Posted on 07-26-2022 06:11 PM
Please tell me we're going to be able to suppress these and a million notifications aren't the future for end users:
Posted on 07-26-2022 06:38 PM
@PhillyPhoto Apple has gotten a _lot_ of feedback that these notifications are detrimental to organizational managed Macs, and they have acknowledged that they need to provide the ability to suppress those messages. Exactly when that's going to arrive in the beta cycle is anyone's guess.
07-26-2022 07:42 PM - edited 08-04-2022 01:47 AM
The notifications are very annoying but what really concerns me is how easy it is to effectively unmanage your machine by unchecking anything you don’t want. I hope I’m missing something, but at this point it seems like anyone can just kill all of our corporate security and management software.
Posted on 07-27-2022 06:41 AM
I've only been administrating Macs for a year, but there is a general feel I've been getting. Things like users should be in control of the devices they use. The user should be comfortable using their device. With things like not having a replacement for a Firmware Password on M1 devices really shows Apple has not been thinking about businesses managing Macs until people put them on blast.
Posted on 07-27-2022 03:54 PM
Hey Fluffy,
There are ways to set the recovery lock on the M1s right now, I am not using them though. I'm waiting for Jamf to drop their supported version but there are ways if you really need it.
https://community.jamf.com/t5/jamf-pro/anyone-using-the-m1-quot-set-recovery-lock-quot-command/m-p/2...
https://gingerscripting.com/setting-an-apple-silicon-recovery-lock-password-through-the-jamf-api/
I get the sentiment all the time from employee's they want to install their own apps and be their own admins. The problem with that is they either A) Can barely use the Mac or B) Know just enough to get in trouble.
Each upgrade now since Catalina they've been making it harder and harder to Administer over the macs. I completely understand the user of the mac's experience should come first and their privacy but we need to make it as easy and secure for them as possible to do their job. Apple's probably working on their own MDM solution, watch it have the power to do everything.
Posted on 07-27-2022 01:29 PM
An interesting thread.
Why are there organisations out there that have JAMF, yet give everyone admin accounts?
This isn’t ISO or CSE+ compliant.
Regarding the notifications, I haven’t checked Ventura yet, but surely these can be killed with a custom tourist config profile?
I kill a heap of these on shared devices with many applications.
Posted on 10-25-2022 12:20 PM
Because there are still an increasing number of items that even admins cannot change when managed via MDM and giving everyone a standard user account heavily increases administrative burden on IT.
Posted on 08-03-2022 06:34 AM
Following thread since when building test machines I get those popping up left and right.
Posted on 08-25-2022 06:10 AM
This is a mess for my automated enrollment workflow for sure. Hope the stable version provides a way to block this for managed distributions
Posted on 08-31-2022 11:52 AM
Apple recently posted a new PDF on AppleSeed called "2022 Login and Background Item Management Test Plan" that contains a sample config profile that you can use to suppress the notifications and prevent users from disabling the launchdaemons that your org configures in the System Settings app.
I have just begun to test this in my environment, so don't have a real-world example profile yet but I will post one when I've got everything working.
Posted on 08-31-2022 12:02 PM
Do you have a link?
Posted on 08-31-2022 12:42 PM
@PhillyPhoto If you don't have access to AppleSeed then a link wouldn't be useful, and if you do have access you'll know where to find the document @sshort referenced.
Posted on 08-31-2022 12:46 PM
I don't use it that much, but I do have access but can't find anything that has PDFs.
Posted on 08-31-2022 12:54 PM
@PhillyPhoto Go to the Downloads tab after logging in to AppleSeed and you'll find the document under Test Plans & Additional Resources
Posted on 08-31-2022 01:23 PM
Got it, thanks!
Posted on 09-14-2022 07:48 AM
When I log into AppleSeed, this is the page I see, I dont see a downloads tab??
Posted on 09-14-2022 08:59 AM
@mathewsl05 You have to log in to appleseed.apple.com using a Managed Apple ID (using a "regular" Apple ID re-directs you to a different site for Apple developers)
Posted on 09-14-2022 09:10 AM
Yep, I think I JUST figured that out! Thank you :)
Posted on 09-08-2022 06:44 AM
Have you managed to get this working yet @sshort ? I have been trying for a while, without success!
Posted on 10-11-2022 03:22 PM
Yes! I finally got it working earlier today. 3 tips:
* Make sure you're running beta 10 or 11 for the profile to consistently work.
