iPads. When one of the guys needs troubleshooting help on a pad, I always get in and noticed an overwhelming amount of games and streaming services loaded onto the pad. I dont think I need to argue my case here.

I'm learning about Apple Business Management, and MDMs. I just today set up a designated email alias to establish a the business management account. Its still "in review". It looks like I should be able to retroactively add all of our devices, because they all were purchased either directly from Apple or directly through our carrier.

The next step, if I understand correctly, is to select an MDM. It looks like I'm deciding between Microsoft Intune, and Mosyle? I'm not concerned with cost difference. I'm mainly concerned with ME being able to successfully manage this while NOT being a fulltime nor professional IT person. I would like to establish varied permissions for each device based on the devices function. Some will have single app uses (our time clocks), and some should have basically full privelages, but just allow me to takeover the device if needed.

For clarity, I will only be using the MDM for iPads at this time. For the employees who have company phones, we basically allow them to use them as personal phones. Many people have worked here 20+ years, and their work phone and personal phone are one in the same. Though, it might not be a bad idea to look at that in the future as a way to hand out phones for lower tier use.

Can any of you offer some insight? From what I see on a few posts, Mosyle sounds like the easiest user interface for someone like me. Does anyone have any other advice for me before I start this project? Maybe a heads-up on what kind of speedbumps I could/will run into? Or some tips to make this process smoother?

A good handful of our iPads are overdue to be updated. So after I get this going, I'll be purchasing a handful of new ones. I'm also learning that it seems more advantageous to purchases direct through apple business as opposed to through our carrier. Can anyone speak to that?

Any advice appreciated.


r/macsysadmin 1d ago

SharePoint Files Inaccessible While Syncing Active?

2 Upvotes

Has anyone seen this before?

We have a client that stores a TON of files in SharePoint across 3 SP sites and recently started having issues that affect 3-4 users out of around 20 or so. When OneDrive syncs, the SP libraries being synced disappear from OneDrive Preferences > Account, as if they were never synced. Then the sync completes, and the SP libraries reappear there. And while syncing, the files are not accessible - if you try to open anything from Finder, no luck. Never seen this before.

I tried a OneDrive full reset (unlink), nuking keychain logins, nuking OneDrive itself (and all related files in /Library, etc) - the same issue re-occurs, but most users don't have the same issue, syncing the same SP sites. All modern Macs, all the same macOS versions (latest Tahoe), identical in most ways.

Going to try creating a new user account on the affected Macs, but any other ideas?


r/macsysadmin 1d ago

Alamo City Mac Admins Summer Social 08/06

2 Upvotes

A big "Hello" to all my Mac Admins!

We are coming off the heels of our June meeting and rolling quickly into the end of summer. We want to have a little summer social gathering before it gets packed for some of us.

Please join us for a fun night out hitting some pins and rack up some frames. Feel free to spread the word!

Hope to see you there!

https://luma.com/yi921dtm


r/macsysadmin 2d ago

Waiting for VPP license

Thumbnail
2 Upvotes

r/macsysadmin 2d ago

Networking New entitlement reenables MAC-Address lookup from arp in iOS 27

25 Upvotes

Hey,

Just letting you all know that Apple added a new entitlement that makes Mac addresses visible from ie arp scans in IOS 27, those that where hidden in iOS 11 due to privacy reasons. It is called com.apple.developer.networking.topology-observation and isn't listed in any Apple doc nor could I find any reference to it on the internet.

it doesn’t need any special code change meaning you just have to add the entitlement and it will return the real MAC addresses instead of the generic fake ones.

It isn't some private entitlement, because you can find it in your entitlements overview for example in Xcode and Apple approved a TestFlight release with this entitlement.

But I am just happy that Apple brought It back.


r/macsysadmin 1d ago

WhatsApp on macOS force-logs me out ~30-60s after linking — even though everything actually works first. Tried everything, still stuck. ("Unexpected error - ‎WhatsApp needs to log you out and restart. Try linking again once the app has restarted")

Thumbnail
0 Upvotes

r/macsysadmin 2d ago

Trying to Force User Account to go back through Onboarding Screens

0 Upvotes

It's been a while since I've done any serious macOS management, and I'm trying to solve a problem that I don't need to solve. I just want to.

At my current workplace, we don't use an MDM to manage devices--we have a small enough deployment that this isn't too taxing--so when provisioning a new laptop I have to create the account manually on the device and log into it to do some final software configurations. This requires me to go through the onboarding steps like choosing any disabilities, Apple Account sign-in, Apple Intelligence/Siri, etc. I'd really like to be able to reset the account after I've done all my work to force the user go back through the onboarding process and experience the first-time user login process.

I don't want or need to delete .AppleSetupDone as I'm not trying to create a new user, but rather trying to reconfigure a currently existing user.

