This year I had the privilege of presenting my first talk at JNUC after attending the previous three conferences. The talk grew out of extensive testing performed while troubleshooting problems in the environment where I was then working.
Its central contention was relatively simple:
Individually correct states do not necessarily produce a coherent system state.
DNS can be correct. Identity can be correct. VPN can be correct. CASB can be correct. EDR can be correct. Individual Network Extension providers can all report that they are functioning normally.
And yet the endpoint can still lack a reliably functioning path for MDM and its supporting transactions.
I sometimes think of this as several independent republics, each functioning according to its own laws but without sufficient diplomacy between them. Every subsystem may be behaving correctly from its own perspective while the system as a whole lacks coherence.
On macOS, this becomes particularly important because multiple security and networking products may participate in, inspect, redirect, permit, decline, or reject network flows using Apple's supported frameworks. Each product can therefore be "working as designed" while their combined behavior produces an emergent failure state.
The symptoms can be deceptively ordinary.
The Mac appears connected. Email works. The Internet works. Internal resources are available. The VPN reports healthy. Security agents are running.
But MDM commands fail, arrive intermittently, time out, or succeed only partially.
What I observed repeatedly was not intentional split tunneling, but something closer to control-path fragmentation: flows being evaluated by multiple providers, handed between mechanisms, rejected or declined at different stages, or traversing interfaces asymmetrically. The result can be increased latency, additional evaluation overhead, backpressure, and ultimately terminated or unreliable transactions.
None of this is an argument for less security.
It is an argument for coherent security architecture.
I documented these behaviors repeatedly on managed endpoints, escalated the findings internally, and subsequently saw the broader architectural concerns corroborated through independent MSP review.
Certainly, every enterprise remains responsible for configuring and tuning the products it deploys. But in a healthy architecture, responsibility for end-to-end interoperability cannot reasonably belong to a single Mac administrator.
It crosses multiple domains:
endpoint engineering, network engineering, security architecture, IAM, SOC operations, vendor engineering, and organizational governance.
In practice, however, the interoperability problem frequently lands on the Mac administrator because somebody still has to make the individual agents and providers coexist on the endpoint.
That can become an extraordinarily difficult engineering problem when organizational boundaries, security policies, SOC requirements, vendor assumptions, and Apple's framework constraints all intersect.
That leads to a proposal I would like to put to Jamf and the broader community:
What if Jamf convened an interoperability summit involving major Apple-focused security, VPN, CASB/SSE, identity, EDR, networking, and endpoint-management vendors?
The purpose would not be to disclose trade secrets, proprietary implementation details, confidential roadmaps, or other protected information.
The objective would be to develop practical, cross-vendor guidance for preserving reliable Apple management operations in increasingly complex enterprise security stacks.
Ideally, the outcome would be a set of agreed architectural principles and interoperability practices recognizing Apple management, identity, enrollment, certificate, bootstrap, and MDM-related transactions as first-class requirements of the enterprise architecture—not incidental traffic that happens to survive whatever combination of inspection products has been deployed.
No single vendor owns the entire transaction path anymore.
That is precisely why I think the ecosystem increasingly needs a shared understanding of how those paths are supposed to coexist.