* iMazing Profile Editor has a helpful new "Service Management - Managed Login Items" payload template that makes creating a custom profile much easier.
* I had a lot of issues with `BundleIdentifer` as the `RuleType`. I recommend using `LabelPrefix` like my example profile: https://github.com/ducksrfr/mac_admin/blob/master/profiles/approved-background-services.mobileconfig
09-22-2022 04:34 PM - edited 09-22-2022 04:37 PM
I am in there and can't find it. Where it be breh? – NM, didn't see the managed ID. I am good. Thanks for pointing out this whitepaper.
Posted on 08-31-2022 01:42 PM
A JSON would be really nice for this, wink wink Apple/Jamf
09-17-2022 03:37 PM - edited 09-20-2022 04:24 PM
The configuration profile won't work until you sign it and upload it signed to Jamf Pro.
Tested on macOS beta 13 (build 22A5342f). Kudos to Bilal from made.com, he gave me this tip via Mac Admins Slack.
You can sign the profile via this command:
/usr/bin/security cms -S -N "<YOUR TEAM ID>" -i "/path/to/file.mobileconfig" -o "/path/to/file-SIGNED.mobileconfig"
Posted on 09-23-2022 06:20 AM
can also use the Handcock app to sign things
Posted on 09-21-2022 04:12 AM
If this has to be signed first that's a real pain as it means every time you want to change it you're having to upload a new config to Jamf and then set the scope etc. and unscope the existing profile.
Posted on 09-21-2022 04:15 AM
Agreed on the signing piece, I have signed our profile now and uploaded to Jamf. Apparently the GUI feature will be coming in a future release of Jamf, so we just have ti stick with it for now.
Posted on 09-28-2022 11:41 AM
Do know if this will before the OS releases?
Posted on 09-28-2022 11:47 AM
@auser I wouldn't bet on it given that we're less than 30 days from the release of macOS Ventura (based on Apple's mention at the event earlier this month that it will be released in October)
Posted on 09-28-2022 11:48 AM
is there a easy way to just block all the items?
11-09-2022 01:45 PM - edited 11-09-2022 01:48 PM
@auser - yes you can. Just built this one and it works so far...installed some test software and no notifications.
BTW, this is a great page for understanding this mess...he should do Apple's docs!
Login Items Management @n8felton did the work. 👍
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>PayloadContent</key>
<array>
<dict>
<key>NotificationSettings</key>
<array>
<dict>
<key>BundleIdentifier</key>
<string>com.apple.BTMNotificationAgent</string>
<key>NotificationsEnabled</key>
<false/>
</dict>
</array>
<key>PayloadIdentifier</key>
<string>com.apple.notificationsettings.12c05d0d-6231-4621-9ac6-a781a626951b</string>
<key>PayloadType</key>
<string>com.apple.notificationsettings</string>
<key>PayloadUUID</key>
<string>12c05d0d-6231-4621-9ac6-a781a626951b</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</array>
<key>PayloadDescription</key>
<string>Disable Background Task Management Notifications</string>
<key>PayloadDisplayName</key>
<string>Disable Background Task Management Notifications</string>
<key>PayloadIdentifier</key>
<string>com.apple.notificationsettings.5ea4543d-f0fe-4f19-9e5f-7fab2051b712</string>
<key>PayloadScope</key>
<string>System</string>
<key>PayloadType</key>
<string>Configuration</string>
<key>PayloadUUID</key>
<string>5ea4543d-f0fe-4f19-9e5f-7fab2051b712</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</plist>
Posted on 09-21-2022 07:36 AM
For those who don't want to hand-craft - imazing Profile Editor can be helpful. Doesn't help with scoping :)
Posted on 09-21-2022 08:20 AM
Thanks, certainly made it easier using Imazing Profile Editor, just a pain you have to manually sign and then upload each time though, especially while you're testing.
Posted on 09-28-2022 04:29 AM
Has anyone got a real world example of a config profile they can share please?
Posted on 09-28-2022 05:03 AM
Here is a part of my array, but the whole thing is under NDA, because of it's beta status.
For details on the profile see Apple Developer Documentation (Apple SEED, mentioned earlier in this thread).
