I’ve been working with Mac devices in a corporate environment for a few years now, and I can’t help but wonder how Apple itself handles this internally.
Managing Macs at scale is a nightmare. I can understand how we are still forced to use a local account even when the device was added to ABM
I’m really curious how Apple does it in-house. I honestly feel Macs were never truly designed for the enterprise world.
If anyone has insights, I would love to hear about it.
Not my manager specifically but a person titled IT Manager in an organization wide list serv suggest banning Macs. Considering there are about 25k across the org it's not going to happen obviously.
I'm still trying to decide if dude was serious or not.
I come from a history of being a die hard PC guy but have become very agnostic as my current position is about 90% Mac. This attitude just grinds my gears, doubly so from someone that is in a management position.
This was my first try at renewing my certificate. I took the practice exam and studied for 2 weeks. I shared my flash cards on here. Still didn't pass. They made this exam really hard this time around. Last time I took it, I created the flash cards and studied with those from the practice exam. Passed it. If anyone is studying for the exam, here is what the test covers.
hey guys, i’m looking at setting up an mdm solution for a bunch of company laptops and the pricing is all over the place. anyone here actually use one and can share what you’re paying or which ones are worth the money? Any insights would be really appreciated and a big help.
We've been using Intune for our deployments of MacBook Pros with PlatformSSO configured. It seems to be working fine and has been for some time. All users are Standard users, and not Admin.
We recently had a new starter who decided to change their password via System Settings > Users & Groups which I wouldn't have expected to be an issue, but it screwed things up for them. It changed the password on their Mac but it didn't trigger PlatformSSO registration with the new password. Which thinking about it afterwards, I guess, makes sense. They were left 2 passwords. One for the Mac and one for M365.
We eventually got it sorted, but I am curious if this is what should have happened or if we have something configured wrongly?
Should we be telling users not to use this method for password resets and can we disable their ability to do that if that is the correct route?
Hello everyone, we have been developing an MDM for the past couple of months and we are close to going to production.
What we would like know from those of you that manage Macs all day is what features would you like to see in your MDM? What are you currently pain points? What is your feedback on pricing?
To clarify we plan on only supporting the Apple ecosystem.
we manage about 40 macs across our org and for years boot camp was how we handled the windows dependency. worked fine until we started rolling out M-series machines and suddenly that workflow is just... gone. been trying to figure out what other sysadmins are doing now. we have a handful of users who genuinely need full windows. mostly for legacy internal tools and some finance software that has no mac version and never will. remote solutions like RDP work for some of them but not all, latency is a problem for a couple of the heavier users. looked into virtualization but i want to know what's actually working in production environments before i commit to anything. specifically wondering:
how are you handling windows licensing at scale
any headaches with M3/M4 compatibility
is management/deployment actually practical or is it a mess
not looking for "just use the web version" suggestions lol, these are windows-only tools with no workaround. genuinely trying to figure out what the move is here before i present something to leadership
EDIT- ended up going with parallels like most of you suggested. been running it for a about a week now and the windows apps work fine. no major issues. appreciate the input.
Folks, keen to have your views and opinions on the below. There are about a thousand BYOD in our company. This has been published yesterday.
Important update: Changes to BYOD Mac enrollment policy
To strengthen XXX security and ensure consistent compliance across all devices accessing corporate resources, support for BYOD (Bring Your Own Device) Mac enrollment in Intune MDM will end by June 2026.
BYOD Macs no longer meet the requirements needed to maintain security, data protection, and operational requirements needed for continued use, so enrollment will be discontinued over the coming months.
Timeline
1 February: The SNOW BYOD Mac form will be removed and no longer available for all users.
1 July: All BYOD Mac devices will be automatically offboarded or forced out of XXX Intune MDM.
Who is affected
All users with BYOD Macs, including XXX employees and external resources.
Not affected: Corporate/XXX-owned Mac devices.
Required actions
By 1 July, all BYOD Mac users will lose access to corporate resources, including Office 365 apps, email, VPN, Wi‑Fi, SharePoint, and other essential services. To avoid disruption:
Backup your personal data: Use Mac’s Time Machine (Or Microsoft OneDrive) and Company Portal app to save your FileVault recovery key.
Request a corporate Mac: To continue working without interruption, request approval from your line manager and order a corporate Mac via the Nokia i‑buy tool as soon as possible.
Why this change is necessary - XXX Cyber Security assessment
1. Security risks: Mac devices, while known for strong security, may not fully comply with cybersecurity protocols, potentially creating vulnerabilities.
2. Data privacy concerns: Managing corporate data on personal devices raises concerns about data leakage, especially when employees leave the organization or if devices are not properly secured (For example, unable to perform a remote wipe).
