Sponsor
This issue of MacAdmins.news is exclusively brought to you by Mosyle, the only Apple Unified Platform.
Mosyle is the only solution that integrates in a single professional-grade platform all the solutions necessary to seamlessly and automatically deploy, manage & protect Apple devices at work . Over 45,000 organizations trust Mosyle to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple .
📸 Focus
In the last two weeks, I got to participate and present five presentations at two MacAdmins meetings and two JamfNation Live events in Haarlem, Amsterdam and Berlin. Many thanks to everyone who helped prepare and organize these events, those who presented with me, and all of you who came up to talk to me afterwards. It is wonderful to experience the great community that we all get to be a part of.
This has kept me from digging deep into the details from the WWDC news, but I did want to share some first impressions and also review how my wish list from two weeks ago fared.
The User Perspective
Before I dive into the system administrator perspective of Apple's 2024 platform upgrades, here are a few of my impressions as a user of these platforms.
First, after years of flattening and monochrome-ing the user interface, we are getting some depth and color back. Apple's preview pages have some examples, like Control Center, the new Password app interface and the Message Tapback icons. It's a subtle change, but personally I am glad that this particular pendulum is turning back again.
On iPadOS, Math Notes and other handwriting improvements are really interesting. But I am disappointed that there are no major improvements to iPadOS to enable this platform to use the potential of its hardware. Maybe next year…
Apple is using the term Apple Intelligence to cover a set of new different features powered by machine learning across all platforms. I appreciate that Apple is pushing the boundaries what happens on-device, even though the hardware requirements are steep, especially on the iPhone, where they require the A17 Pro which only the iPhone 15 Pro has. On iPad and Mac the baseline is the M1 chip, which seems more reasonable. Remarkably, no mention of Apple Intelligence on visionOS.
The writing tools look quite useful, and the new Siri functionality feels long overdue. The work Apple has put into Private Cloud Compute is very impressive. I am curious how this might affect Apple's energy usage and their desire to become carbon neutral.
Aside from the Apple Intelligence features, most of which will not be rolled out with the upgrades in the Fall, but over time, the 2024 releases are not huge feature laden releases. This is a good.
The Mac Admin Perspective
This also shows in the news related for IT. This year, there was only a single session dedicated to managing Apple Devices. Nevertheless, Apple introduced some solid improvements.
Because I have heard the questions already, there do seem to be restrictions that admins can use to turn off the new features, especially the Math Notes and writing tools, as well as the ChatGPT integrations. We will have to test if they are sufficient and file feedback quickly in case they aren't.
As I had wished for, there seems to be not only a way to deploy and manage LaunchDaemons, but admins will be able to do so in way that prohibits tampering from users, even when they have admin privileges. This will require support from the MDM solution, but I can't wait to test this and experiment.
Platform SSO should now also work at the Filevault unlock window (check that off the wish list!), but no iPad support yet. The DDM based Software Update management gains some new features, which remove the reliance on older pre-DDM commands and profiles to manage updates, once your fleet is entirely upgraded to macOS 15 and iOS 18.
Managed Apple IDs (MAIDs) are now called Manage Apple Accounts (MAA) and we all have to rewrite our documentation. Apple Business Manager and Apple School Manager will receive a welcome new feature that allows orgs to clear an activation lock, but no news on when Apple Business Essentials and the related services, like more iCloud storage and managed AppleCare will be available outside the US or to other management systems.
Once again, I am missing improvements for managed deployments of app subscriptions or in-App purchases. I guess that will go into my Enterprise Report Card survey for the fifth year.
Overall, these look like solid upgrades, but Apple seems to have gotten the balance right, it does not look like there are going to be too many disruptions. We now have three months with a lot of testing and filing feedback ahead of us!
A New Beginning
As an Apple nerd, the week of WWDC is both a great and a terrible time to launch something new.
Always exciting to see a new blog by a former co-worker!
WWDC 2024 - First Thoughts on First Looks
Here are a few of the biggest highlights and changes we are most excited about
WWDC 2024: What Apple Admins Need to Know
there were plenty of other announcements that Apple IT admins need to know about.
📰 News and Opinion
Apple Has 'Very Serious' DMA Issues, EU to Enforce Rules 'Soon'
Apple is facing a "number" of "very serious" issues with its Digital Markets Act compliance in Europe
More info in Michael Tsai's summary.
I Will […] Piledrive You If You Mention AI Again
Wonderful, if expletive-laden, rant about the current AI craze.
Mac Admins Foundation Announces Mentorship Pilot Program
The Mac Admins Foundation […], is excited to unveil its pilot mentorship program.
⚙️ Apple Updates
- Final Cut Pro: Mac 10.8, iPad 2.0, What's new (Mac), What's new (iPad)
🔐 Security and Privacy
How Twitch Helper Can Be Used for Privilege Escalation
there have been many examples of XPC being abused due to a lack of validation or authorization for communications between it and helper binaries. In this post, we will look at one such example: the helper for the Twitch Studio app.
🔨 Support and Tutorials
Adobe Admin Console Packages
bundle packages were deprecated in macOS 14.4 and if you’re testing macOS Sequoia (and you really should be), you’ll find that bundle packages are no longer supported.
Does Sequoia’s Password app change keychains?
code such as LaunchDaemons and LaunchAgents that don’t run in a user context, but through launchd, can’t currently access a Data Protection keychain, and must rely on file-based keychains. Traditional keychains aren’t going away yet.
🤖 Scripting and Automation
Using Wi-Fi hardware network interface information with Jamf Pro to identify macOS virtual machines
how to reliably identify a virtual machine.
AutoPkg Pre/Post-Processor Security Considerations
This post explores how custom AutoPkg processors are potentially vulnerable when used as pre/post-processors.
📺 Watch
Down the Rabbit Hole: How to set the computer name (MacAD.Uk 2024)
My presentation from MacAD.UK this year is now available on YouTube for all to (re-)view! Presentation notes, links and slides are available here.
🎧 Listen
The Latest on MITRE ATT&CK with Cat Self
In this episode, we’ll talk about security, ATT&CK, and the changing landscape of Mac security with one of our favoritest guests, Cat Self.
(Almost) everything you always wanted to know about cybersecurity, but were too afraid to ask, with Tjitske de Vries
we speak with Malwarebytes Product Marketing Manager Tjitske de Vries about the modern rules around passwords, the difficulties of stopping criminals on the dark web, and why online scams hurt people far beyond their financial repercussions.
The ACEs 2024 Debrief We Never Knew We Needed
Joe and co-hosts Sam and Jerry debrief the ACEs Conference 2024.
WWDC recap
I talk with Alcyr Araujo from Mosyle about Apple's WWDC announcements that affect Apple IT teams.
How will sideloading apps affect IT teams?
Apu Pavithran from Hexnode about the potential risks for Apple IT managers when it comes to sideloading apps on iOS.