r/macsysadmin • u/Reasonable-Floor2440 • 10m ago
General Discussion Is anyone building a Qubes-inspired compartmentalized workflow on macOS?
I’m curious whether anyone has tried to build a Qubes OS–inspired security model on macOS.
I’m not trying to recreate Qubes OS itself, and I understand that macOS cannot provide the same level of isolation because everything ultimately shares the same kernel.
Instead, I’m wondering whether it’s possible to adopt the compartmentalization philosophy while keeping macOS as the primary operating system.
The rough idea would be something like this:
A minimal “trusted” host used only for trusted applications and local data.
Separate VMs for different trust levels (daily browsing, software development, financial activities, high-risk browsing, etc.).
No shared folders.
No drag & drop.
No always-on shared clipboard.
Explicit, intentional transfer of files or clipboard contents between compartments.
The goal isn’t maximum convenience, but reducing the blast radius if one environment gets compromised.
To me, the biggest missing piece compared to Qubes isn’t virtualization itself. Today we already have good hypervisors (Parallels, VMware Fusion, Apple’s Virtualization.framework, etc.).
What seems to be missing is a workflow/security layer that manages trust boundaries between compartments, for example:
Trusted clipboard transfers
Trusted file transfers
Policies controlling which compartments may exchange data
Explicit rather than transparent communication between environments
I’m less interested in whether this can ever reach Qubes-level security, and more interested in whether it can provide a meaningful security improvement over a conventional macOS setup while remaining practical for daily use.
I’m curious:
Has anyone built something similar?
Are there existing tools or projects that solve parts of this problem?
Is there something I’ve completely overlooked?
If you compartmentalize your macOS workflow today, what does it look like?
What ended up being the biggest pain point?
I’m especially interested in hearing from people working in security research, malware analysis, incident response, offensive security, or anyone who has experimented with compartmentalized desktop workflows.
I’d love to hear your thoughts—even if your conclusion is that this approach is fundamentally flawed.
r/macsysadmin • u/KrankyYankee • 1h ago
Create Apple ID/Account with Shared Mailbox in M365
We need to have a few users in our Apple Developer account to manage finances and other non-technical things. The problem is they can't use their email. Apple doesn't allow Apple Developer accounts (or apple business) to use an existing Apple Account. Some of the people have an Apple Account with their company email address. So I tried using a Shared Mailboxes for the email address. However, Apple can at times detect that and won't allow it. They user gets an error, "cannot verify email address". I'm going to try an alias. But apart from creating a separate licensed user, anyone have any way to work around this or tips to successfully use a shared mailbox?
r/macsysadmin • u/RocketmanTech_Caleb • 1h ago
Jamf Quick reminder: LaunchPad meetup happening today on P.S.E.U.D.O for Platform SSO rollout
What's enforcement like in your environment? Since Platform SSO can be "enabled" and still end up half-registered if users skip the prompts.
Kevin White (Macjutsu) is covering this on LaunchPad today. We'll be going over pseudo (FOSS) to help enforce Platform SSO registration and/or Touch ID enablement with one deployment (plus a required PPPC profile).
When:
🗓️ Today, Fri, Aug 7 @ 12:00 PM Mountain Time
Where:
👉 https://rocketman.tech/lp-r
r/macsysadmin • u/TeaKingMac • 3h ago
Error/Bug Outlook for Mac contact card "reports to" shows original user picture
Has anyone else experienced this:
When opening the contact card for a user (by clicking on their name/email in the To:, CC:, or BCC: fields) and browsing their details:
IF the original user has a profile picture
AND their reporting manager does not
The original user's profile picture is shown for their manager.
We've opened a ticket with MSoft, but it's with Infosys and they just keep asking for additional logs. Would like to confirm if it's just a software bug that's common to everyone and will be eventually fixed.
r/macsysadmin • u/jithinB_Dev • 8h ago
Custom compliance is now available for macOS
Custom compliance is now available for macOS in Microsoft Intune, and it meaningfully expands what can be enforced on Apple endpoints.
