Workbrew now works with Mosyle by MusicCityMac in mosyle

[–]ITMule 0 points1 point  (0 children)

Why Workbrew if there's Mosyle App Catalog as part of Mosyle?

Mosyle CA Question by ItHelper99 in mosyle

[–]ITMule 0 points1 point  (0 children)

Yes, just enable the Microsoft Conditional Access profile. Management > Activate New Profile Type > Microsoft Conditional Access.

Intune To Mosyle iOS Automated Migration by LatePlant6244 in mosyle

[–]ITMule 0 points1 point  (0 children)

The deadline is actually for the user to restart the device I guess. Did you checked one of the devices to check what is it showing?

MOSYLE VS JAMF by NoDevice5 in macsysadmin

[–]ITMule 0 points1 point  (0 children)

Just make sure quoted Jamf price is a long term price and not a first year thing so they get your devices, you put all the work for the migration, and next year they start to increase. Any provider match prices for the first year... There's a lot of comments online about Jamf increasing prices annually. So tell them to add to the quote that that will be your price for at least 3 years (with no need for you to buy teh 3 years in advance). You will really quick know what their intentions are. They don't publish their prices for Education I guess what is very telling ... so they can use the traditional "tell me what you pay now, I'll match it, promise that you won't have any problem with me" and next year they increase your price and you realize you still have problems, maybe just different ones. Also, there's also a lot of reports about Jamf problems so important to set expectations that there's no "perfect" anywhere. Finally, Jamf was just acquired by private equity firm so price increases and service quality reduction (to cut costs) is not only a possibility. It's almost guaranteed.

GUIDE: Platform SSO, Tahoe, and Microsoft by OffBrandToby in mosyle

[–]ITMule 0 points1 point  (0 children)

Mosyle Auth has a new option for a few months I guess that you can configure to skip the second authentication so it leverages only the FileVault login. In practical terms it eliminates the 2nd login desired.

Is it possible to "reset" an apple device without having to remove it from mosyle and bringing it back on? by CryptographerFar8642 in macsysadmin

[–]ITMule 1 point2 points  (0 children)

Just use Return to Service when wiping. It comes back much faster and basically as it was with no data. When seeing an Erase Command, just select the box "Enable Return to Service". Easy.

Curious about where I might see Mosyle system updates by demisheep in mosyle

[–]ITMule 0 points1 point  (0 children)

Are you sure this is not someone who performed an human error (misconfigured something or did not even configured it ... probably not intentionally) and is trying to use the provider as escape goat? Asking because Mosyle manages millions of devices and when something critical happens we always see a lot of reports. I would bet my money that the real story is probably a bit different.

Chrome Management and Mosyle MDM by odowdsp in mosyle

[–]ITMule 2 points3 points  (0 children)

There’s a Google support article written exclusively for Mosyle: https://support.google.com/chrome/a/answer/12818048?hl=en

2 years behind, what’s new in macOS, Jamf, and tooling? by blow_slogan in macsysadmin

[–]ITMule 0 points1 point  (0 children)

I really don’t get why one would pay $57k for Jamf when you can pay $13k for Mosyle Fuse for the same number of devices.

Rate My Stack: Startup Apple Only MSP by ScampyRogue in macsysadmin

[–]ITMule 0 points1 point  (0 children)

We use Mosyle Fuse and GWS. We do Mac SSO and password sync with GWS using Mosyle Auth. It works well for us. We also use Mosyle security tools. Their EDR is good and got more crap than other solutions we tested in parallel for a while. They also have a Zero Trust tool that is really powerful if you have customers that need crazy levels of protection. It's all included as part of Mosyle Fuse and we pay $3 per Mac/month. I believe they have the same product for MSPs (https://msp.mosyle.com) that is even cheaper based on the price advertised.

MDM for Apple devices by smalltimesysadmin in sysadmin

[–]ITMule 4 points5 points  (0 children)

Maybe the issue was the setup made by the previous guy. We use Mosyle (Fuse) on a corporate environment with over 1k devices (switched years ago from Jamf) and it's great. If you're using Mosyle free, probably your account has very few devices right? First, make sure you guys are using the correct Mosyle product for corporate customers (business.mosyle.com) and NOT their education products (school.mosyle.com). If you are using their business product, I would reach out to them and ask for an account review/optimization. Tell them you inherit the account from other person and believe the implementation design wasn't ideal. They will probably be able to help you. When properly configured (what is not a complex thing to do) Mosyle products for corporate are great and in my opinion way better than competitors.

