Hacker News new | ask | show | jobs
by astockwell 1824 days ago
FWIW, with JAMF, your employer can ship it straight from Apple to your door, and still get their MDM all over it the second it connects to the internet the 1st time.
4 comments

I understand this sort of thing pisses people off but Windows Autopilot and automatic enrolment into Intune has been an incredible help this last year.

Where I work we managed to ship thousands of laptops to students homes from the manufacturers during lockdown and but still ensured that they had the correct E-Safety software and configurations on them when they turned them on for the first time.

Apple DEP (== Autopilot) on Mac can still by bypassed by simply not connecting to the internet when going through the setup wizard.

On iOS however, it can't. iOS won't let itself activate without internet.

Any product leveraging the built in MDM hooks can do this, no need to single out JAMF.
Indeed, MSFT launched similar. JAMF was just the most well known in the Mac ecosystem.
> FWIW, with JAMF, your employer can ship it straight from Apple to your door, and still get their MDM all over it the second it connects to the internet the 1st time.

How would that work?

You buy the hardware through an Apple business portal and Apple will register the machine to your MDM server. The first thing the laptop does when being set up is to check if it should download MDM configuration.

We do this for all Macs and iPhones for our employees, we buy them directly through our Apple business portal and it all automatically registers to our JAMF account.

Any technical resource/paper with the details on this?

This seems ripe for exploiting for nefarious purposes. With Apple having built it, all it takes is one court order targeting a serial# and it auto-installs full remote control spyware on that mac?

Yep, it's based on device certs.