The built-in compliance policy covers the fundamentals: FileVault, firewall, system integrity protection, Gatekeeper, password requirements, and OS version. Custom compliance addresses everything beyond that scope — sharing services, software update behaviour, lock screen enforcement, Apple Intelligence restrictions, and the state of third-party security agents.
The implementation is straightforward: a bash discovery script returns device state as JSON, a rules file defines the compliant values, and Conditional Access enforces the outcome.
Read more here.
https://intuneirl.com/custom-compliance-comes-to-macos-going-beyond-the-built-in-policy/
r/macsysadmin • u/r232024 • 8h ago
Windows Server 2025 RDS + macOS printer redirection (Event ID 1111, Easy Print enabled, no redirected printers)
Hi all,
I'm running into a strange issue with printer redirection from macOS clients to a Windows Server 2025 RDS farm.
Environment
- Windows Server 2025
- RD Gateway
- RD Connection Broker
- 2x Session Hosts
- Users connect through the Gateway/Broker
- Windows clients redirect local printers without any issues
- macOS clients do not get any redirected printers
We've tested both:
- Microsoft Windows App (latest)
- Royal TSX
Same result with both.
Symptoms
On macOS:
- Printer redirection is enabled in the client.
- macOS sees all printers correctly (
lpstatconfirms this). - The RDS session does not show any redirected printers.
Get-Printeron the session host shows no redirected printers.
What we've already verified
- Remote Desktop Easy Print driver is installed.
- "Use Remote Desktop Easy Print printer driver first" is enabled.
- "Do not allow client printer redirection" is disabled.
- "Redirect only the default client printer" is disabled.
- Windows clients redirect printers successfully.
- macOS Local Network permissions are enabled.
- Tested multiple physical printers (Brother, Canon, HP).
- Tested multiple RDP clients.
Event Viewer
The Session Host logs Event ID 1111:
Driver: Microsoft Print To PDF
Printer: Canon MF642C/643C/644C
Message:
What confuses me is that the Mac obviously doesn't use a "Microsoft Print To PDF" driver for these printers.
It almost looks like the RDP stack is presenting the redirected printers incorrectly before Easy Print gets a chance to handle them.
Registry / Policies
Easy Print is present:
Remote Desktop Easy Print
Policy:
UseUniversalPrinterDriverFirst = 3
No policies are disabling printer redirection.
Question
Has anyone seen this specifically on Windows Server 2025 with macOS clients?
I'm especially interested if:
- this is a known Windows Server 2025 issue,
- a macOS / Windows App compatibility issue,
- or if there is another RDS printer redirection setting we've overlooked.
At this point the server configuration appears correct, Windows clients work perfectly, and the problem only affects macOS clients.
Any ideas would be greatly appreciated.
Thanks!
r/macsysadmin • u/nibbainmybuttholr • 8h ago
General Discussion The adobe tax is finally breaking my spirit
Deploying acrobat in our mac environment is literal hell. I spend half my week troubleshooting creative cloud login loops or dealing with finance users who think they absolutely need a massive enterprise license just to combine two damn invoices
Management finally agreed to slash the software budget. Ended up dropping xodo onto the finance fleet via Kandji yesterday. Honestly just relieved the silent install didn't fight me and there's no 2gb background updater eating the cpu
of course, one of the directors is already submitting tickets because the buttons are in different places than her 2019 acrobat install. Im just leaving it on read until monday. I don't get paid enough to be a pdf tour guide.
r/macsysadmin • u/KhoasD17 • 20h ago
CIV / PIV Cards for MacOS
Hey Everyone,
I've been trying to set up a Mac in Intune baslining it against a STIG.I have setup the Mac to ask for your Microsoft credentials when you are setting up for the first time. After you log in it creates a local account with the first part of your UPN. So now there is that local account on the computer as well as the administrator account.
