/r/macsysadmin
A subreddit for all things related to the administration of Apple devices.
The reddit for Mac Professionals.
Please keep all content and discussions professional.
/r/macsysadmin
Hello Sys Admins,
I manage a growing startup with about 20 MacBooks under management. We use Mosyle with Google Workspace Federation for user accounts.Anytime a user forgets to sync their updated Google password to their local account, it creates lockouts that are very difficult to troubleshoot (due to FileVault).
If the user has rebooted their machine and it does not reconnect to WiFi, there is no way to send a local account password update to the device.
A few times, I have had the user log in to the local admin user account to reset the local password, but obviously, this isn't scalable or secure.
Does anyone have some good suggestions on how to properly manage these cases and unlock employees who forget their local password more easily?
I have a small team (less than 3 MacBooks) in my small business. Looking for a recommendation on managing such a small number of devices. I will want to be able to manage them (software installs, software updates, etc) and wipe them if needed. I trust the team so I don’t need to go crazy with locking them down.
I also need a recommendation on how I should handle Apple IDs on the devices. I assume it is better to not allow them to sign into their own Apple IDs since they are company owned devices?
Thanks for any thoughts.
I provide support for various different MDMs. InTune is still a little new to me. I got pointed out to a feature in iTUnes where you can update cellular plans through the MDM with iOS/iPadsOS. As far as I'm aware, our partnership with our major cellular provider can do that for them. Can anyone explain what that feature is mainly used for?
I have a work MacBook that I created an apple account specifically for and received admin rights from the company for it. Then I logged into my personal apple account to make it easier to work from my other apple devices. Now I’m trying to install the new update and got the “Authentication failed” message after entering my MacBook’s password so I figured I should switch to the account I got the admin rights on but it won’t log me back in because the MacBook password is required and I keep getting the same message. What should I do now?
Hello,
Is there a way to use Jamf composer to import a list of projectors (in the format that Epson iProjection wants) into the app installation package?
Ultimately is there a way to use Jamf composer to include a file that the app will be able to use by default?
I am reaching out on the Jamf side as well.
“The available software updates have changed. Try again or contact Apple support for assistance”
This error seems to be happening on Mac’s updating to 15 from 14.7.1. It seems to also be happening on only Intel Mac’s. Has anyone experienced this
I am a little lost here, My company has tasked me with finding an Apple MDM solution for our multi tenant organization. We currently use Intune to manage our windows devices and our Mac devices are in Intune as well. I am looking at Jamf pro and Mosyle Fuse for our Mac MDM, but I am unsure about a few things. None of our Macs are in ABM , I just created an account for our organization , If we go with one of the above Apple MDM's what does migration from Intune look like? How do we get our devices into ABM without having to wipe it clean?
Hi all,
So I want Mosyle to create the standard user account and create the admin account as a local account during set up. I believe I’ve configured everything correctly but the account isn’t showing up. Any insight on what I should check?
I am a helpdesk guy in a small company (just me and my boss in IT) and had a user who is usually remote and uses an AD joined Macbook pro. She has had issues where after restarting her computer she gets locked out of her account. We have to log into the admin account and then log out (while on premises) and then she can log in.
I did some digging and asked my boss some questions and we found this( scroll to the bottom and you will see that apple responded and said using sysadminctl as the expected resolution):
The user has changed their password(away from the mac) in the past and I am assuming since we did not do this whole sysadminctl thing, the secure token is still attached to the old password and she cant login when she resets after being away from the DC for a while because it uses that secure token like a cached credential. I might be butchering it, and I know this whole Mac/AD setup is going to have issues naturally, but it seems that Apple is fine with having to manually change the password by having the user password and the admin password entered (do you give the user the admin creds? do they give you their password? Is this Kosher?) all to be able to have the secure token update and match with the new password, because for some reason it doesn't do it automatically. This is a quote from that thread where Apple responded to someone with the same issue: "If you don't have FileVault enabled (when changing mobile AD passwords away from the Mac), there is no mechanism to automatically update the the SecureToken password and you would need to update the SecureToken password manually with sysadminctl. This is expected behavior."
I am just a curious level 1 guy trying to understand if this is actually good security practice or if this is apple just not wanting to deal with this kind of stuff.
Hi All,
Im a Systems Administrator for a university.
We are getting an odd issue that I can’t quite narrow down. We are a macOS only environment and using a Konica Minolta 4065 with an attached finisher (booklet maker).
