Post

Replies

Boosts

Views

Activity

Notes from Security lab (Wednesday, June 9th 2021)
Question: As of macOS Big Sur, it is not required for an installer package to be signed or notarized in order for it to be installed via Installer.app or the installer command line tool. Is this still the case on macOS Monterey? If it is not, what requirements have changed? Answer: Restrictions are the same as on macOS Big Sur for installer packages with regards to notarization. Question: Is there any additional guidance from Apple on the installation and use of multiple solutions using System Extensions and/or Network Extensions when it comes to co-habitation? For example, is it supported by Apple to have two "Network Filters" (each managed by a separate application) installed and active? Answer: Having multiple network system extensions installed is supported by Apple. Multiple content filters are supported on iOS and macOS: iOS: 2 filters maximum macOS: 8 filters maximum Question: As of macOS Big Sur, it is not required for an application to be signed or notarized in order for it to be installed or run on an installation of macOS with Apple's full security settings enabled. Is this still the case on macOS Monterey? If it is not, what requirements have changed? Answer: Restrictions on macOS Monterey are the same as on macOS Big Sur for applications with regards to signing and notarization. Question: What are Apple’s plans, if any, to support Azure AD workplace join as a replacement for on-premise Active Directory binding? Answer: We see you're also signed up for the Friday Security lab, we'll see if we can get this question answered there. Question: What are Apple's plans, if any, to support using Apple's own two-factor authentication system (not the two step one which uses SMS) to log into a Mac running macOS Answer: We see you're also signed up for the Friday Security lab, we'll see if we can get this question answered there.
1
0
926
Jun ’21
Notes from Custom app distribution and device management lab (Wednesday, June 9th 2021)
Question: Will Apple be eliminating the use of kernel extensions on macOS Monterey? Answer: No. In general, restrictions are the same as on Big Sur but as Apple adds new APIs for system extensions, new restrictions may be added for kernel extensions. If kexts are whitelisted by MDM, behavior is the same as on Big Sur. Question: Does Apple have any plans to support “managed” migration assistant so supervised devices can easily transfer user data from old to new macs without compromising MDM enrollment. Managed with a profile to ensure only specific data can be migrated would be very helpful. Answer: Not at this time, please submit feedback if you want this feature. Question: Is there any additional guidance from Apple on the installation and use of multiple solutions using System Extensions and/or Network Extensions when it comes to co-habitation? For example, is it supported by Apple to have two "Network Filters" (each managed by a separate application) installed and active? Answer: Having two network filters installed and active is supported by Apple. Consult with your vendor or vendors for best practices. Question: Can admins enforce software update deferrals for X number of days after they’re released by Apple, rather than X number of days after a given device first sees the software updates? Answer: Software deferral is based on the date metadata associated with the update and that's in macOS today. Question: Can admins force Mac users to install software updates on macOS Monterey without interrupting users with a surprise reboot? Desired state is to gracefully prompting users to install mandatory updates, but also have those updates have an admin-chosen deadline where the updates get installed automatically without further deferral. Answer: There are a number of changes in macOS Monterey which address these concerns. Please see the "Manage software updates in your organization" session video. One change is that you can schedule using the marketing version number instead of a product key. For example, you can now specify "macOS 12.1" instead of a specific product key. Question: Are printer drivers still supported in macOS Monterey? Answer: Yes. Question: Since Apple Silicon Macs technically can support NetBoot, can NetBoot be restored as a device provisioning tool? Answer: NetBoot is not supported as a mechanism for macOS provisioning on Apple Silicon Macs. Question: What are Apple’s plans, if any, to support Azure AD workplace join as a replacement for on-premise Active Directory binding? Answer: Apple can't comment on future plans. Please submit feedback if you want this feature. Apple does offer the Kerberos extension for connecting to on-premise Active Directory.
0
0
962
Jun ’21
WWDC 2021 notes by rtrouton
Notes from What's new in managing Apple Devices (Tuesday, June 8th 2021): https://developer.apple.com/forums/thread/681765
Replies
9
Boosts
0
Views
2.9k
Activity
Jun ’21
WWDC 2022 notes by rtrouton
Notes from What's new in managing Apple Devices (Tuesday, June 7th 2022): https://developer.apple.com/forums/thread/707518
Replies
9
Boosts
0
Views
4.1k
Activity
Jun ’22
WWDC 2023 notes by rtrouton
Notes from What's new in managing Apple Devices (Tuesday, June 6th 2023): https://developer.apple.com/forums/thread/731076
Replies
8
Boosts
3
Views
2.4k
Activity
Jun ’23
Notes from Custom app distribution and device management lab (Thursday, June 9th 2022)
I took notes during the "Custom app distribution and device management" lab. If interested, please see the attached "Notes from lab": Notes from lab
Replies
2
Boosts
0
Views
1.5k
Activity
Jun ’22
Notes from What's new in managing Apple Devices (Tuesday, June 6th 2023)
I took notes during the "What's new in managing Apple Devices" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc23/10040
Replies
2
Boosts
2
Views
2.1k
Activity
Jun ’23
Notes from Manage Devices with Apple Configurator (Wednesday, June 9th 2021)
I took notes during the "Manage Devices with Apple Configurator" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc21/10297
Replies
1
Boosts
0
Views
1.4k
Activity
Jun ’21
Notes from Security lab (Wednesday, June 9th 2021)