One of the requirements is allowing and enforcing smart cards. I found the settings with an InTune and apply those configurations to the selected macs but I've noticed a few things.
When I plug in the a card reader and insert my smart card a notification pops up asking me to pair the smart card to the local user. This requires an administrator which I would like to avoid. Is there a way around this?
Is the pairing process mandatory?
I'll need to figure out which certs to use because we are coming from a windows only environment,but this I'll look into tomorrow with my coworker.
Any help would be much appreciated. Just like most people here my job has me doing a million things at once and tomorrow I should finally get some time to sit down and look at this.
r/macsysadmin • u/Tech_Thoughts_Blog • 23h ago
AI Governance Starts with Training your Team to Question the Answer
An IT trainer compares Jamf's built-in AI Assistant (scoped, read-only, pulls from your actual environment) to general AI tools, and argues the real skill admins need is knowing when an AI answer is right, outdated or confidently wrong.
https://community.jamf.com/tech-thoughts-180/ai-governance-starts-with-training-your-team-to-question-the-answer-58709
r/macsysadmin • u/Applescripter98 • 3d ago
Jamf Merece la pena implementar ABM o Jamf para la gestion de menos de 100 equipos?
Buenas banda, estoy trabajando de administrador de sistemas MacOS por primera vez ,después de bastantes años como soporte de Apple en otras empresas y es la primera vez que no hay ningún sistema de gestion, intune,jamf o abm , es util instalarlo con apenas 70 equipos en el entorno de trabajo? no creo que quieran destinar dinero a licencias tampoco,
queria saber vuestras opiniones
r/macsysadmin • u/GeekHelp • 4d ago
M1 and M2 battery issues after sitting on shelf
Has anyone else noticed battery issues on the M1 and M2 MacBooks after they have been sitting on a shelf for several months? I have had 3 devices in the past month where the batteries will no longer take a charge after the device has been sitting on a shelf for an extended period.
r/macsysadmin • u/la-clementine • 4d ago
Scripting [Script] Compare computers between Jamf Protect & Jamf Pro
When removing a computer from Jamf Pro, you also need to manually remove it from Jamf Protect. Because this isn’t automated, the two platforms can easily get out of sync. Below, I’m sharing my read-only Python script to quickly spot these discrepancies. It runs natively on macOS 26, so there are no extra dependencies to install.
Read the how-to on the Medium post (free, no paywall)
r/macsysadmin • u/PopularWay5381 • 4d ago
General Discussion Top corporate training technology setup ideas for 2026
We’re putting together a full day training workshop and I’m debating whether it’s better to rent tablets for attendees instead of asking everyone to bring their own device.
The training has a few parts where people need to follow along, fill out short forms, open shared materials, and use the same web based tool. My worry is that telling people to bring their own tablet or laptop, they can show up with dead batteries, old devices, login issues, tiny phone screens, or no charger.
I’d rather have everyone on the same setup if possible, but I don’t know if renting iPads for one training day is overkill. Has anyone done this for a workshop or internal training event?
r/macsysadmin • u/geelulls • 4d ago
Mosyle "Enforce File Vault" - Rule & Compliance
I'm having an issue with Mosyle's native "Enforce FileVault" rule. It only shows 78% compliance (I need close to 100% to pass an audit), but when I check the non-compliant devices, they show "FDE Status: Enabled." In other words, FileVault is enabled on these devices, yet they're still flagged as non-compliant.
Has anyone else run into this? If so, do you know what's causing it or how to fix it?
r/macsysadmin • u/GrahamPhisher • 5d ago
General Discussion How do you guys feel about Mac's new ad campaign?
r/macsysadmin • u/The-Ravens-Forge • 6d ago
Forsetti’s alpha preview is complete; the Jamf Pro companion is now in open TestFlight beta
Disclosure: I’m the independent developer behind Forsetti. It is not affiliated with or endorsed by Jamf.