<array>
<dict>
<key>RuleType</key>
<string>TeamIdentifier</string>
<key>RuleValue</key>
<string>EQHXZ8M8AV</string>
<key>Comment</key>
<string>Google Inc.</string>
</dict>
<dict>
<key>RuleType</key>
<string>TeamIdentifier</string>
<key>RuleValue</key>
<string>S272Y5R93J</string>
<key>Comment</key>
<string>Citrix Systems, Inc.</string>
</dict>
<dict>
<key>RuleType</key>
<string>TeamIdentifier</string>
<key>RuleValue</key>
<string>9GQZ7KUFR6</string>
<key>Comment</key>
<string>Nudge</string>
</dict>
<dict>
<key>RuleType</key>
<string>TeamIdentifier</string>
<key>RuleValue</key>
<string>483DWKW443</string>
<key>Comment</key>
<string>Jamf Software</string>
</dict>
<dict>
<key>RuleType</key>
<string>TeamIdentifier</string>
<key>RuleValue</key>
<string>UBF8T346G9</string>
<key>Comment</key>
<string>Microsoft Corporation</string>
</dict>
</array>
Posted on 09-28-2022 05:03 AM
Posted on 09-28-2022 05:18 PM
Turns out it's actually pretty easy. I added it to our existing muted notifications as an application under Configuration Profiles > Application & Custom Settings > External Applications. Works like a charm! (XML at the bottom.) Yes, I know there is now a notifications section in JSS.
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>NotificationSettings</key>
<array>
<dict>
<key>BundleIdentifier</key>
<string>com.apple.btmnotificationagent</string>
<key>NotificationsEnabled</key>
<false/>
<key>AlertType</key>
<integer>0</integer>
<key>ShowInLockScreen</key>
<false/>
<key>ShowInNotificationCenter</key>
<false/>
<key>BadgesEnabled</key>
<false/>
<key>SoundsEnabled</key>
<false/>
</dict>
</array>
</dict>
</plist>
Posted on 09-29-2022 10:01 AM
Does this block all background apps notices from coming up?
Posted on 09-30-2022 06:30 AM
I did some testing yesterday, and it seems to be independent.
Posted on 10-07-2022 10:05 AM
There's a step missing here: which source did you choose for your external application? :)
Posted on 10-07-2022 10:17 AM
Sorry. It's the Custom Schema used for the other 18 in place already. Schema at the bottom.
External Applications > Source > Custom Schema:
{
"title": "macOS Notifications (com.apple.notificationsettings)",
"description": "This payload specifies the restriction enforced notification settings for apps, using their bundle identifiers. It is supported on iOS 9.3 and later. https://developer.apple.com/business/documentation/Configuration-Profile-Reference.pdf#page=57 https://developer.apple.com/documentation/devicemanagement/notifications/notificationsettingsitem",
"__feedback": "bill@talkingmoose.net",
"properties": {
"NotificationSettings": {
"title": "Applications",
"description": "Specifies the restriction enforced notification settings for apps, using their bundle identifiers. It is supported on iOS 9.3 and later.",
"property_order": 10,
"type": "array",
"items": {
"title": "Application",
"type": "object",
"properties": {
"BundleIdentifier": {
"title": "Bundle Identifier",
"description": "Required. Bundle identifier of app to which to apply these notification settings.",
"type": "string"
},
"NotificationsEnabled": {
"title": "Allow Notifications from App",
"description": "Optional. Whether notifications are allowed for this app. Default is true.",
"type": "boolean"
},
"AlertType": {
"title": "App Alert Style",
"description": "Optional. The type of alert for notifications for this app.",
"type": "integer",
"options": {
"enum_titles": [
"None",
"Banners",
"Alerts"
]
},
"enum": [
0,
1,
2
]
},
"ShowInLockScreen": {
"title": "Show In Lock Screen",
"description": "Optional. Whether notifications can be shown in the lock screen. Default is true.",
"type": "boolean"
},
"ShowInNotificationCenter": {
"title": "Show In Notification Center",
"description": "Optional. Whether notifications can be shown in notification center. Default is true.",
"type": "boolean"
},
"BadgesEnabled": {
"title": "Badges Enabled",
"description": "Optional. Whether badges are allowed for this app. Default is true.",
"type": "boolean"
},
"SoundsEnabled": {
"title": "Sounds Enabled",
"description": "Optional. Whether sounds are allowed for this app. Default is true.",
"type": "boolean"
}
},
"required": [
"BundleIdentifier",
"NotificationsEnabled",
"AlertType",
"ShowInLockScreen",
"ShowInNotificationCenter",
"BadgesEnabled",
"SoundsEnabled"
]
}
}
}
}