Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-2554: How to deploy mobileconfig profiles on Mac OS X 10.7 and higher.

Centrify Identity Service, Mac Edition ,  

12 April,16 at 11:11 AM

Applies to: Centrify DirectControl 5.2.0 and higher on Mac OS X 10.7 and higher.
 
Question:
 
Some configuration profiles (mobileconfig files) can be exported from the iPhone Configuration Utility or Profile Manager in OS X Server and used on OS X systems. These are very useful for deploying settings which are not yet available via GP, such as some wireless and VPN configurations.
 
Can these mobileconfig profiles be deployed using Centrify group policies?

Reference links:
(All external links are provided as a courtesy)
 
 
Answer:

For Centrify User Suite 2014.1 (Mac agent version 5.2.0) and higher:
 
Deployment of Apple mobileconfig files is now natively supported via the following group policies:
  • Computer Configuration / Centrify Settings / Mac OS X Settings / Custom Settings / "Install MobileConfig Profiles"
     
  • User Configuration / Centrify Settings / Mac OS X Settings / Custom Settings / "Install MobileConfig Profiles"
 
Notes:
  • The Computer Configuration GP will install profiles at the Device Level and is supported for OS X 10.7 and higher.
  • The User Configuration GP will install profiles at the User Level and is supported for OS X 10.9 and higher.
  • Make sure to check the Explain tabs in both GPs for correct usage and deployment.
  • Before deploying a mobileconfig profile, test it locally on a Mac system first by copying it over and double-clicking the exported file. If the settings work via a manual install, then they should also work via the GP.
  • Please note that the Profile Manager and iPhone Configuration Utility are both Apple products - any issues regarding the mobileconfig profiles themselves will need to be presented to Apple Support.
     
 


For systems with Mac agent versions lower than 5.2.0:

For system that have not yet been updated to 5.2.0, it may be possible to install the profiles via a login script using the steps below:
 
Important:
  • The following scripting hints are provided as a proof-of-concept ONLY.
  • Centrify Support does not cover custom-scripting - please contact Centrify Professional Services for further assistance with any scripting.
 
---
 
Example steps for configuring and deploying Wi-Fi mobileconfig settings via GP:
  1. Using the iPhone Configuration Utility, create a new Configuration Profile and enter the wireless settings under the section:
     
    Configuration Profiles > Wi-Fi
     
    User-added image
     
     
     
  2. In the General section, enter a unique identifier name in the "Identifier" box and make a note of this for later:
     
    Configuration Profile > General
     
    User-added image
     
     
  3. Export the profile settings and when asked, select "None" for the Security option.
     
  4. Download the attached login script and open it with a UNIX capable text editor.
    (Notepad++ is recommended on Windows systems, do not use notepad.exe)
     
  5. Find and edit the following lines to match the exported mobileconfig file:
     
    PROFILE_IDENTIFIER='com.company.profile'
    - (The identifier name from Step 2.)
     
    MOBILECONFIG_FILE='exported_profile.mobileconfig'
    - (The filename of the exported mobileconfig file)
     
  6. Copy the mobileconfig profile to the AD server in the folder:
     
    \\ <domain> \SYSVOL\ <domain> \
     
    User-added image
     
     
  7. Copy the install_mobile_config.sh script to the folder:
     
    \\ <domain> \SYSVOL\ <domain> \scripts\ 
     
    User-added image
     
     
  8. Set up the "Copy file" GP at:
     
    Computer Configuration / Centrify Settings / Common UNIX Settings / "Copy files"
     
    - In the GP, click Add, then Browse and select the mobileconfig file.
    - Destination: /var/db/ConfigurationProfiles/
    - Do not copy as binary file
     
  9. Set up the Login Script GP at:
     
    User Configuration / Centrify Settings / Mac OS X Settings / Scripts / "Specify login script"
     
    - Enter the filename of the script only: install_mobile_config.sh
    - Run with root user privileges: Enabled
     
  10. To allow the GP to take affect immediately, go to the Mac as the AD user, open up Terminal and run the command:
     
    adgpupdate
     
  11. The wireless profile should take immediate affect and if within range, will automatically connect.
 
Note:
  • The attached example script will install the mobileconfig as a 'Device Profile'.
  • To install the mobileconfig as a 'User Profile', open script change the instructions starting with:
     
    sudo /usr/bin/profiles ... 
     
    To:
     
    /usr/bin/profiles ...
     
    (There are three instances).
     
  • Once the sudo commands have been edited, place the script in the "Specify multiple login scripts" GP instead of the "Specify login script" GP.


(All external links provided as a courtesy.)
Attachments:

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.