Skip to main content
Other MDMs cover — same profile, same command, any vendor. AgenShield does not require a specific MDM. If yours can push a custom macOS configuration profile on the device channel and run a root shell script, it can deploy AgenShield with no user interaction. Read MDM enrollment first — it explains what the two pieces are and why. This page is the clicks.

The recipe, whatever your MDM calls it

1

Upload the profile

Upload deployment.mobileconfig unmodified, on the device (system) channel, scoped to your device group. Many MDMs re-sign uploaded profiles — that is fine.You do this once. The profile carries no enrollment token, so it stays valid across campaign rotations and new releases.
2

Run the install command as root

Add the campaign’s install command as a root script or command object, targeting the same group:
Give it a generous timeout — the download and install together take a few minutes. It exits non-zero if the device does not finish enrolling.
Upload the profile as-is rather than rebuilding it in your MDM’s native payload editors. It already pairs every payload with the correct extension identifiers, including the Full Disk Access grant — the one that matters most. A device without it enrolls and looks healthy but cannot enforce file policy.

Options for unattended runs

Set these before the curl. Most rollouts need none of them; the full list with defaults is in Installing and uninstalling.

Kandji

Kandji also has native System Extension and PPPC library items. If you prefer to mirror the payloads there, use the campaign’s profile as the reference — and push either the native items or the uploaded profile, never both.

JumpCloud

Devices must be enrolled in JumpCloud MDM — not only the agent — for the approval payloads to apply. JumpCloud re-signs profiles. The command’s result view is trustworthy: a red result means the device did not enroll, not that the script was noisy.

Mosyle

Workspace ONE (Omnissa)

Upload a freshly downloaded profile. Workspace ONE cannot parse .mobileconfig files carrying a <!DOCTYPE ...> line — it reports an error like 3840 Encountered unexpected character and the profile reaches the device corrupted, or not at all. Campaign profiles no longer include that line, but an older download or a hand-rebuilt profile may. Check with head -2 deployment.mobileconfig; if line 2 is a <!DOCTYPE ...> line rather than <plist version="1.0">, delete that line and re-upload. Full steps: Profile fails to install.
Workspace ONE fixes a profile’s channel when it is created, so a profile made as a User Profile cannot be switched to Device afterwards — delete it and create it again. Upload the profile unsigned: signing it yourself grants no additional permissions and turns it into an opaque binary your MDM console may no longer be able to read.

Anything else

Ask your MDM two questions:
  1. Can it push an unmodified custom .mobileconfig on the device channel? If yes, AgenShield’s approvals will be silent.
  2. Can it run a root shell script? If yes, the install is silent too.
If the answer to the second is no, push the campaign’s all-in-one profile and the signed .pkg instead — see If you cannot run a script. You still push a profile either way; only the install mechanism changes.

Verify

On a target Mac:
The device appears under Devices in the Frontegg Portal within a minute of the command completing. If it does not, work through the troubleshooting table.

Next

MDM enrollment

What each payload does and how a device joins your fleet.

Enrolled devices

Reading fleet health once devices land.