Post

Replies

Boosts

Views

Activity

Reply to Forget network as a standard user
Appreciate the response. I appreciate and am aware of that part of the PSSO spec, however, sadly Microsoft does not currently support Group Management and Network Authorisation as part of their implementation. Please see: https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-scenarios-macos While my investigation on other IDP's is not recent, when I last checked, no IDP has implemented that feature. I appreciate that this spec would solve this issue, however considering it was announced at WWDC 2023 and the primary IDP Globally, Microsoft, still does not support it regardless of how many feature requests we have all made - Means that this feature practically does not exist for our orgs. I would love it if you could consider implementing a Device Management Solution for this issue, that would resolve this concern without relying on a third party and their languid development choices.
Topic: General SubTopic:
Business & Education Q&A
Jun ’26
Reply to Apple Classroom: Macs with standard accounts
I'm not the OP but this issue is extremely important to me and something I've spent countless hours on - So I'm going to jump in and provide some context. Possibly too much! FB23054233 Classroom on MacOS - Under-utilised due to circumvention and deployment issues. Preamble: Classroom app is a fantastic tool, the features and native integration are brilliant and the team should be commended but there are deployment blockers that stop it from being mass adopted. Issue: Classroom on macOS is under-utilised due to being too easy to circumvent by Students or too difficult to configure for IT Admins. Background: 
Please note that everything I’m discussing is on Multi User Lab or 1:1 School Owned, ASM Registered, Supervised Devices Managed through a Device Management Service.
 For simplicity Sake, Classroom requires 3 Things: Same Network, Bluetooth On & Classroom/Education Config.
 Classroom can be configured via three methods. Ad-Hoc: Leaves configuration to teacher, creates support overhead and is not scalable. Education Configuration Profile: Deployable via MDM. EDU Configs set Student / Teacher Relationship without Managed Apple Accounts. Fantastic for organisations unable to use Managed Apple Accounts or for Lab Machines. ASM Class Data Synced via Managed Apple Account: Requires User to be signed in with Managed Apple Accounts. Circumvention Methods: 
1. Students Changing Wifi Network - Students are able to change Wifi Networks during School Hours to other networks, dropping the ability for Classroom to function. All Methods of Classroom Configuration Effected. Solution: FB17222601 Provide forceWifiToAllowedNetworksOnly restriction key for macOS like we have on iOS.
 Students Turn Off Bluetooth - Students are able to change Bluetooth state dropping Classroom functionality. Existing allowBluetoothModification key freezes Bluetooth in current state, rather than setting it on or off. All Methods of Classroom Configuration Effected.

 Solution: FB17222612 Expand allowBluetoothModification restrict key to provide a set On / Off State.
 Students Signing out of their Managed Apple Account in Settings, dropping the Classroom configuration. This could be solved by restricting allowAccountModification but would require us to implement this only after a Managed Apple Account is signed in, which is not surfaced to the MDM/DDM spec. Similarly, The “Limit Device Sign in to Managed Apple Accounts” option within Apple School Manager is not graunlar enough as while this would solve the issue for Student Devices, our Staff cannot use their personal Apple Account which we want to allow. ASM Managed Apple Account Classroom Configuration Effected.

 Solution: FB18518306. Surfacing the ASM “Limit Device Sign In” control to MDM Vendors and being able to scope this to individual groups would solve this issue. Alternatively, surfacing the current logged in iCloud Apple Account to the MDM would allow us to then restrict the ability to sign out, once its logged in. This issue would also be resolved by using MDM Deployable Education Configuration Profile - See Below. 
 Education Configuration Profile Issues: While EDU Config profiles can stop users from circumventing Classroom control via signing out of their Managed Apple Account, they cannot be used in a vast variety of K-12 Use Cases due to the way User Accounts are typically created in these enviroments. The Education Profile requires the User Channel. User accounts created outside of the setup assistant, like using 3rd party Login Window agents, eg. XCreds, JamfConnect, Iru Passport, Mosyle Auth 2 etc are not MDM-Enabled and as such, cannot have User Channel profiles deployed to them. In our environment, we have a 1:1 Student Mac Program and some Lab Machines. All are using XCreds for initial user account creation due to the seamless workflow it provides and integration with our IDP & MDM stack. None of these accounts are MDM-Enabled and as a result, cannot use User Channel Profiles, rendering this method of Classroom management impossible. It is worth noting that in my testing, even if we migrated to PSSO, this would allow the 1:1 Users to become MDM-Enabled, allow for User Channel Profiles and configure Classroom in this manner but this is not the case for our Lab machines. Any secondary users created, after the first user, are not MDM-Enabled. As there is no way at the Device Management Service level to manage the users MDM-Enabled status, these lab machines cannot be managed in this way. 

