AgenShield does not require a specific MDM. If yours can push a custom macOS
configuration profile on the device channel and run a root shell script, it
can deploy AgenShield with no user interaction.
Read MDM enrollment first — it explains what the two
pieces are and why. This page is the clicks.
The recipe, whatever your MDM calls it
1
Upload the profile
Upload
deployment.mobileconfig unmodified, on the device (system)
channel, scoped to your device group. Many MDMs re-sign uploaded profiles —
that is fine.You do this once. The profile carries no enrollment token, so it stays valid
across campaign rotations and new releases.2
Run the install command as root
Add the campaign’s install command as a root script or command object,
targeting the same group:Give it a generous timeout — the download and install together take a few
minutes. It exits non-zero if the device does not finish enrolling.
Upload the profile as-is rather than rebuilding it in your MDM’s native payload
editors. It already pairs every payload with the correct extension identifiers,
including the Full Disk Access grant — the one that matters most. A device
without it enrolls and looks healthy but cannot enforce file policy.
Options for unattended runs
Set these before thecurl. Most rollouts need none of them; the full list with
defaults is in
Installing and uninstalling.
Kandji
Kandji also has native System Extension and PPPC library items. If you prefer to
mirror the payloads there, use the campaign’s profile as the reference — and push
either the native items or the uploaded profile, never both.
JumpCloud
Devices must be enrolled in JumpCloud MDM — not only the agent — for the
approval payloads to apply. JumpCloud re-signs profiles.
The command’s result view is trustworthy: a red result means the device did not
enroll, not that the script was noisy.
Mosyle
Workspace ONE (Omnissa)
Workspace ONE fixes a profile’s channel when it is created, so a profile made
as a User Profile cannot be switched to Device afterwards — delete it and create
it again. Upload the profile unsigned: signing it yourself grants no additional
permissions and turns it into an opaque binary your MDM console may no longer be
able to read.
Anything else
Ask your MDM two questions:- Can it push an unmodified custom
.mobileconfigon the device channel? If yes, AgenShield’s approvals will be silent. - Can it run a root shell script? If yes, the install is silent too.
.pkg instead — see
If you cannot run a script.
You still push a profile either way; only the install mechanism changes.
Verify
On a target Mac:Next
MDM enrollment
What each payload does and how a device joins your fleet.
Enrolled devices
Reading fleet health once devices land.