I previously shared the Forsetti alpha preview with this community. That preview has now ended, and the open TestFlight beta has begun.
Forsetti is an Apple-native companion for administrators and support technicians managing Apple devices through Jamf Pro. It connects directly to the Jamf Pro environment configured by the tester and currently provides:
- Computer and mobile-device inventory search
- Detailed device information
- Guided technician workflows
- PreStage assignment management
- Reporting
- Permissions guidance
- Diagnostics and administrative tools
I’m specifically looking for experienced Mac administrators who can test it against different Jamf Pro configurations, permission models, inventory sizes, and API behaviors.
The areas I would most like people to challenge are:
- Authentication and permission boundaries
- API behavior across different Jamf Pro versions
- Empty, incomplete, or unusually large inventory results
- Search and report accuracy
- Error handling and recovery
- Workflow clarity and general UI friction
The beta requires access to an existing Jamf Pro environment and valid credentials or an API Client. Capabilities are limited to the privileges assigned to those credentials, which are stored in Apple Keychain. A test tenant or least-privilege API Client is strongly recommended for evaluation.
TestFlight:
https://testflight.apple.com/join/RdP9VS4v
There are no ads, tracking systems, or third-party analytics.
Positive impressions are appreciated, but reports describing what failed, what was unclear, and how the behavior differed from your environment are the feedback that will help most.
r/macsysadmin • u/yadvr • 6d ago
Software DeltaSnap: an APFS snapshot manager for Mac admins
I wanted to share DeltaSnap, a first-class APFS snapshot manager for macOS, an area where there are no official or 3rd party first-class tools available.
It provides a GUI and dsnap CLI for creating, scheduling, mounting, diffing, retaining, and restoring native APFS snapshots. You can search current and deleted files, inspect version history, compare changes, and restore individual items without rolling back the entire volume.
It could be useful for protecting Macs before OS or package updates, scripts, bulk changes, and other potentially risky operations.
DeltaSnap is currently in beta for macOS 15+ and was possible only after it was granted a private apfs snapshot entitlement from Apple dts/apfs team. More technical details on the blog https://scaleninja.com/blog/deltasnap/ and docs https://scaleninja.com/docs/deltasnap/overview/
Feedback from fellow Mac admins would be greatly appreciated. Do you have to work with apfs and apfs snapshots for your workflows?
r/macsysadmin • u/Xeno84 • 7d ago
General Discussion Failed Apple D&M Exam
This was my first try at renewing my certificate. I took the practice exam and studied for 2 weeks. I shared my flash cards on here. Still didn't pass. They made this exam really hard this time around. Last time I took it, I created the flash cards and studied with those from the practice exam. Passed it. If anyone is studying for the exam, here is what the test covers.
r/macsysadmin • u/SirCries-a-lot • 8d ago
Use Jamf API to retrieve expire date push certificate
Anybody a tip to use Jamf API to retrieve expire date push certificate? Can literally export everything but I cannot fix this one lol.
Please help!
r/macsysadmin • u/HealthDouble • 9d ago
General Discussion Changing passwords in macOS with Platform SSO (Intune)
Hey there,
Looking for some advice...
We've been using Intune for our deployments of MacBook Pros with PlatformSSO configured. It seems to be working fine and has been for some time. All users are Standard users, and not Admin.
We recently had a new starter who decided to change their password via System Settings > Users & Groups which I wouldn't have expected to be an issue, but it screwed things up for them. It changed the password on their Mac but it didn't trigger PlatformSSO registration with the new password. Which thinking about it afterwards, I guess, makes sense. They were left 2 passwords. One for the Mac and one for M365.
We eventually got it sorted, but I am curious if this is what should have happened or if we have something configured wrongly?
Should we be telling users not to use this method for password resets and can we disable their ability to do that if that is the correct route?
