r/macsysadmin 17h ago

New To Mac Administration MacOS VM inside MacOS

13 Upvotes

Hi, I'm new to macOS and I'm looking for a way to run a macOS virtual machine on my MacBook M5 to test applications in an isolated environment. On Windows, I used Windows Sandbox because it was quick, lightweight, and isolated. Since switching to macOS, I'm looking for a similar solution.

I'm looking for a free option that lets me quickly create a macOS VM with full CPU and GPU support for good performance. What would you recommend?


r/macsysadmin 2h ago

Scripting Easy Way To Install Full Adobe Suite On Macs?

Thumbnail
2 Upvotes

r/macsysadmin 6h ago

New To Mac Administration Newly taking over Mosyle — How are you handling zero-touch deployment, FileVault, and Dock management?

2 Upvotes

Hello r/macsysadmin ,

I recently inherited our company’s MDM after working under our previous Mac admin for about 2 years. My boss has tasked me with re-vamping our Mac deployment to be as close to "true" Zero-Touch as possible, but I’m running into a few friction points in our current workflow and want to see how other admins handle this.

Here’s where we are at and what’s tripping me up:

1. FileVault & Bootstrap Tokens

Currently, our ADE profile creates an IT admin account, and we create the local user account during Setup Assistant after enrollment.

  • The Problem: Because the IT Admin is created via ADE before any user logs in, it doesn't automatically get a SecureToken (FileVault unlock rights).
  • Why it breaks Zero-Touch: To ensure our local IT Admin can actually unlock FileVault down the road, I've been manually logging into that Admin account at least once during setup before I enable FileVault. (We escrow the file vault key in Mosyle so we wont get locked out completely its just better if our IT admin account can unlock FileVault )
  • The Question: How are you ensuring your local IT Admin account gets FileVault unlock rights / SecureTokens on a fresh Mac without someone from IT physically logging in? Are you relying on the end-user's initial login session to pass tokens, using Mosyle Embark, or something else?

2. Dock Customization & App Deployment Delay

Right now, I run a custom command/script to wipe the default Dock and populate our company’s default apps (Chrome, Zoom, etc.).

  • The issue: Mosyle’s app installation for some apps like Chrome and Zoom have been taking up to 20 minutes lately during initial setup. Because the Dock script runs before the apps actually land on disk, the apps end up missing form the dock unless I manually wait.
  • I’m looking into modifying the script to loop and check for app existence before editing the dock, but it still feels clunky.
  • Question: How do you set a default initial Dock layout for new users without breaking user customization later? Are you using tools like dockutil, Mosyle’s native tools, or something else?

3. Moving to SSO / IdP Login (Okta)

We currently use Okta across the company. My boss wants us to explore moving to an Identity Provider / SSO login screen for setup/login on macOS.

Question: For those using Okta + Mosyle for macOS setup, did it genuinely improve your Zero-Touch experience, or did it add more friction to account creation and FileVault token handoffs? Is it worth restructuring our whole workflow around?

4. General Recommendations & Resources

Since I’m stepping into the Lead Mac Admin role now, I really want to modernize and optimize our fleet management.

If you have workflow blueprints, recommended scripts, or learning resources (blogs, MacAdmins Slack channels, books) that helped you master macOS deployment and Mosyle specifically, I’d be super grateful!

Thanks in advance for any insights!


r/macsysadmin 7h ago

Macbook Intune Cloud build - SSO issue

2 Upvotes

Hello Everyone,

I am trying to get our Macbooks off of our hybrid enrollment build and onto a strictly cloud based enrollement. After I enroll it and I log into the macbook as a test user and sign into Company Portal, I get the error that says "device is not registered". My configuration profile looks fine when I compare it to the guides I've found online when trouble shooting.

The Mac device is in Apple Business Manager and in Intune I'm able to assign the user affinity profile to the device.

When I look at the device in Intune after I've attempted to enroll it, it has all the informtation listed about it such as device name, primary user, enrolled by etc. It even has a green tick. In the hardware settings where it says Microsoft Entra Registered, however, it says unknown and my configuration profile for platform SSO is failing, getting the error code 10001.

Anyone have any ideas on how to get cloud builds working on Macs?


r/macsysadmin 20h ago

Can't disable Google updates

2 Upvotes

I've been going crazy over this all day. I use Mosyle Free for our small org that does not have the Managed App Store. I use Installomator to deploy the apps that we want to our Macs, as it is simple, works and keeps all of them up to date.

However, since I manage the updates via Installomator, is there a way to disable the in-app updater for both Google Chrome and Google Drive so that Installomator can take care of it? I tried pushing a plist and mobileconfig profile following these instructions as well as pushng some defaults commands but it is not working and Chrome is still able to update by itself. Is there something I'm missing?

Thanks!


r/macsysadmin 11h ago

Strange Keyboard Problem with New M4 Mini

1 Upvotes

I've stumbled over a strange problem: a coworker added a brand new MacMini M4 to our ASM and handed the device to me so I can run it through setup and restore from a time machine backup. The device boots and instantly prompts to enable pairing mode on the keyboard. Only problem: there's an USB keyboard and mouse attached (via docking station) which doesn't seem to work.

I've tried to use my Lenovo USB keyboard but the system doesen't respond to it at all ...

Amy idea what went wrong and how to fix it?


r/macsysadmin 12h ago

Allowing users to log out of their managed apple account in the iOS app store

1 Upvotes

We have recently run into the following problem: We have always allowed our employees to use our iPhones for private use (within reason of course).

When a user needed an app for private use we would tell them to go to the app store, tap on the user icon in the top right, scroll down and log out of their managed account, log into a private account and download the app.

Now apple seems to have added an extra step of having to tap on account information and settings that isn't accessible with a managed apple account.

I've looked in apple Business but not found a setting that would cause this. I've also removed all our restriction profiles on a test device with no results.

Has anyone run into the same problem and found a workaround or solution, or does apple just not want anyone to have a separate account logged into the app store?


r/macsysadmin 22h ago

Current state of network scanning apps on macOS 27

Thumbnail
1 Upvotes