For years now I have been relying on some custom scripts to conduct Apple OS & 3rd party software updates on our Mac fleet. As Apple continues to clamp down on security (especially that new T2 chip) I am finding that these scripts are no longer working very well, support is no longer there, and I am looking for what the future has to offer.
I don't have a lot of time and resources to dedicate to trying out a bunch of new patching solutions, so I want to find the best method moving forward. After spending some time reading through the interwebs and on JAMF nation it seems like there are pretty much two options: JAMF Patch Management & Munki. Let me know if there is something else I am missing.
JAMF Patch Management - This option looks the most future proof, but I am hesitant to move forward due to the difficulty of adding 3rd party software packages and also not seeing much forward momentum since it came out in 10.2. If I want to add 3rd party software I have to spin up my own software server it sounds like or use one of the open source communities to do so. I also hear that there are not many custom options when it comes to how the end user interacts with the notifications.
Munki - This looks very well developed and has a strong community attached. Some large companies I have heard use it, but it looks like a lot of overhead work to set it up properly. And I am worried what the future holds for Munki 2-3 years down the line.
My wish list for a patching workflow. These are not deal breakers, but would be great to have:
- User friendly. Bonus if uses can defer before choosing to upgrade/patch.
- Ability to customize branding.
- Ability to set time of notification.
- Ability to pre-cache packages.
- Future proof. Will it be around in a year or two?
I work in an enterprise environment that uses DEP. We have about 500 Macs. So I am reaching out to you all to get your thoughts. What do you currently use? If you had to do it again would you do something differently? If you had to guess, which method is going to be future proof for the next 2,3,5 years?