Is this even possible? I've been out of the macOS management game since 2022 so I'm not as up to snuff on the latest capabilities as I'd like to be.


r/macsysadmin 3d ago

Problems with Managed Migration Assistant

3 Upvotes

Hi everyone.

I was wondering if anyone else has been having issues with the new Managed Migration Assistant Profile when attempting to migrate after the initial Setup.

The profile seems to work just fine when setting up using Setup Assistant, but it does not work from the desktop app.

Also when being promoted to update the OS in setup assistant when migrating, i’m finding it always asking for a password even on a freshly wiped machine. Attempting to use the old password or a blank password does not let me complete the install.

Any ideas?


r/macsysadmin 2d ago

Macos powerusers, this one is for you...

Enable HLS to view with audio, or disable this notification

0 Upvotes

Every dictation tool keeps hearing "engine x" for nginx.. we built a local, real-time dictation that gets tech vocab right. the tool runs a speech model on your machine and types live into any app with capitalization and punctuation. all free and opensouce + nothing ever leaves your machine. repo is https://github.com/eliasmocik/dum-dictation ;) feedback very welcome..if it looks useful, a star will help us keep going!


r/macsysadmin 5d ago

General Discussion Intune - SSO not working as expected for Standard and admin users

9 Upvotes

Hi all

I've got 2 policies for SSO, one for standard users and the other for admin.

Standard users is set to All Users with the exclusion of a security group.

Admin users is set to security group only.

Im finding that my user in this security group is being set up as the standard user and I cant figure out why.

Any help appreciated.


r/macsysadmin 7d ago

Open Source Tool Mac Health Check (4.0.0)

Post image
21 Upvotes

A major update to the practical, MDM-agnostic, user-friendly approach to surfacing Mac compliance information directly to end-users — and now enterprise reporting data warehouses — via your MDM’s self-service app

Overview

Mac Health Check provides a practical, user-friendly, MDM-agnostic approach to surfacing Mac compliance information directly to end-users via an MDM’s self-service app.

Built using the open-source utility swiftDialog, the solution acts as a “heads-up display” presenting real-time system health and policy compliance status in a clear and interactive format.

Administrators can customize the user interface using swiftDialog’s visual capabilities, making the experience both informative and approachable.

The tool logs results for review, while not altering device configuration, and a “Silent” Operation Mode makes Mac Health Check ideal for IT visibility without end-user intrusion.

Mac Health Check version 4.0.0 generates client-side JSON — leveraging new Inspect Mode features of swiftDialog 3.1.0 — which can optionally be delivered via Splunk HEC

Continue reading …


r/macsysadmin 7d ago

New To Mac Administration Passwordless Login + Entra

19 Upvotes

Windows sys admin jumping into the Mac world, please forgive me.

We are a fully cloud Azure shop. We want to roll out MacBooks, and use either Yubikeys, or any other physical token/smart card to login to the Mac, and ideally SSO into Entra apps too. The big requirement is a quick login using the token + a PIN.

Can this be accomplished?

I went down the rabbit hole of Platform SSO and JAMF connect but couldn’t get it to work. Not sure if it’s not possible, I’m doing it wrong, or the Yubikey is not compatible. Any tips would be appreciated.


r/macsysadmin 7d ago

Mac Devices - Microsoft One Login

Thumbnail
2 Upvotes

r/macsysadmin 8d ago

Open Source Tool Built a free macOS app to inspect signing details and generate macOS 27 DDM JSON

10 Upvotes

I made a small SwiftUI utility while testing the new macOS 27 application-execution controls.

Instead of manually running several commands and copying Team IDs, Signing IDs, designated requirements, architecture information, and other values, you can select an .app and see everything in one place.

It also has a graphical declaration builder where you can add multiple apps, choose allow or deny, create specific-app or developer-wide rules, enable managed-app allowances, add path restrictions, and then copy or export the complete JSON.

It includes duplicate and redundancy warnings because broad Team ID rules can easily overlap with more specific app rules.

A few important notes:

It runs locally and does not upload anything.

It does not require Jamf credentials.

It does not modify the app you inspect.

It is currently source-only, so you need Xcode to build it.

It is focused on .app bundles, not standalone binaries or every embedded helper.

The macOS 27 schema is still based on beta documentation and could change.

There is no direct Jamf upload integration yet.

The repository is here:

Jerez1lla/macos-app-signing-inspector: Native macOS utility for inspecting app signing details and building macOS 27 DDM application-execution declarations.

Feedback and testing from other Mac admins would be appreciated, especially against applications with unusual signatures or complex embedded components.


r/macsysadmin 7d ago

Configuration Profiles MacOS Intune Device Enrollment, Company Portal MDM error, please assist

Thumbnail
2 Upvotes

Hey everyone, if you could please read my post and let me know anything to point me in the right direction, I would greatly appreciate any support. Thank you in advance