Blocking MacOS Sonoma installer

ajamfadmin1810
Contributor

Hello all

 

I am blocking Macos Sonoma beta with two different restricted software setups, one is Install macOS Sonoma beta.app and the other is "Install macOS 14 beta.app" Im using both just to be safe and make sure I catch the installer .

 

With the production relase of MacOS Sonoma around the corner I was wondering if anyone has setup their environment to block macos sonoma already. Im looking for the process name

 

Thank you again

16 REPLIES 16

MichaelMcG
New Contributor III

I'm sure it will follow the same naming convention but there is no way to tell until its released.

I've got mine set to block "Install macOS Sonoma.app"

AJPinto
Honored Contributor

You can search discussions for blocking Ventura, its the same. 

  • Macs running macOS 11.3.1 or newer will not download install macOS Sonoma.app. So, blocking that installer really does not do anything other stopping people who download the app manually, still a good idea to block but wont help much.
  • MacOS 11.3.1 and newer will download Major Software updates as a delta, the ONLY way to block this is with a OS update deferral configuration profile. You cannot defer longer then 90 days.

Deferring Availability of macOS Software Upgrades and Updates with a Configuration Profile - Technic...

MichaelMcG
New Contributor III

Yea I have my deferral set for 90 days in Jamf already, this is just incase people try and download it in other ways

easyedc
Valued Contributor II

This also is the new way to block folks running the beta OS, as well. Under  your Software Update payload is a check-box to enable/disable installing macOS beta releases. Create one for those who are allowed to pre-test the Software, leave unchecked for all others.

Screenshot 2023-09-14 at 8.48.58 AM.png

Do i leave the others checked and just uncheck the beta one?

easyedc
Valued Contributor II
Do you? That's up to you and your team (or teams depending on who all needs to weigh in to provide an answer). I'm going to say yes, you do. Gone are the days of slow-rolling software updates to see if they break things or leaving things mostly in the hands of the End-User to perform. In today's day and age where Macs are as much a target as any other platform, yes, stay current. Do as much of it as you can via automation.

JamfAdmin2
New Contributor II

Hello All can i get confirmation if this restricted access i did to kill the mac os sonoma beta will work? 

JamfAdmin2_0-1695060232357.png

JamfAdmin2_1-1695060245197.png

 

AJPinto
Honored Contributor

As far as I am aware there is not an install macOS Sonoma Beta.app. Your restriction on install macOS Sonoma.app should work fine, however I strongly suggest testing this yourself. Keep in mind blocking install macOS Sonoma.app wont do anything on Macs running greater then 12.3.1 as they will never download the app to upgrade.

sorry can you elaborate on that. What do you mean by they will never download the app to upgrade?

I mentioned this in another comment on this thread. Apple changed how macOS Major upgrades are installed with macOS 12.3.1. The install macOS XYZ.app is no longer downloaded. Instead the update comes down as a delta, and there is no way to block it aside of a configuration profile. 

 

I did mistype and put 11.3.1, it was 12.3.1.

 

You can search discussions for blocking Ventura, its the same. 

  • Macs running macOS 11.3.1 or newer will not download install macOS Sonoma.app. So, blocking that installer really does not do anything other stopping people who download the app manually, still a good idea to block but wont help much.
  • MacOS 11.3.1 and newer will download Major Software updates as a delta, the ONLY way to block this is with a OS update deferral configuration profile. You cannot defer longer then 90 days.

Deferring Availability of macOS Software Upgrades and Updates with a Configuration Profile - Technic...



 

JamfAdmin2
New Contributor II

so if all macs are on ventura they will not be able to download the sonoma beta? 

No, @AJPinto is just saying it doesn't download a complete installer, just an update containing the necessary files to upgrade to macOS 14.

You don't really need a software restriction to block OS betas anyway, it's a simple checkbox available in a configuration profile:

Bretterson_0-1695316016717.png

 

hmmm okay thank you for the info let me ask you is it possible to block the sonoma 14 beta? in the restricted software sections or is it different this year where you are unable to at all?

I am only asking because i asked a lot of people and i am getting mixed answers people are telling me yes where others are telling me no and to create a config profile 

I'm honestly not sure, but my guess is yes since it is possible to download a full installer. This thread seems to support that: https://community.jamf.com/t5/jamf-pro/blocking-sonoma-developer-beta/m-p/292714

easyedc
Valued Contributor II

The old-school method to block software updates involved setting Restricted Software process blocks for the software that you wanted to deny. In Ventura's case, it was a combo of blocking the InstallAssistant, Ventura as a process, and I also blocked Install macOS Ventura.app. You can change both scoping and wording to affect different outcomes.  For Sonoma, your process names/app names would just be updated to reflect that. I would feel like the Configuration Profile restriction would be more effective though.  

Screenshot 2023-09-22 at 9.05.59 AM.png

Screenshot 2023-09-22 at 9.06.14 AM.png

Screenshot 2023-09-22 at 9.06.32 AM.png

   

JamfAdmin2
New Contributor II

even with restricting install assistant did not work for me, does it work on your end?