As an alternative, if we attempted to use ASM Classroom Configuration with Managed Apple Accounts, it would require the student users of the Lab machines to log into the machine with their MAA. This is a non-functional solution as it both takes time away from the lesson and it supposes that the students will not realise that the MAA provides the Classroom management and refuse to log in. Solution: FB17222496 Resolve the underlying User Channel issue in some way, by allowing MDM’s to mdm-enable users or create a framework to allow users created outside of the setup assistant to become mdm-enabled.
Topic: General SubTopic:
Business & Education Q&A
Jun ’26
Reply to Forget network as a standard user
Not OP but I submitted one for this. I'm in the same boat and wish a Device Management Service could handle the small but annoying calls to authorizationdb that we need to do on every Mac. The only two I can think of right now are Forgetting a Network and Adding a Printer. FB23048818. Thanks for everything you all do.
Topic: General SubTopic:
Business & Education Q&A
Jun ’26
Reply to MDM Support for Enabling Location Services on Managed Macs
While I can't talk for the OP, it sounds like one of their end goals might be to have forceWifiToAllowedNetworksOnly on macOS, as you've suggested. If thats the case I can wholeheartedly agree with this request. We are a K-12 1:1 Managed Mac School and this key coming to macOS would solve a variety of issues. Example: The Classroom app is entirely dependant on the student being on the same network. Forcing Student devices to only connect to managed networks during school hours, removes their ability to switch SSID's to circumvent Classroom management. Feedback was submitted for this last year. FB17222601
Topic: General SubTopic:
Business & Education Q&A
Jun ’26
Reply to Forget network as a standard user
Appreciate the response. I appreciate and am aware of that part of the PSSO spec, however, sadly Microsoft does not currently support Group Management and Network Authorisation as part of their implementation. Please see: https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-scenarios-macos While my investigation on other IDP's is not recent, when I last checked, no IDP has implemented that feature. I appreciate that this spec would solve this issue, however considering it was announced at WWDC 2023 and the primary IDP Globally, Microsoft, still does not support it regardless of how many feature requests we have all made - Means that this feature practically does not exist for our orgs. I would love it if you could consider implementing a Device Management Solution for this issue, that would resolve this concern without relying on a third party and their languid development choices.
Topic: General SubTopic:
Business & Education Q&A
Replies
Boosts
Views
Activity
Jun ’26
Reply to Apple Classroom: Macs with standard accounts
I'm not the OP but this issue is extremely important to me and something I've spent countless hours on - So I'm going to jump in and provide some context. Possibly too much! FB23054233 Classroom on MacOS - Under-utilised due to circumvention and deployment issues. Preamble: Classroom app is a fantastic tool, the features and native integration are brilliant and the team should be commended but there are deployment blockers that stop it from being mass adopted. Issue: Classroom on macOS is under-utilised due to being too easy to circumvent by Students or too difficult to configure for IT Admins. Background: 
Please note that everything I’m discussing is on Multi User Lab or 1:1 School Owned, ASM Registered, Supervised Devices Managed through a Device Management Service.
 For simplicity Sake, Classroom requires 3 Things: Same Network, Bluetooth On & Classroom/Education Config.
 Classroom can be configured via three methods. Ad-Hoc: Leaves configuration to teacher, creates support overhead and is not scalable. Education Configuration Profile: Deployable via MDM. EDU Configs set Student / Teacher Relationship without Managed Apple Accounts. Fantastic for organisations unable to use Managed Apple Accounts or for Lab Machines. ASM Class Data Synced via Managed Apple Account: Requires User to be signed in with Managed Apple Accounts. Circumvention Methods: 
1. Students Changing Wifi Network - Students are able to change Wifi Networks during School Hours to other networks, dropping the ability for Classroom to function. All Methods of Classroom Configuration Effected. Solution: FB17222601 Provide forceWifiToAllowedNetworksOnly restriction key for macOS like we have on iOS.
 Students Turn Off Bluetooth - Students are able to change Bluetooth state dropping Classroom functionality. Existing allowBluetoothModification key freezes Bluetooth in current state, rather than setting it on or off. All Methods of Classroom Configuration Effected.