Question: As of macOS Big Sur, it is not required for an installer package to be signed or notarized in order for it to be installed via Installer.app or the installer command line tool. Is this still the case on macOS Monterey? If it is not, what requirements have changed? Answer: Restrictions are the same as on macOS Big Sur for installer packages with regards to notarization. Question: Is there any additional guidance from Apple on the installation and use of multiple solutions using System Extensions and/or Network Extensions when it comes to co-habitation? For example, is it supported by Apple to have two "Network Filters" (each managed by a separate application) installed and active? Answer: Having multiple network system extensions installed is supported by Apple. Multiple content filters are supported on iOS and macOS: iOS: 2 filters maximum macOS: 8 filters maximum Question: As of macOS Big Sur, it is not required for an application to be signed or notarized in order for it to be installed or run on an installation of macOS with Apple's full security settings enabled. Is this still the case on macOS Monterey? If it is not, what requirements have changed? Answer: Restrictions on macOS Monterey are the same as on macOS Big Sur for applications with regards to signing and notarization. Question: What are Apple’s plans, if any, to support Azure AD workplace join as a replacement for on-premise Active Directory binding? Answer: We see you're also signed up for the Friday Security lab, we'll see if we can get this question answered there. Question: What are Apple's plans, if any, to support using Apple's own two-factor authentication system (not the two step one which uses SMS) to log into a Mac running macOS Answer: We see you're also signed up for the Friday Security lab, we'll see if we can get this question answered there.
Replies
1
Boosts
0
Views
926
Activity
Jun ’21
Notes from Move Beyond Passwords (Wednesday, June 9th 2021)
I took notes during the "Move Beyond Passwords" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc21/10106
Replies
1
Boosts
0
Views
1.2k
Activity
Jun ’21
Notes from What's new in notarization for Mac apps - Tuesday, June 7th 2022
I took notes during the "What's new in notarization for Mac apps" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc22/10109
Replies
1
Boosts
0
Views
1.6k
Activity
Jun ’22
Notes from What's new in Endpoint Security - Wednesday, June 8th 2022
I took notes during the "What's new in Endpoint Security" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc22/110345
Replies
1
Boosts
0
Views
2.4k
Activity
Jun ’22
Notes from Explore advances in declarative device management (Wednesday, June 7th 2023)
I took notes during the "Explore advances in declarative device management" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc23/10041
Replies
1
Boosts
1
Views
1k
Activity
Jun ’23
Notes from What's new in managing Apple Devices - Tuesday, June 8th 2021
I took notes during the "What's new in managing Apple Devices" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc21/10130
Replies
0
Boosts
0
Views
2k
Activity
Jun ’21
Notes from Meet Declarative Device Management
I took notes during the "Notes from Meet Declarative Device Management" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc21/10131
Replies
0
Boosts
0
Views
1.6k
Activity
Jun ’21
Notes from Faster and Simpler Notarization for Mac apps (Wednesday, June 9th 2021)
I took notes during the "Faster and Simpler Notarization for Mac apps" session. If interested, please see the attached "Notes from session": Notes from session For the session video, please see the following link: https://developer.apple.com/wwdc21/10261
Replies
0
Boosts
0
Views
1.1k
Activity
Jun ’21
Notes from Custom app distribution and device management lab (Wednesday, June 9th 2021)
Question: Will Apple be eliminating the use of kernel extensions on macOS Monterey? Answer: No. In general, restrictions are the same as on Big Sur but as Apple adds new APIs for system extensions, new restrictions may be added for kernel extensions. If kexts are whitelisted by MDM, behavior is the same as on Big Sur. Question: Does Apple have any plans to support “managed” migration assistant so supervised devices can easily transfer user data from old to new macs without compromising MDM enrollment. Managed with a profile to ensure only specific data can be migrated would be very helpful. Answer: Not at this time, please submit feedback if you want this feature. Question: Is there any additional guidance from Apple on the installation and use of multiple solutions using System Extensions and/or Network Extensions when it comes to co-habitation? For example, is it supported by Apple to have two "Network Filters" (each managed by a separate application) installed and active? Answer: Having two network filters installed and active is supported by Apple. Consult with your vendor or vendors for best practices. Question: Can admins enforce software update deferrals for X number of days after they’re released by Apple, rather than X number of days after a given device first sees the software updates? Answer: Software deferral is based on the date metadata associated with the update and that's in macOS today. Question: Can admins force Mac users to install software updates on macOS Monterey without interrupting users with a surprise reboot? Desired state is to gracefully prompting users to install mandatory updates, but also have those updates have an admin-chosen deadline where the updates get installed automatically without further deferral. Answer: There are a number of changes in macOS Monterey which address these concerns. Please see the "Manage software updates in your organization" session video. One change is that you can schedule using the marketing version number instead of a product key. For example, you can now specify "macOS 12.1" instead of a specific product key. Question: Are printer drivers still supported in macOS Monterey? Answer: Yes. Question: Since Apple Silicon Macs technically can support NetBoot, can NetBoot be restored as a device provisioning tool? Answer: NetBoot is not supported as a mechanism for macOS provisioning on Apple Silicon Macs. Question: What are Apple’s plans, if any, to support Azure AD workplace join as a replacement for on-premise Active Directory binding? Answer: Apple can't comment on future plans. Please submit feedback if you want this feature. Apple does offer the Kerberos extension for connecting to on-premise Active Directory.
Replies
0
Boosts
0
Views
962
Activity
Jun ’21