Posted on 08-21-2017 11:36 AM
Hot off the press:
Prepare for changes to kernel extensions in macOS High Sierra
https://support.apple.com/en-us/HT208019
Posted on 08-21-2017 11:48 AM
Seems like disabling SKEL with MDM enrollment is a good solution to the problem of getting untrusted kexts in place and at scale.
Posted on 08-21-2017 12:11 PM
In macOS High Sierra, enrolling in Mobile Device Management (MDM) automatically disables SKEL. The behavior for loading kernel extensions will be the same as macOS Sierra.
I read this as, simply enrolling into JAMF will disable SKEL. No?
Posted on 08-21-2017 02:01 PM
@dpertschi si.
Posted on 08-21-2017 03:04 PM
uh... in beta 6 SKEL wasn't disabled... testing beta 7
C
Posted on 08-21-2017 03:09 PM
We don't perform MDM enrollment for our clients. MDM wasn't a thing when we started using JAMF and it never became part of our architecture since it didn't bring anything new to the table for us. Our JSS doesn't even have access to the Internet for security reasons.
Has anyone rolled out MDM enrollment late in the game? I'm very nervous that this will cause problems for us, but I have to handle SKEL somehow and the other options are untenable, requiring manual touch.
Posted on 08-21-2017 04:13 PM
@alexjdale Once you get all of your ports open, shouldn't be a big deal to get it enabled. Pay attention to the MDM remediation part of @rtrouton's script here:
You don't need to worry about removing old MDM profiles, but the remediating new MDM profiles may be helpful.
Posted on 08-31-2017 11:33 AM
I'm thinking that although it disables it for users when enrolled in JSS, i think it also means that we wil also be able to control which ones are approved via the JSS, so we gain some institutional control
Posted on 08-31-2017 01:08 PM
@kstrick Needs a future version of macOS, with an updated MDM spec, to do that. Not to mention Jamf supporting the updated MDM spec, which they usually do right away...
Posted on 08-31-2017 02:28 PM
@RobertHammen yeah, i'm thinking long term.... we don't know if it would show up in 10.13.2 or 10.14.2, but at least the intention is there...
Posted on 09-22-2017 02:16 AM
FYI...anyone confirm this?