 Solution: FB17222612 Expand allowBluetoothModification restrict key to provide a set On / Off State.
 Students Signing out of their Managed Apple Account in Settings, dropping the Classroom configuration. This could be solved by restricting allowAccountModification but would require us to implement this only after a Managed Apple Account is signed in, which is not surfaced to the MDM/DDM spec. Similarly, The “Limit Device Sign in to Managed Apple Accounts” option within Apple School Manager is not graunlar enough as while this would solve the issue for Student Devices, our Staff cannot use their personal Apple Account which we want to allow. ASM Managed Apple Account Classroom Configuration Effected.

 Solution: FB18518306. Surfacing the ASM “Limit Device Sign In” control to MDM Vendors and being able to scope this to individual groups would solve this issue. Alternatively, surfacing the current logged in iCloud Apple Account to the MDM would allow us to then restrict the ability to sign out, once its logged in. This issue would also be resolved by using MDM Deployable Education Configuration Profile - See Below. 
 Education Configuration Profile Issues: While EDU Config profiles can stop users from circumventing Classroom control via signing out of their Managed Apple Account, they cannot be used in a vast variety of K-12 Use Cases due to the way User Accounts are typically created in these enviroments. The Education Profile requires the User Channel. User accounts created outside of the setup assistant, like using 3rd party Login Window agents, eg. XCreds, JamfConnect, Iru Passport, Mosyle Auth 2 etc are not MDM-Enabled and as such, cannot have User Channel profiles deployed to them. In our environment, we have a 1:1 Student Mac Program and some Lab Machines. All are using XCreds for initial user account creation due to the seamless workflow it provides and integration with our IDP & MDM stack. None of these accounts are MDM-Enabled and as a result, cannot use User Channel Profiles, rendering this method of Classroom management impossible. It is worth noting that in my testing, even if we migrated to PSSO, this would allow the 1:1 Users to become MDM-Enabled, allow for User Channel Profiles and configure Classroom in this manner but this is not the case for our Lab machines. Any secondary users created, after the first user, are not MDM-Enabled. As there is no way at the Device Management Service level to manage the users MDM-Enabled status, these lab machines cannot be managed in this way. 

As an alternative, if we attempted to use ASM Classroom Configuration with Managed Apple Accounts, it would require the student users of the Lab machines to log into the machine with their MAA. This is a non-functional solution as it both takes time away from the lesson and it supposes that the students will not realise that the MAA provides the Classroom management and refuse to log in. Solution: FB17222496 Resolve the underlying User Channel issue in some way, by allowing MDM’s to mdm-enable users or create a framework to allow users created outside of the setup assistant to become mdm-enabled.
Topic: General SubTopic:
Business & Education Q&A
Replies
Boosts
Views
Activity
Jun ’26
Reply to Forget network as a standard user
Not OP but I submitted one for this. I'm in the same boat and wish a Device Management Service could handle the small but annoying calls to authorizationdb that we need to do on every Mac. The only two I can think of right now are Forgetting a Network and Adding a Printer. FB23048818. Thanks for everything you all do.
Topic: General SubTopic:
Business & Education Q&A
Replies
Boosts
Views
Activity
Jun ’26
Reply to MDM Support for Enabling Location Services on Managed Macs
While I can't talk for the OP, it sounds like one of their end goals might be to have forceWifiToAllowedNetworksOnly on macOS, as you've suggested. If thats the case I can wholeheartedly agree with this request. We are a K-12 1:1 Managed Mac School and this key coming to macOS would solve a variety of issues. Example: The Classroom app is entirely dependant on the student being on the same network. Forcing Student devices to only connect to managed networks during school hours, removes their ability to switch SSID's to circumvent Classroom management. Feedback was submitted for this last year. FB17222601
Topic: General SubTopic:
Business & Education Q&A
Replies
Boosts
Views
Activity
Jun ’26
Reply to Software Updates in Education
FB23047699 - Adding onto the pile.
Topic: General SubTopic:
Business & Education Q&A
Replies
Boosts
Views
Activity
Jun ’26