This KB explains the new feature introduced in Apple MacOS version 10.13.2, where User MDM profiles now need User input before being applied, and how profiles installed using Centrify will be impacted
Question:
User Approval of MDM enrollment has been introduced with macOS High Sierra 10.13.2. How does that impact Mac enrollment with Centrify Identity Platform?
Apple Reference for User Approved MDM enrollment: (link provided as a courtesy and subject to change): https://support.apple.com/en-us/HT208019
Answer:
An Administrator or User will now see a notice under the Centrify Identity Platform Profile, indicating: "Functionality may be limited until this profile is approved.":
In working with Apple, Centrify noticed the following two things;
1. Users do not need to approve the profile and it does not affect any MDM profiles.
2. As of 10.13.2, the only MDM functionality that will be unavailable to a un-approved MDM enrollment is the ability to install the new (to 10.13.2) "Secure Kernel Extension Loading" payload. Centrify does not do 'Secure Kernel Extension Loading' in the MDM profiles.