Sponsor
This issue of MacAdmins.news is exclusively brought to you by Mosyle, where High-Quality Apple Management & Security is made Surprisingly Accessible.
After helping thousands of organizations to migrate from other solutions to Mosyle, we've gained a unique perspective of all the concerns companies face when evaluating the migration of their Apple Management & Security solution. Based on this extensive knowledge, we've created the most comprehensive Migration Program in the Apple’s Management & Security market, addressing the most critical technical, financial, and strategic considerations involved in this pivotal decision. Check our website for more details!
So, I took a summer break last week, but it sure seems like hardly anyone else in the Apple and wider tech industry did.
Apple reported their quarterly results (reactions, shipped not just one, but two updates (macOS 14.6 and 14.6.1, iOS 17.6 and 17.6.1, etc.) and not just one, but two betas for the Fall releases (a first beta for iOS 18.1 and macOS 15.1 with Apple Intelligence (where available) and the fifth beta for for the .0 releases). The next episode of Apple/EU DMA saga was released (reactions), and Google Search was found to have abused their monopoly, which will have far reaching consequences for the entire tech industry.
There are some changes in macOS 15 that admins and users may not be so happy about. The process of installing apps and pkgs that are not signed or notarized is getting more complicated and apps that require screen recording privileges (which are necessary for screen sharing, or other functionality such as color pickers) will require frequent re-approvals. (reactions)
Please test these changes in your environments with your current betas and provide feedback where necessary! There is still a window to influence these decisions.
📰 News and Opinion
Existential thoughts about Apple’s reliance on Services revenue
In the most recent financial quarter, Apple generated $24.4 billion in revenue from Services. The Mac, iPad, and wearables categories together generated just $22.3 billion. Only the iPhone is more important to Apple’s top line than Services.
Updates to runtime protection in macOS Sequoia
In macOS Sequoia, users will no longer be able to Control-click to override Gatekeeper when opening software that isn’t signed correctly or notarized. They’ll need to visit System Settings > Privacy & Security to review security information for software before allowing it to run.
macOS Sequoia adds weekly permission prompt for screenshot and screen recording apps
Apple is rolling out a change that will require you to give explicit permission on a weekly basis to these types of apps, and every time you reboot your Mac.
Apple’s permissions features are out of balance
Here’s Apple’s problem: Apps that track your location, record the contents of your screen, or access your video camera or microphone have the potential to be deeply invasive and violate your privacy in innumerable ways. Since those features are also useful, Apple has built a system of permissions that Apps must request, and then users are prompted to be sure that an app should be granted that kind of access.
ICANN approves use of .internal domain for your network
The Internet Corporation for Assigned Names and Numbers (ICANN) has agreed to reserve the .internal top-level domain
Better late than never. Now that most orgs are moving their identity services to the cloud, and Active Directory integration is far less common, we have to worry less about .local
domains. But it is finally good to have an official alternative.
Apple Intelligence: What Mac Admins Need to Know
Apple will likely give MDM solutions like Kandji the ability to restrict access to Apple Intelligence; we’re still waiting for full details on that.
⚙️ Apple Updates
macOS
- macOS Sonoma 14.6 (22G80) and 14.6.1 (23G93): What's new, Developer Release Notes, Security (14.6), Enterprise
- macOS Ventura 13.6.9 (22G820) and 13.6.10 (22G830: What's new, Enterprise, Security (13.6.9)
- macOS Monterey 12.7.6 (21H1320): What's new, Enterprise, Security
- Safari 17.6: WebKit Features, Developer Release Notes, Security
iOS and iPadOS
- iOS 17.6.1: About, Enterprise
- iPadOS 17.6.1: About, Enterprise
- iOS and iPadOS 17.6: Developer Release Notes, Security
- iOS and iPadOS 16.7.10: iOS, iPadOS, Security (16.7.9)
Other Platforms
- watchOS 10.6: About, Developer Release Notes, Security
- tvOS 17.6: About, Developer Release Notes, Security
- visionOS 1.3: About, Developer Release Notes, Security
- HomePod Software 17.6: About
- Schoolwork 3.0.1
Guides
- Apple Platform Deployment: Welcome, What's new, Document revision history
🔐 Security and Privacy
macOS stealer posing as Loom may be linked to Crazy Evil group
we’ve recently uncovered a sophisticated and alarming threat spreading through Google-sponsored URLs. The threat, a stealer malware targeting macOS, poses as the popular application Loom, a widely used screen recording tool.
Beware of Fake Apple Updates: Fake iOS Update Research
Jamf Threat Labs explores how bad actors use fake iOS updates to maintain persistence on compromised devices.
InfoStealer Uses SwiftUI, OpenDirectory API to Capture Passwords
We wanted to take a close look at […] the stealer’s dropper, which is written in Swift and leverages APIs not seen in other recent stealers to capture and verify the user’s password.
