Just an FYI... If your organization uses SSL Inspection on network traffic, and you haven't whitelisted the entire apple.com domain, you will want to add tbsc.apple.com to your whitelist. SSL Inspection on that server will result in failed installs or updates to macOS Mojave (I didn't test Catalina) when those also required a BridgeOS update be download and installed.
Apple's Use Apple products on enterprise networks doesn't yet list this server, but an update has been requested. It's now included in Apple's Use Apple products on enterprise networks document.
