Check the endpoint
1
Confirm identity
Open Settings and check the installed release.Expected result
Settings shows Stable , build , and Guardian Disabled.If this differs
Contact support before replacing an incompatible installed variant. Jamf and Iru treat as a minimum build so an install check can accept a newer build. Verification of this Stable release still expects the version and build named here.
Settings shows Stable , build , and Guardian Disabled.If this differs
Contact support before replacing an incompatible installed variant. Jamf and Iru treat as a minimum build so an install check can accept a newer build. Verification of this Stable release still expects the version and build named here.
2
Confirm policy and connection
For MDM deployments, inspect the connection and each setting your profile forces in Settings.Direct installs store the typed API key in the user’s login Keychain. Connection fields are not Managed unless a profile is also installed. On MDM Macs, the profile supplies the URL and key.Expected result
MDM Macs show Managed for the API URL, API key, and every other setting you intended to force. There is no Applying, Restart required, or Needs attention state. When the first-run connection screen is displayed, it reports Firewall connection verified.If this differs
Resolve pending or failed states with troubleshooting. Correct invalid profile values using the settings reference. They do not silently fall back to local values. For Restart required, fully quit and reopen the affected agent and start a new session.
MDM Macs show Managed for the API URL, API key, and every other setting you intended to force. There is no Applying, Restart required, or Needs attention state. When the first-run connection screen is displayed, it reports Firewall connection verified.If this differs
Resolve pending or failed states with troubleshooting. Correct invalid profile values using the settings reference. They do not silently fall back to local values. For Restart required, fully quit and reopen the affected agent and start a new session.
3
Confirm the baseline stayed in place
Compare the pilot Mac’s assignments and configuration profiles before and after the Silmaril rollout. These are administrator checks in your MDM.They are separate from live Protection activity.Expected result
The pilot Mac still has the baseline controls that were present before Silmaril, and it also has the Silmaril profile. A Mac outside the Silmaril tag, group, or label keeps that baseline and has no new Silmaril assignment.If this differs
Stop the rollout. Restore any missing baseline profile, and remove a Silmaril assignment from any Mac that was outside the intended scope.
The pilot Mac still has the baseline controls that were present before Silmaril, and it also has the Silmaril profile. A Mac outside the Silmaril tag, group, or label keeps that baseline and has no new Silmaril assignment.If this differs
Stop the rollout. Restore any missing baseline profile, and remove a Silmaril assignment from any Mac that was outside the intended scope.
4
Confirm live protection
Prepare supported agents and start a new agent session.Expected result
A new session produces current activity in Protection.If this differs
The endpoint is not confirmed protected. Recheck identity and connection, resolve any Restart required state, and start another new session. Package status, profile assignment, and a Managed label can all be true while this activity is still absent.
A new session produces current activity in Protection.If this differs
The endpoint is not confirmed protected. Recheck identity and connection, resolve any Restart required state, and start another new session. Package status, profile assignment, and a Managed label can all be true while this activity is still absent.