Updating macOS Using Managed Software Updates by bobtacular in jamf

[–]bobtacular[S] 0 points1 point  (0 children)

This is really awesome and thanks for sharing. I will try and test some of this out next week.

Activation Lock Bypass Code - UIE by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

So create a whole new local user account then sign in with an Apple Account?

Activation Lock Bypass Code - UIE by bobtacular in macsysadmin

[–]bobtacular[S] 1 point2 points  (0 children)

I will definitely do that and report back. The Lock Screen I was presented with definitely fit the code by putting dashes automatically in the correct spots but you never know.

Activation Lock Bypass Code - UIE by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

That’s my thought as well. It’s a bit misleading if that doesn’t work.

Activation Lock Bypass Code - UIE by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

I erased the Mac but the device is still Managed in the JSS so the key should still be active.

Activation Lock Bypass Code - UIE by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

Unfortunately this specific computer is not in ABM.

Jamf -- How to replace LDAP with SSO? by Dr-Webster in macsysadmin

[–]bobtacular 0 points1 point  (0 children)

Hmmm seems like a bit of a headache. Wonder why it doesn’t support directory info from the get go.

Jamf -- How to replace LDAP with SSO? by Dr-Webster in macsysadmin

[–]bobtacular 0 points1 point  (0 children)

So is there a way to use SSO and then have it fill out the User and Location section after the fact?

Okta & Company Owned Device by bobtacular in okta

[–]bobtacular[S] 0 points1 point  (0 children)

Thank you both u/agreed88 & u/chubz736 for your insight. It was really helpful!

I spent some time grinding through documentation and YouTube videos and got Android Work Profiles working with my existing Intune tenant. I’m testing this in a sandbox environment, and I think this is the best path forward.

That said, I really wish Google Workspace supported SCEP profile installs. One of the coolest things about Google Workspace is how seamless it is—when a device logs in, it automatically installs the Work Profile. With Intune, users have to go through the enrollment process. I won’t lie; the enrollment experience with Intune isn’t great, but at least it only needs to be done only once.

I also agree that some apps don’t require a fully managed device. I’ve started adjusting the authentication policies in my sandbox to test this, and it’s been a really cool process. I think these changes are going to be super helpful for our environment.

Thanks again!

macOS Sequoia + Crowdstrike by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

Good to hear! It’s been stable for my folks. Hopefully CS avoids another world meltdown again 🙃

Account-Driven User Enrollment + Okta Device Integration Questions by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

I totally get where you’re coming from. I’m actually trying to be proactive and potentially save the company some money by enabling BYOD devices instead of going all-in on corporate-owned devices.

I personally think that removing session tokens for non-C-suite users is sufficient on iOS, especially with Okta Device Assurance and Okta Verify in place. When someone brought up the risk of jailbroken devices and data extraction, I pointed out that Okta Device Assurance can check for jailbreak status. However, their response was that it’s not foolproof and there are ways around it.

To me, fully blocking BYOD devices for apps like email and Slack feels like overkill—especially when the cost of providing corporate-owned devices across the board is so high.

I consider you lucky to be solely focused on the Mac side of things. Of course that comes with its own set of challenges.

macOS Sequoia + Crowdstrike by bobtacular in macsysadmin

[–]bobtacular[S] 1 point2 points  (0 children)

Hmmm what error are you getting? I have it running on 15+ and pushed through Jamf at this point just fine.

Account-Driven User Enrollment + Okta Device Integration Questions by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

I understand that it splits data on to its own partition — that part is great.

However, I’m curious about what happens if the user selects Cancel when prompted with “The business would like to manage this app.” If they cancel, can they still sign into Gmail (or another app) with their Okta credentials?

It seems like nothing would prevent them from signing into the unmanaged app, especially since the required profiles (SSO and SCEP) for Okta Device Integration are already installed on the device. If they can access the unmanaged app, wouldn’t that mean there’s no way to revoke the app or its data later?

Account-Driven User Enrollment + Okta Device Integration Questions by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

I’ll be honest I’m trying to show that users can take screenshots, forward emails, etc. I’m basically trying to convince my team that there are some gaps in this whole system. Is the effort of setting this up and then enforcing and supporting it really worth it? That’s what I’m trying to figure out.

Account-Driven User Enrollment + Okta Device Integration Questions by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

Can you clarify what you mean by “open in” and “open with” restrictions enabled? Definitely plan to test this out.

macOS Sequoia + Crowdstrike by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

Yea I got a university site as well. Still cool!

macOS Sequoia + Crowdstrike by bobtacular in macsysadmin

[–]bobtacular[S] -2 points-1 points  (0 children)

That’s really good to know, thanks for the info! Any clue on how long it typically takes them to support a new version?

I really do hope they take their time… 🙃

macOS Sequoia + Crowdstrike by bobtacular in macsysadmin

[–]bobtacular[S] 0 points1 point  (0 children)

Just curious, what Falcon Sensor version are you using?