Deploy with Iru
1
Prepare
Have administrator access, an enrolled Mac running , and the vendor management agent where required. Download the Stable () Guardian Disabled PKG and complete the required configuration before upload.Expected result
The completed
Finish the rollout plan before creating the Library Items.
The completed
Silmaril-Managed.mobileconfig has passed validation, and the package is the Stable PKG.If this differsFinish the rollout plan before creating the Library Items.
2
Upload the System Channel profile
Create an Iru Custom Profile Library Item, upload the completed
One Custom Profile Library Item holds this profile identity, on System Channel, behind the
Update the existing Library Item when
Silmaril-Managed.mobileconfig, and use System Channel.Keep the Mac on its existing base Blueprint. On that Blueprint’s Assignment Map, add a conditional node for a dedicated tag such as silmaril. Place this profile behind that condition, and leave baseline Library Items outside it.Do not move the Mac to a separate Silmaril Blueprint. Changing Blueprints can remove baseline profiles. The condition matches a Mac that contains one of the listed tags, so other tags on the Mac can remain.If the same profile identity already exists, update that Library Item instead of creating a duplicate.Expected resultOne Custom Profile Library Item holds this profile identity, on System Channel, behind the
silmaril condition on the existing base Blueprint. Baseline items stay outside that condition.If this differsUpdate the existing Library Item when
dev.silmaril.mdm.managed is already present. A second profile with the same identity is outside this workflow. Moving the Mac to another Blueprint is also outside this workflow.3
Wait for profile completion
Use the Library Item Status tab and target device Activity to confirm the InstallProfile operation completed before assigning the app. The shared conditional node does not order the profile and the app.For the initial pilot, leave the Mac Custom App unassigned until Activity shows that operation completed. Profile delivery can take time.Before you apply the
That profile’s InstallProfile operation has completed on the initial pilot Mac.If this differs
For the initial pilot, leave the Mac Custom App unassigned until Activity shows that operation completed. Assigning the app earlier skips the required order.
silmaril tag to any later Mac, use the later-cohort hold.Expected resultThat profile’s InstallProfile operation has completed on the initial pilot Mac.If this differs
For the initial pilot, leave the Mac Custom App unassigned until Activity shows that operation completed. Assigning the app earlier skips the required order.
4
Create the Mac Custom App
Create a Mac Custom App with Package Type Installer Package, upload the () PKG, choose Audit and enforce, leave restart disabled, and use the Guardian Disabled audit and console-user post-install scripts below. Exit 0 means a matching Guardian Disabled build at or above minimum build is installed. A nonzero audit result triggers enforcement. The minimum-build check accepts or newer and prevents downgrade. Assign it to the same Assignment Map condition as the profile, and only after that profile install is confirmed on those Macs.Expected result
Audit exits 0 for bundle ID
A nonzero audit means that match is not installed, so Iru enforcement runs. Restart stays disabled. An audit that passes and a package that installs still leave protection unconfirmed until verification.
Audit exits 0 for bundle ID
dev.silmaril.SilmarilMacOS, Guardian Disabled, and build or newer. The post-install script opens Silmaril for a signed-in console user above UID 500. With no signed-in user, it exits 0 and the profile opens Silmaril at the next login.If this differsA nonzero audit means that match is not installed, so Iru enforcement runs. Restart stays disabled. An audit that passes and a package that installs still leave protection unconfirmed until verification.