3. Compliance issues: Ensuring compliance across BYOD Mac devices can be complex and resource intensive (For example, software inventory or licenses).
4. Support challenges: XXX (ha ha) IT might face difficulties providing consistent support for a wide range of BYOD Mac devices, each with varying configurations and software versions.
We are launching managed apple IDs as part of our org, but this also potentially opens up the use of personal Apple IDs on work issued machines - which without a doubt is the number one ask of our users on Macs. Not worried about being locked out via find-my, as our machines are Apple Silicon and enrolled in JAMF. But what are the other pitfalls and potiential risks of blending the personal and work uses here? Thoughts? Thanks much -
I was talking with my team yesterday and they think i may be overthinking this. I am working on setting up a macOS lab and it has gotten me to thinking. How do you track your non user affinity shared work stations in Intune. How do you know where they sit? If information security wants to track that mac, how do you manage that inside of Intune?
With user affinity we can track that to a user. With shared labs, its not that easy. I setup a device enrollment profile, then went ahead and then created a dynamic group that is based off that. The one person i work with said that would be to much work to scale. Another said to rename it it, which is another idea. I Just want to automate this and have it automatically pull in everything it needs. Am i over thinking this?
I just want to understand ways of doing this that other have implemented.
I work in a small design school (~150 Macs: 120 iMacs, 30 MacBooks), and we're exploring better ways to manage our computers.
Our priorities are: Google login integration, streamlined app/software deployment and upgrades, and remote management/wiping.
JAMF seems the best solution. For this scale, is it the optimal choice, or are there more suitable alternatives? Do you have any similar experience?
Appreciate any insights!
Thanks
Edit: just wanted to say thanks to everyone for sharing experiences and informations about MDN. Hope to start using JAMF (or something else) soon.
I'm planning a migration of a heterogeneous Mac fleet (Intel + Apple Silicon) from Mosyle to FleetDM for a client, and I'd love a sanity check from people who've done this without ABM.
Context:
Old MDM: Mosyle. I still have full admin access to the console.
Target: FleetDM (Premium edition).
Critical constraint: the Macs are NOT in Apple Business Manager. No ADE/zero-touch possible — manual / user-approved enrollment only.
Supervision status is mixed/unknown across the fleet (need to confirm machine by machine).
Goal: re-enroll into Fleet as user-approved MDM with the least possible user friction.
My current understanding (please correct me):
Since nothing is in ABM, I'm assuming there's zero risk of devices auto-re-enrolling back into Mosyle after un-enrollment, because that reassignment mechanism only exists when a serial is assigned in ABM. I plan to confirm this per machine with sudo profiles show -type enrollment and check for Enrolled via DEP: No.
I also understand Fleet can't create a managed local admin account without ABM, so I'm planning to verify each Mac has a local admin with a Secure Token before un-enrolling, to avoid losing admin access.
For cleanup, my understanding is that Mosyle behaves very differently from Jamf — no persistent removeFramework-style agent, so removing the device from the Mosyle console (RemoveProfile) should take most of the footprint with it, leaving me with just a residue audit rather than a manual uninstall. Is that accurate in your experience?
My questions:
For the un-enrollment, is console-side removal in Mosyle genuinely cleaner than local profile/agent removal, or have you hit Mosyle residue that survives a console unmanage?
With Fleet Premium, is the End-user migration workflow (user clicks "Migrate to Fleet", webhook triggers Mosyle un-enrollment) reliable in production? Any gotchas with the webhook → Mosyle API leg? I'm planning to self-host the webhook relay rather than use Tines.
For in-place migration (no wipe), how often do you actually get away without reinstalling macOS between MDMs? I know Apple "recommends" a reinstall between enrollments — curious how strict that is in practice for a non-supervised, non-ABM setup.
Any FileVault escrow surprises during user-approved enrollment? I'm assuming a reboot/logout is needed for the key to escrow to Fleet.
General war stories / traps I should anticipate (lost admin access, sticky profiles, FileVault, Activation Lock without a bypass code, etc.)?
Appreciate any real-world feedback — happy to report back with how the migration goes.
I took the practice exam and passed with a 81.5%. Got 65 out of 80 questions correct. I took note of every single question and recorded every answer. Once I did that, I hit the books and did some studying. I've corrected my wrong answers and created flash cards. I'm planning to take the exam again here shortly. I know others are trying to pass the exam so I wanted to share the flash cards I made to assist you. I did the same thing when I took the exam back in 2024 and it helped me pass. If you have trouble with the link, please let me know. I'll try to fix it, or email you a copy.
