Deploy with Jamf Pro
1
Prepare
Have administrator access, an enrolled Mac running , and the vendor management agent where required. Download the Stable () Guardian Disabled PKG and complete the required configuration before upload.Expected result
The completed
Finish the rollout plan before creating the Jamf profile or package policy.
The completed
Silmaril-Managed.mobileconfig has passed validation, and the package is the Stable PKG.If this differsFinish the rollout plan before creating the Jamf profile or package policy.
2
Upload the device profile
In Computers > Configuration Profiles, upload the completed
The stored payload matches the completed file, including every supplied identifier, UUID, and permission payload.If this differs
Export the stored profile and compare it with the file you uploaded. Restore the supplied identity before enabling the package policy. Inventing new UUIDs is outside this workflow.
Silmaril-Managed.mobileconfig as a Computer Level profile set to Install Automatically. Scope it to a dedicated Silmaril rollout group, either smart or static. Leave unrelated profiles on their existing scopes. Signed profiles are read-only in Jamf. An unsigned import may change content, so export and compare the stored payload. When dev.silmaril.mdm.managed already exists, use Jamf’s supported replacement workflow and never randomize UUIDs. If the console cannot replace a signed profile, pause only the Silmaril app install policy, plan removal and reimport with the same supplied identity, verify restored policy on pilot Macs, then resume that app installation.Expected resultThe stored payload matches the completed file, including every supplied identifier, UUID, and permission payload.If this differs
Export the stored profile and compare it with the file you uploaded. Restore the supplied identity before enabling the package policy. Inventing new UUIDs is outside this workflow.
3
Confirm profile installation
Use the target computer record’s Management and History views to confirm the profile install command completed and the profile is installed before enabling the package policy. For a later cohort, keep that package policy disabled until the new Macs show the profile installed. Adding computers to a group whose package policy is already enabled does not recreate this order.Expected result
The profile install command completed and the profile is installed on the pilot Mac.If this differs
Leave the package policy disabled until that record shows the profile installed. A scoped profile that has not finished installing is not a reason to deploy the PKG.
The profile install command completed and the profile is installed on the pilot Mac.If this differs
Leave the package policy disabled until that record shows the profile installed. A scoped profile that has not finished installing is not a reason to deploy the PKG.
4
Upload and deploy the PKG
Upload the () PKG in Settings > Computer management > Packages. Create a build-specific policy with Recurring check-in, Once per computer, package action Install, no restart, and the same Silmaril rollout group as the profile. Run the verify-and-launch script after the package. It checks bundle ID
The policy installs that Guardian Disabled PKG once, does not restart the Mac, and the script exits 0. Exit 0 with a console user above UID 500 also opens Silmaril. Exit 0 with no signed-in user leaves launch to the next login.If this differs
The script’s failure message names the mismatch. It can report a missing app, an unreadable bundle ID or build, an unexpected bundle ID, a build older than , or a Guardian variant that does not match this policy. Correct that result before treating the policy as successful. Package success alone does not mean protection is active.
dev.silmaril.SilmarilMacOS, build , and Guardian Disabled, then opens Silmaril for the console user or relies on login launch when nobody is signed in.Expected resultThe policy installs that Guardian Disabled PKG once, does not restart the Mac, and the script exits 0. Exit 0 with a console user above UID 500 also opens Silmaril. Exit 0 with no signed-in user leaves launch to the next login.If this differs
The script’s failure message names the mismatch. It can report a missing app, an unreadable bundle ID or build, an unexpected bundle ID, a build older than , or a Guardian variant that does not match this policy. Correct that result before treating the policy as successful. Package success alone does not mean protection is active.
5
Verify
Open Silmaril on a pilot Mac and complete endpoint verification. The profile supplies the connection values. Package success or a Managed label alone does not confirm protection.Expected result
Endpoint verification shows the app identity, a Managed connection, and fresh Protection activity from a new agent session.If this differs
Keep the rollout on the pilot. Use troubleshooting. Restart required means fully quit and reopen the affected agent, then start a new session.
Endpoint verification shows the app identity, a Managed connection, and fresh Protection activity from a new agent session.If this differs
Keep the rollout on the pilot. Use troubleshooting. Restart required means fully quit and reopen the affected agent, then start a new session.
6
Update or replace policy
For an update, deploy only the intended Guardian Disabled version and update supported app/package metadata at the same time. Replace the existing profile while preserving all supplied profile and payload identifiers, UUIDs, and permissions. Never invent identifiers to bypass a conflict. Removing managed keys restores saved local preferences. Removing the profile does not uninstall Silmaril.For every new app version, create a new version-specific Once per computer policy and script with the new minimum build. Disable old installer policies before enabling the new one. Editing an old Once per computer policy does not rerun it on Macs that already completed it.Expected result
Pilot Macs that already completed an older policy receive the new build only from the new policy, and Settings shows the intended Guardian Disabled build.If this differs
A Mac left on an older completed policy still has the previous install. Create and enable the new policy after the old installer policy is disabled, then verify again.
Pilot Macs that already completed an older policy receive the new build only from the new policy, and Settings shows the intended Guardian Disabled build.If this differs
A Mac left on an older completed policy still has the previous install. Create and enable the new policy after the old installer policy is disabled, then verify again.
7
Uninstall
Disable every Silmaril package policy for the target Macs so Jamf cannot reinstall the app. Leave unrelated policies and groups in place.Removing a computer from the rollout group is not an uninstall procedure. Keep baseline profile and policy scopes unchanged. Do not delete a group that also scopes other controls.Run the shared Uninstall through MDM script as root with the affected user signed in, and retain the JSON receipt and exit code. Exit 2 reports remaining items to review. It does not identify Guardian residue.Follow the shared result-handling instructions and remove only the Silmaril profile when policy should no longer apply. Leave baseline assignments and controls in place.Upload the script in Settings > Computer management > Scripts and add it to a scoped script-only policy under Computers > Policies. Set Once per computer and leave restart disabled.If this differs
Use that exit-code table before retrying. A missing app or helper does not prove that earlier cleanup completed.
Use that exit-code table before retrying. A missing app or helper does not prove that earlier cleanup completed.
Verify-and-launch script
MIN_BUILD is the numeric Stable build . EXPECTED_GUARDIAN is false for this Guardian Disabled policy. The script opens Silmaril only after the bundle ID, build, and Guardian variant match.