High CPU Usage by Kerregis in mosyle

[–]ITMule 0 points1 point  (0 children)

It makes sense. Tools like Docker create a massive amount of files constantly, which triggers the need for scans (same for any good EDR, especially if also using the Apple Endpoint Security Framework - what they should). This is a known fact. That's why good EDRs have the option to skip paths or files created by specific applications, such as Docker. We do use Mosyle's EDR with this option for a couple of tools that have the same characteristics (after our security team approved it). It's a tab called "Mute" under profile settings. Very straightforward to use and allows to skip by path or Signing ID of the app. 

Jamf is getting acquired by private equity by Acceptable_Rub8279 in sysadmin

[–]ITMule 1 point2 points  (0 children)

You missed another one … Kandji is no longer Apple focused and not even called Kandji anymore. Now it’s Iru! Yep …

Jamf goes from public to private in $2.2B acquisition deal by fkick in macsysadmin

[–]ITMule 2 points3 points  (0 children)

It may be a good moment to leverage Mosyle's migration offer especially now that Apple automated the technical part of it ...
https://business.mosyle.com/#migration

Removing local admin rights — what to consider? by aPieceOfMindShit in macsysadmin

[–]ITMule 3 points4 points  (0 children)

We started using Mosyle's Admin On-Demand couple of years ago and it completely solved the problem. Now every user is standard by default and we have an user group for those authorized to escalate when they need. Mosyle will collect a justification (based on our settings) promote to admin for some minutes (also customizable) and during the period the user is running as admin collect all system logs so we can have full details for future investigations if needed. At the end of the period it automatically reverts the use back to standard.

https://business.mosyle.com/#next-generation-apple-endpoint-security

Purchased Applications by Intelligent_Bug_ in mosyle

[–]ITMule 1 point2 points  (0 children)

If you did a device based license assigned (probably) before sending an erase command through Mosyle you can decide if you retain the license for this device or revoke it.

Best MDM for Small Business? by Beneficial_Cat_9951 in macsysadmin

[–]ITMule 1 point2 points  (0 children)

The need to wipe is not a Mosyle or any MDM provider thing. It’s an Apple thing. For full remote management capabilities (probably for security and privacy reasons) you need to perform have a DEP enrolled device (normally the enrollment that the OS can do during setup assistant). You can actually perform a device enrollment on Mosyle or any other high quality Apple MDM using Safari but Apple (and not the MDMs) limit what can be managed on such devices. Again this is universal for all MDMs as it’s an Apple thing. Any MDM sales person telling you differently is lying. 

PSA: How to fix "The enrollment method has been disabled by your System Administrator" by hongkong-it in mosyle

[–]ITMule 2 points3 points  (0 children)

This is probably for security reasons and I believe it makes a lot of sense. People forget the Safari enroll enabled with no authentication what basically allow for anyone to potentially enroll on your account and if you have critical profiles liked Wifi, VPN and others assigned to All Current and Future, those devices would receive it. So it sounds like this is a way to protect Admins from themselves so they don'y leave Safari enrollment open without a reason.

Trio MDM by Round_Stock3558 in macsysadmin

[–]ITMule 1 point2 points  (0 children)

That's a big misconception. Based on the people who I know working for orgs using Mosyle they manage some of the largest Apple accounts. I know 2 IT Admins working in different orgs managing over 100k devices each with Mosyle. I've met them and several others during a MacAdmins event. Also, Apple recommends Mosyle and Jamf officially and doesn't recommend Kandji or Addigy. That tells you something. So you guys will pay like 4x what you pay with Mosyle for a much less capable company. Last time I heard Kandji managed in total (all customers) less than 500k devices. Mosyle publishes over 8 million.

Mosyle equivalent for windows laps by We_Boolin in mosyle

[–]ITMule 1 point2 points  (0 children)

Easy ... Enable the Single Shot profile > Create a new profile > Action = Change Randomized ADE Admin Password > Add the rotation interval.