5
Hold each later cohort
After the Custom App is on the
Each new Mac stays excluded from the Silmaril Custom App while its profile installs, and baseline items stay in place. After InstallProfile completes, removing that Mac from the exclusion permits the app.If this differs
Do not apply the
silmaril condition, a newly tagged Mac receives the profile and the app together. For every later cohort, hold the app before you apply the tag.Edit the Assignment Map and select the Silmaril Mac Custom App. Expand Manual device exclusions, choose Add device, select each new Mac, and Save. Leave the profile and the baseline items assigned. Saving the map reevaluates the rules. On the map or in device lookup, confirm the app is excluded. Device lookup highlights the Library Items assigned to that Mac.Then add the silmaril tag to that cohort. Confirm InstallProfile has completed on each of those Macs. Only then remove just those Macs from the Custom App exclusions with the X control and Save. That permits the app. Do not use Clear all, and do not change exclusions for other devices.Keep the same tag condition on the existing base Blueprint. Do not create another Blueprint or a second tag. An exclusion holds app deployment. It is not an uninstall.Expected resultEach new Mac stays excluded from the Silmaril Custom App while its profile installs, and baseline items stay in place. After InstallProfile completes, removing that Mac from the exclusion permits the app.If this differs
Do not apply the
silmaril tag until the exclusion is saved and lookup shows the app excluded. Do not remove an exclusion while InstallProfile is still incomplete for that Mac.6
Verify
Open Silmaril on a pilot Mac and complete endpoint verification. The profile supplies the connection values. Package success or a Managed label alone does not confirm protection.Expected result
Endpoint verification shows the app identity, a Managed connection, and fresh Protection activity from a new agent session.If this differs
Keep the rollout on the pilot. Use troubleshooting. Restart required means fully quit and reopen the affected agent, then start a new session.
Endpoint verification shows the app identity, a Managed connection, and fresh Protection activity from a new agent session.If this differs
Keep the rollout on the pilot. Use troubleshooting. Restart required means fully quit and reopen the affected agent, then start a new session.
7
Update or replace policy
For an update, deploy only the intended Guardian Disabled version and update supported app/package metadata at the same time. Replace the existing profile while preserving all supplied profile and payload identifiers, UUIDs, and permissions. Never invent identifiers to bypass a conflict. Removing managed keys restores saved local preferences. Removing the profile does not uninstall Silmaril.Expected result
The same profile identity remains, the app metadata matches the intended Guardian Disabled build, and a pilot Mac passes verification.If this differs
Restore the supplied profile identity and confirm the installed build before expanding the rollout. Add later Macs through the later-cohort hold before applying the
The same profile identity remains, the app metadata matches the intended Guardian Disabled build, and a pilot Mac passes verification.If this differs
Restore the supplied profile identity and confirm the installed build before expanding the rollout. Add later Macs through the later-cohort hold before applying the
silmaril tag. Removing the profile leaves the app installed.8
Uninstall
Pause every Silmaril Mac Custom App assignment for the target Macs so Iru cannot reinstall Silmaril. Leave the base Blueprint and its baseline Library Items in place.Removing the
An exit 2 receipt that shows the app and Guardian gone, with only permissions left, is finished by unassigning the removal item and completing the permission follow-up. Rerunning after the helper is gone cannot turn that result into exit 0.
silmaril tag does not uninstall Silmaril.Run the shared Uninstall through MDM script as root with the affected user signed in, and retain the JSON receipt and exit code. Exit 2 reports remaining items to review. It does not identify Guardian residue.Follow the shared result-handling instructions and remove only the Silmaril profile when policy should no longer apply. Leave baseline assignments and controls in place. Do not delete the Blueprint.Paste the script into the Audit Script field of an Iru Custom Script Library Item, leave Restart disabled, and do not add a remediation script. Inspect its script output and exit code. Install once per device retries nonzero results. If the exit 2 receipt confirms app removal and Guardian absence with only permissions remaining, unassign the removal item and complete the reported permission follow-up instead of rerunning the missing helper.If this differsAn exit 2 receipt that shows the app and Guardian gone, with only permissions left, is finished by unassigning the removal item and completing the permission follow-up. Rerunning after the helper is gone cannot turn that result into exit 0.
Guardian Disabled audit script
Exit 0 means bundle IDdev.silmaril.SilmarilMacOS, Guardian Disabled (SilmarilPrivilegedProtectionEnabled false), and CFBundleVersion greater than or equal to MIN_BUILD. MIN_BUILD is the numeric Stable build . Any other result exits 1.