Mac Configuration Enhanced Workflow
Apple introduced macOS BigSur in November 2020 and as the newest version of Apple's operating system, it brought about many upgrades in terms of security and privacy. Because of these upgrades, changes have been introduced in Mac Management.
How does this impact you?
There are certain Mac Configurations which will become non-functional (till the build 10.0.648), if the target machines contain BigSur.
For now, System preferences Mac based User configurations will function in target machines with macOS Catalina or below only.
How can you overcome this?
Endpoint Central has introduced MDM Profile. By doing so, certain Mac Configuration workflows have been enhanced and this will circumvent any problems in Mac Management. The computer based configurations that require the introduction of MDM Profile are as follows -
- AirPrint
- App Notifications
- Background Service Management
- Custom Configuration
- Energy Saver
- Extensible SSO
- Firewall
- Fonts
- Gatekeeper
- Global HTTP Proxy
- Login Window
- Login Items
- Passcode
- Restrictions
- PPPC
- Per-App VPN
- System Extensions
- System Preferences
- VPN
- Web Content Filter
- Wi-Fi
What steps should you undertake?
The steps you must take vary in the context of whether your target machine possesses macOS BigSur or whether MDM Profile has been installed on the machine or not. The table below will guide you for any of the different cases based on your network.
| macOS Bigsur & above versions? | MDM Profile? | Steps to do |
|---|---|---|
| Not present | Not installed | After configuring the required prerequisites, MDM Profile needs to be installed on the Mac Computers. Prior to this, any MDM profile dependent configuration will not be deployed. Learn more about MDM Profile and its prerequisites. |
| Not present | Installed | If the end user has not approved MDM Profile, they have to install it manually through the notification window. |
| Present | Not Installed | After configuring the required prerequisites, MDM Profile needs to be installed on the Mac Computers. Prior to this, any MDM profile dependent configuration will not be deployed. Learn more about MDM Profile and its prerequisites. Note Note: MDM profile dependent configurations that are deployed before build 10.0.648 can be reused for target machines running on any macOS except Bigsur. |
| Present | Installed | If the end user has not approved MDM Profile, they have to install it manually through the notification window. |
What happens when your MDM Profile dependent Configurations are Moved to Trash?
If you perform the action "Move to trash" from the Configurations tab for the relevant MDM Profile Support configuration, then the configuration will be revoked from the agent machine.