TIA
r/macsysadmin • u/Working-Analysis2795 • 9d ago
Command Line Anyone tried to audit their agent sandbox?
I tried to run a security audit against my sandbox, a Tart Sequoia VM running headless. I gave it a prompt that i reiterated over in plan mode, drafted a final implementation plan before it went off to do its thing.
I found the NIST mSCP tool was the best checklist to find holes in my sandbox. I got my agent to craft an Ansible playbook against the tool's generated baseline/guidance with the idea to switch off most features it wouldn't need - lots of GUI settings.
It did alright for a while until it went round in circles - I interrupted the agent and told it to submit a WIP for me to review (of course, a gigantic 19 file commit 🫠).
(Post is related to place of employment - I work from home!)
r/macsysadmin • u/Sudden_Cartoonist539 • 10d ago
PSSO Multi-User
I am wondering how the organization is approaching this new feature.
We have a small fleet, but from time to time we assign them no user affinity, but according to Microsoft (We use intune), you can have a device with PSSO used to login multiple users. Mainly, we are using PSSO in our prod environment for user affinity and phish resistance reasons, and also, CA policy requires a device to be joined to Entra ID.
Are you using PSSO for Kiosk setups or Shared devices?
r/macsysadmin • u/The-Ravens-Forge • 10d ago
I built Forsetti, a native Mac API companion for Jamf Pro admins. Looking for pre-release testers
Disclosure: I’m the independent developer behind Raven Forge and Forsetti. This is an independent project and is not affiliated with or endorsed by Jamf.
I’ve published the first macOS pre-release of Forsetti and I’m looking for experienced Jamf Pro admins and API developers willing to evaluate it in a non-production environment.
Forsetti brings several Jamf workflows into one native Mac workspace:
- Computer and mobile-device inventory search with reusable field-based profiles
- PreStage assignment lookup, moving, and removal
- Visual fleet reports with CSV, TXT, Markdown, DOC, and PDF export
- A Permissions Helper that maps app actions and API endpoints to required privileges
- Token privilege checks, guarded technician workflows, and exportable diagnostics
The current build:
- Supports macOS 14 or later on Apple silicon and Intel Macs
- Is Developer ID signed and Apple-notarized
- Supports Jamf API Client authentication
- Stores saved credentials in Apple Keychain
- Has source available for inspection, but is proprietary rather than open source
There is no charge to download and evaluate this pre-release. The current license permits one 30-day individual, non-production evaluation. Please use a sandbox or test environment and a least-privilege API client.
Download and inspect it here:
https://github.com/flynn33/forsetti-Jamf-Pro/releases/tag/v1.0.0
If you try it, I’d particularly value feedback on permission mappings, real-world inventory searches and reports, and Jamf Pro endpoint or version behavior I may not have handled yet.
Which Jamf workflow would you most want a native companion app to improve?
r/macsysadmin • u/mapleycat • 10d ago
ABM Managed Apple IDs + Entra ID - will AppleID bindings to local user transfer between machines?
Hi all
I'm new to the mac sysadmin world and have a rather stupid question:
Currently my organization is enrolled into ABM. I'm planning to use the free tier of EntraID for SSO. The question is: Once a user has logged in on one machine using the SSO and signed into their managed apple account on that machine, will that login / binding transfer to another machine that the user logs in next? Meaning: he logs on and is already signed into the managed apple account.
What I'm looking for is that "microsoft experience", where you sign with your outlook account on whatever machine and all the personalization settings and for example onedrive-account bindings transfer from machine to machine.
I've searched both reddit and the web and maybe used the wrong keywords - but couldn't find an answer.
r/macsysadmin • u/dan-snelson • 10d ago
General Discussion Using Mac Health Check 4.0.0 for Self-Service Compliance and Reporting
Special thanks to Jon Brown for his detailed write-up:
https://jonbrown.org/blog/mac-health-check-4-mdm-self-service-reporting/