Posted on 10-18-2022 01:57 PM
Hello All,
Im currently tweaking our company restrictions on macOS devices and was curious how others were going about this. I find the restrictions on the macOS side more difficult to sort out because of how its set up as opposed to the IOS side that just lets you turn on one item for a restriction. Specifically iCloud restrictions which in some cases I only want to restrict certain items for a some and completely restrict it for others. Same for software deferrals, since all these live in the functionality tab it makes more difficult to separate. Unless i'm going about this the wrong way Id love to see if anyone has some suggestions or a workflow that has been working good for them. Thanks in advance and please excuse this if it seems like a low level inquiry.
Posted on 10-18-2022 05:47 PM
@JalteredM Until Jamf finally gets around to updating the GUI for creating a Restrictions payload you'd be better off looking at a tool like the iMazing Profile Editor which will generate profiles that only add the settings necessary for when you've modified a default. If you sign the profiles created by this tool before uploading to Jamf Pro it will ensure that the settings don't get modified to include ones you don't want configured.
Posted on 10-19-2022 07:51 AM
I make several Restrictions Configuration Profiles based on our needs. I set up smart groups to funnel devices in to the correct Restrictions. Generally I have Three, Low, Medium, and High (default). By and large all devices will fall in to High unless something tells JAMF to do otherwise. There are a few one offs for custom restrictions when needed by a specific business unit.
I do everything for restrictions in the JAMF Pro GUI.
The Restrictions Configuration Profiles I use.
Beyond what I mentioned there are general restriction differences, but they are not really noteworthy.
How I scope everything.
Once all this is setup its really no maintenance. Let smart groups do all the scoping and everything happens automatically.
Every one of these exemptions would funnel you in to the scope of a different restriction.
Posted on 10-20-2022 01:24 PM
Thanks for the info! This is great information. I also have a few levels set up for restrictions that are linked to smart groups but i just haven't been happy with the workflow so some of these suggestions will be really helpful. I also set up some extension attributes if i want to move a user to another level. The software update differal was the one thing that has been a pain because I have a lot of power users and If i need to run an update for a specific user while im on their machine troubleshooting I then have to move their restriction level to do so. It would be great if the software update differal was separate and I have been to lazy to build a script for just that (lol). Im going to check out iMazing as well as I re assess our restrictions.
Thanks!