We push out the printer drivers to our lab Mac Studios and BYOD MacBooks using Jamf.
The issue most people are having is while printing and then using the finishers print menu by going file -> print > printer options -> fiery features -> and clicking “Full properties”. Another window opens without issue, but when you click the option “define custom cover” which should popup another menu the entire “full properties “ crashes and doesn’t allow you back in until you close the application and reopen it.
This button is supposed to allow you to use a piece of cardstock as the front and back cover if that matters.
I have tried creating another user account with success, so a new user account on the same Mac seems to work, as in doesn’t crash when you bring up that window.
The application we are using is InDesign 2025 but it happens on everything including text edit.
What I am wondering is what exactly is specific to the user account that the program or finisher could be trying to access that may be the problem? I tried to pull any printer related folders out of the Application support folder to no success.
Any ideas would be helpful.
Thanks!
Got a client with around 8000 images from various projects going back 20+ years. In a mess of folders. And the organization of them is somewhat lacking due to no one being in charge for 99% of that time. And at times (more often than you'd think) someone would want to mess around and just duplicate a folder than modify one file out of 20 in the new folder to not break a link someone else might have.
Arrrrrrg.
Is there a tool I can point at this folder and it search for all files of a certain type and do a binary test to see which are dups. Maybe after doing a file name match. Then give the option to delete all but one of them?
They are totally over breaking any links to get this done. These are mainly used for proposals and the people involved in this now are way more coherent and in sync in their process.
I've use dupguru at times for similar things but it is more based on comparing 2 folders. (Unless I'm missing something.) I have just one folder. The folder duplicating I mentioned might be 3 or 4 levels deep in any one project.
This is a one off process lasting maybe a week or few.
TIA
EDIT: SOLVED u/brywalkerx
Hi everyone. We have a suite of Macs enrolled into Intune using platform SSO.
Every time a new user logs on they are greeted by this very unresponsive window:
Is there any way to disable this?
I work at a school district. We mostly use Chromebooks and Windows devices, however we have a few labs at various schools that use shared Macs/MacStudios/MacBooks mostly for Audio/video/photo editing/production. We also have a small number of iPads mostly for communication devices. Currently all Mac devices just use a shared local user for students.
We’re currently using JAMF Pro for device management, linked with Apple School Manager for enrollment and license deployment. We have not done any kind of Azure AD integration with any Apple devices yet but plan to for the next school year.
I’m trying to weigh the pros and cons of using JAMF Connect (JC) vs Apple School Manager (ASM) for SSO with our Azure AD.
From what I’ve gathered, JC offers AAD login by syncing account and local password data with Azure, but accounts are still technically just local accounts and passwords can come out of sync.
ASM offers Apple Managed Accounts for all AAD users, allowing email/password login using said Apple accounts. I assume this would resolve a password sync issue since the Apple accounts would be synced with AAD, rather than just local accounts, but not sure.
We don’t have any current plans to utilize Apples app suite that requires Apple accounts (messenger, airdrop, etc), so I’m not sure how I feel about having a bunch of Apple managed accounts but if it means seamless AAD integration and no password sync issues that may be the direction to go.
I’d love to get some thoughts from anyone else using either of these solutions (or even anything else) and why you chose the solution for your school/org.
EDIT: One other note is we will likely need to continue to offer iPads for use WITHOUT AAD authentication.
Hey everyone,
I was wondering if anybody have the same issue.
On my Sequoia Mac, 15.3, I can not open some links in Safari in my Default Profile, but just my default profile. All other profiles work fine.
For example, in Jamf Pro, I can not open the Patch Management section and also not the software update link.
Anyone else same issue?
Hi Everyone, I'm currently pursuing a career as an eDiscovery Specialist, and I wanted to ask for your advice on some tools and training I’ve recently invested in. I’ve downloaded Paladin from SUMURI I buy for free but i need to create an account first in their website, as I’ve heard it’s a great free tool for forensic investigations, and I was wondering if it could be helpful in my career path as an eDiscovery Specialist.
Additionally, I recently took advantage of a 10% discount on SUMURI's Mac Forensics Survival Course (MFSC), which focuses on Mac forensics. Since Apple devices are frequently involved in eDiscovery cases, I feel this could be a valuable area to develop expertise in. Do you think the MFSC training is beneficial for someone in the eDiscovery field?
Finally, I noticed that SUMURI has other software like Recon Lab and Recon ITR on their shop page. From your experience, would investing in these tools help enhance my skills in digital forensics and eDiscovery?