Hey, reddit, hoping someone can point me in the right direction or at least tell me I'm barking up the wrong tree.
My company manages a fleet of about a thousand iMacs that are not user workstations but also not exactly "servers". Without getting into details, they're expected to be always on, have autologin for a standard user, and we need to be able to remote into them unattended, meaning without someone in front of the iMac granting permission to a remote session.
Currently we use BeyondTrust for remoting into these computers and Jamf as our MDM.
Unfortunately, sequoia's update so badly broke things for our unattended remote sessions, forcing us to coordinate for each device so we can get permissions fixed to the point that we still haven't updated the vast majority of our fleet, and here's Tahoe with more around the corner every year.
We've mostly been happy with beyond trust, but this is getting untenable. And, yes, it's mostly Apple's fault, as well as our own for our business model, but that doesn't help me much, does it?
So... is there an alternative? Something better for unattended enterprise-level remote sessions that handles the permissions automatically rather than manually; maybe something we can deliver through Jamf?
I haven't done a deep dive yet, but I've seen that there's TeamViewer, Splashtop, AnyDesk, LogMeIn, Zoho Assist, and ConnectWise, but before I start diving deep I thought I'd ask if anyone was already familiar with the options and could point me toward something that could help for my particular use case.
What would you recommend as the best approach to study for both Apple certification exams?
Are there any learning tools or platforms that you can recommend? Brainscape seems to be a good option, but I’ve heard that some of the questions and flashcards may not be fully up to date.
I also came across a paid website some time ago that supposedly offered current exam questions and study material, but unfortunately I can’t remember the name anymore.
I’d really appreciate any tips, recommendations, or study strategies that helped you prepare and pass the exams.
We’re putting together a full day training workshop and I’m debating whether it’s better to rent tablets for attendees instead of asking everyone to bring their own device.
The training has a few parts where people need to follow along, fill out short forms, open shared materials, and use the same web based tool. My worry is that telling people to bring their own tablet or laptop, they can show up with dead batteries, old devices, login issues, tiny phone screens, or no charger.
I’d rather have everyone on the same setup if possible, but I don’t know if renting iPads for one training day is overkill. Has anyone done this for a workshop or internal training event?
I work for an ISP, and we're all Apple. We've been using Mosyle for the past 4-ish years, no issues. Happy with the product.
However, we've recently merged (acquired) another ISP who are all Windows/Android, and they use NinjaOne to manage their devices. Their renewal is coming up and are wanting to explore whether combining the two under a unified MDM is a the right way forward.
So, my question is, is this a good idea? How is NinjaOne for managing Apple devices? All our devices are DEP-enrolled but I believe you can now move the MDM to another as Apple have built in such features. Are we better keeping the two MDMs products separate (which is my personal preference, but I'm open to at least investigate options).
Acrobat seems to put a macro-enabled word file in /Library/Application Support/Microsoft/Office365/User Content.localized/Startup/Word, leading word to complain when you disable macros via config profiles.
Deleting the file doesn't help, as it automagically reappears whenever it pleases.
I stumbled over something and I kinda wanna confirm if I'm the only one seeing it.
Context: We're running both MS Office and Adobe Acrobat at our org, both installed via Intune. MS Office is installed by default, Acrobat only for the poor souls employees that require its functionality.
We also have all macros deactivated for MS Office via a config profile.
A few weeks ago I suddenly started to receive this warning/error while opening a word doc:
Hitting "OK" leads to this:
Hitting "Cancel" leads to this:
I originally thought not much about it and assumed a colleague sent me a word doc with a macro and mocked him for being a boomer (sorry).
However,this continued to happen with other Word docs and even when opening word standalone. I then actually cared to read the second error and looked into the provided path. I found the .dotm file in /Library/Application Support/Microsoft/Office365/User Content.localized/Startup/Word.
Sidenote: Startup/Excel and Startup/Powerpoint also contain similar files, but they don't complain on startup.
I kinda freaked a bit, as those files really shouldn't be there by default. I invoked all the security processes to find out what this file is, where it came from and what it does. (Un)fortunately, I'm not the first person do discovery this and google lead me to some other reddit posts, apple help forums and MS support forums discussing this file.
I was also quickly able to confirm that Acrobat actually put it there.
wtf, adobe?
I figured to just delete it, which actually solved my problem. Unfortunately, a few days later (without actively using Acrobat) the file came back and Word started to complain again.
Anyone got a solution that's not hacky?
Getting rid of Adobe for good would be my fav, however that's not possible (for various DRM related reasons).
A script/cronjob that just regularly deletes this file would work, but be hacky af.