MacOS 11 "Big Sur" prevents automatic installation of profiles using the command line "profiles" command.  This was introduced for security reasons (to prevent malware from installing silently profiles which could damage the device installation), this has an impact on how profiles must be installed with FileWave.


Currently, FileWave manages profiles:


In addition, FileWave keeps track if a profile has been installed via command line tool before it has been MDM enrolled. The reasons are:

Therefore, FileWave keeps track of the method of installation and keeps managing via the profiles command line a profile which has been installed that way initially.


But, MacOS Big Sur now makes profiles -I command ineffective ; as FileWave removes and then reinstalls profiles when upgrading them, this can lead to profile removal.


Solution

Starting with FileWave 14.0.2, upgrading (command line) profiles on macOS Big Sur using the fwcld agent will be disabled, so profiles will not be removed accidentally. The next steps will be:

  1. ensure your device is MDM enrolled (DEP or User Approved)
  2. for any profile installed via command line, you need to remove the association so FileWave removes the profile via command line
  3. re-associate the profile, so FileWave now installs the profile via MDM

Nuclear Solution

If you are unable to get Filewave to remove the profiles by removing the association you will have to purge Filewave from the client:

  1. Create an association with the fileset "FileWaveUninstallermacOSv4 - incl.logging"
  2. Update Model and wait for client to deploy payload
  3. The client should now turn red and can be deleted from the server
  4. On the client - Remove the Filewave enrollment Profile (this should be the only remaining profile at this point)
  5. Reinstall the FileWave Client
  6. Run the Check Enrollment App to get a proper DEP Enrollment
  7. Import the Client into Filewave Server
  8. ???
  9. Success


Removing profile(s) may disconnect your device from your network ; proceed carefully. It may be required to deploy another profile which will allow the device to stay connected during the process.

Related articles

Related articles appear here based on the labels you select. Click to edit the macro and add or change labels.



Related issues