🔨 Support and Tutorials
Empowering secure and seamless learning: Multifactor authentication without a smartphone
Traditional MFA processes are unrealistic for students, as institutions from primary schools to universities cannot expect every student to have a phone or device to deploy legacy MFA options.
MacOS and Certificate Bases Authentication
we’ll cover the Intune configuration for deploying root and SCEP certificates on macOS. Additionally, we’ll discuss how these settings impact the user experience.
Building a Strong macOS Foundation: A Guide for MDM Administrators
This guide provides an in-depth look at the basics of macOS, from its file system and user management to its security features and troubleshooting tips.
Blocking Apple Account login access in System Settings on macOS Sonoma
The scenario discussed was a computer lab, where the lab admin wanted to make sure that folks using the lab weren’t able to sign into their personal Apple Accounts on lab machines.
How long does Apple support Mac firmware?
But for how long does [Apple] support the firmware in each model?
Xsan Ventura & Sonoma upgrade failures and a workaround using profile “Magic”
We just discovered a way to get these updates and upgrades to work.
Apple Remote Desktop constant resizing
we run into a problem when connecting to a remove system via ARD where the window wildly resizes itself and eventually errors out
🤖 Scripting and Automation
Providing GlobalProtect portal address via macOS configuration profile on macOS Sonoma
with some work, it is possible to use a profile to provide the portal address information to the GlobalProtect VPN client. For more details, please see below the jump.
How to issue Restart Mobile Device command en masse and on predefined schedule leveraging Jamf Pro API
Have you ever been tasked with restarting your mobile device fleet on a schedule? Do you set yourself task reminders and issue the command using the Jamf Pro admin console?
Launching the macOS Tips app using URL links on macOS Sonoma
a custom URL scheme, which allows the Tips app to be opened by calling a particular URL
BeyondTrust EPM: Flexibilities
Easily assign macOS computers to a BeyondTrust Endpoint Privilege Management High, Medium or Low Workstyle Flexibility via a Jamf Pro Script Parameter
Also see the follow-ups: BeyondTrust EPM: Inspector and [BeyondTrust EPM: Racing Stripes(https://snelson.us/2024/08/beyondtrust-epm-racing-stripes/)
Using the Jamf Pro agent to set computer name to match the Mac's hardware serial number on macOS Sonoma
In a number of environments, Mac admins have chosen to use the Mac’s hardware serial number when naming the computer’s hostname (otherwise referred to as the computer name.)
Naming devices is one of those things that gets more complex the longer you think about it. I have some concerns with using the full serial number as the computer name, which I elaborated in my MacADUK presentation earlier this year, with solutions to those concerns.
Homebrew Version Extension Attribute
Yet another Jamf Pro Extension Attribute which returns the installed version of Homebrew
Understanding Jamf Pro API Roles And Clients
For Jamf Pro admins who currently automate the setting up of users and groups in new instances using the Jamf Pro API, I have demonstrated how we can instead manage the setting up of API Roles and Clients.
UPDATE: Using PowerShell with Jamf Pro API
with recent changes with Jamf Pro, the script that was posted in that article was no longer working to get a bearer token
♻️ Updates and Releases
Installomator Mate
Installomator Mate provides a graphical interface for searching available labels, configure settings and either copy the code to memory or export as a script to use in your workflows.
🎧 Listen
SIEM is not storage, with Jess Dodson
In the world of business cybersecurity, the powerful technology known as “Security Information and Event Management” is sometimes thwarted by the most unexpected actors—the very people setting it up.
The inside story of Y2K panic and the greatest cooperative effort ever
Nancy James about her upcoming book, Year 2000 - The Inside Story of Y2K Panic and the Greatest Cooperative Effort Ever
Managing Macs at MSPs with Ross Matsuda
Ross Matsuda joins the Podcast from Ntiva, where he manages a ton of Macs in a ton of different systems and ways.
Tech Upgrades, MFA Madness and More!
Sam talks about his recent trip to Las Vegas to see Dead & Co at The Sphere
Positivity and Practical Tips: Navigating Tech Challenges with New Insights
In this episode, we discuss a range of topics from VPN configuration issues with the UniFi system, to the advanced security features of iCloud.
MacStadium and Orka, with Chris Chapman
Chris Chapman joins us from MacStadium, […] to tell us all about Orka Desktop, help us understand VMs that can be defined in code, and how we can all have more performant and better testing environments!
It works 93% of the time
Rogers Sands from Wyebot about their new (Digital Experience Monitoring) software solution.
All You Need To Know About JNUC 2024
Our co-hosts and guests discuss what is staying the same with the conference, what is changing, and what is brand new.
🎈Just for Fun
Mac OS X Racho Cucamonga: Twilight
A year later, I wanted to return to Rancho and create an updated variation of the wallpaper.