In our environment we've blocked the execution of the 10.11.x installers for El Capitan until we update relevant core software on the machines to support it.
Machines that check in and eventually update software to meet these requirements fall into a smart group more or less called "Cleared for 10.11 El Capitan".
We have the restricted software policy set to "All Machines, Exclude 'Cleared for 10.11 El Capitan' ". The restriction functions as expected, but when the machines do eventually meet the requirements and are moved into the "cleared" smart group, the software is still restricted on the machine. If I check on the machine in Casper, it does not show that it has any restricted software in scope (as expected), but when attempting to run the software in question it is still blocked. The machines check in several times per day and update inventory daily, they also always have connectivity to the jamf server - yet the restriction is never lifted.
I have run jamf policy and jamf recon and no change takes place. Intermittently, after several hours or days the restriction is lifted on some machines, but not all. What triggers the updated restricted software list on client machines? The only way I have found to reliably lift the restriction is to 'jamf manage' the machine, but I feel this is unnecessary and should not be required. Why is this software list not updated locally with a 'jamf policy'?