I’d really appreciate any thoughts or recommendations from those who’ve used these tools or have experience in eDiscovery. Thank you for your guidance!
I have two users with M3 Macs that are bound to Active Directory. However, both accounts are showing locked out when they enter their credentials. I can’t find any information in AD about why they’re getting locked out. The only way both users can log in is using the admin account. I’ll log out and let the user enter their credentials, which allows them to log in to their local account.
Has anyone else experienced this issue before? If so, do you have any suggestions for resolving it?
Sorry if this gets asked often, how the hell is anyone doing this? Especially if you have machines that are off site / no line of sight to any infrastructure.
Anyone have this currently setup that could tell me how you’ve achieved this?
I am attempting to use this dock on my 2020 M1 Mac Pro. Everything is connecting other than the display which is not being detected.
I have tried plugging the dock into both a windows laptop and a Samsung phone with Dex and these also don’t detect a display.
No idea what’s going on here. Any help appreciated.
Anyone seeing this? These Macs can share a screen with no issues, but windows are green. Not seeing this w. M series Macs (all Macs are running 15.2/15.3 and latest version of Teams.)
Hi everyone,
I’ve set up an Apple Business Manager (ABM) account and created a user for one of our employees. Using this user account, I’ve successfully set up a used iPhone. However, the device cannot install any apps.
I suspect the solution lies under the "Devices" section in ABM, but I can’t access that area because it’s asking for a "Customer Number" or "Reseller ID," which I don’t have since the iPhone wasn’t purchased through an official reseller.
My questions are:
Any insights or advice would be greatly appreciated. Thanks in advance!
I'm having an issue with SUPERMAN where the first time it runs daily, it won't see that a user is logged in. After this first run, all subsequent runs can see the GUI user.
So, my two questions are:
SOLVED:
Turns out this is a known shortcoming of super and is on the feature list for upcoming versions. I implemented the changes suggested on the thread linked below and all is well! Thank you David London and sch4llfl3g3l!
After successfully having registered the device (1 year), the registration becomes "lost". When looking at the profile there's no assigned registration and company portal then prompts for a new registration.
This happened after an update with intune/company portal. I can successfully register the device again, but after a short while (30 minutes) it loosing the connection again.
We have the same settings, standard, for all mac's and the device seems to be compliant.
Anyone else experiences these fallouts? Is this a JAMF problem or intune?
For better or worse, I'm currently using the Kerberos SSO extension, pushed by a configuration profile in Jamf.
For the most part, it works as expected, but for 6 users (0.5% of the total) nothing seems to get it working properly - they don't see the key icon in the menu, and they don't get a token (unless they run kinit, but they still don't see the icon).
They all have the profile installed (so it's not an issue with profile installation), and they have all been restarted several times.
Really, I don't even know where to begin with this, so any help would be appreciated.
I have a 2024 MacBook Pro M3 which I have upgraded to MacOS Sequoia. However, when I erased my Mac and attempted a clean reinstall through Recovery, I was only offered to reinstall Sonoma, not Sequoia. If memory serves me correctly, in the past upgrading to a new OS also upgraded the Recovery, but not anymore. Does this mean that the only way to do a clean reinstall is to create a bootable drive?
Thanks.
But not from inside of the Mail app?
I'm open to a defaults write or similar from terminal or a profile.
But we don't use mail for anything and I don't want to set it up just to do this.
TIA
EDIT: Thanks. Plenty of useful information here. Especially the macadmins.software replacement.
So i've got a Macbook Pro 2020 with the error code 69624 when i try to format the disk as GUID with APFS partitioning.
Tried everything...
GUID with HFS+ works just fine, but i can't install any MacOS on that.
GUID with APFS creates the container but fails when it comes to the Volume creation (69624).
Tried zerodisk and then erasedisk - Same error...
Does anyone have a fix on this error?
Hi,
I am trying to enrol an iPad to ABM for the first time. I have MDM setup at Mosyle, verification went through and everything.
The iPad is wiped, I load up the network profile and configure everything through the Prepare button. But then a 400 error pops up with the SUPPORT PHONE INVALID tag line.
This is what Apple says on their website:
SUPPORT_PHONE_INVALID: The support_phone_number field in the uploaded profile is either empty or has exceeded the maximum allowed length (50 UTF-8 characters).
I didn’t find any place where I could import a support phone number when creating a profiles.
Do you have any ideas?
Getting reports of kernel panics of 15.2 , anyone else?