This page is for the package route — pushing the signed
.pkg with the
all-in-one profile, as described in
If you cannot run a script.
If you deploy with the install command, you need none of this: the command
reports its own result.What the package already does
Installing the package is all AgenShield needs. On its own, the package:- upgrades an existing install in place while protection keeps running — there is nothing to stop or remove first;
- sets itself up for whoever is signed in and asks macOS to approve its extensions, which the profile makes silent;
- enrolls the Mac with the token from
agenshield.mobileconfig, and keeps trying every few minutes if the profile arrives after the package; - installs and starts even when nobody is signed in, and finishes extension approval at the first sign-in;
- keeps itself up to date afterwards.
What each script is for
All three are optional. Use the ones your MDM supports; the
table below shows which.
The scripts
All three are read-only, run as root the way MDM scripts do, and use only tools that ship with macOS.Install check
Set the two values at the top:-
MODE— how your MDM reads the result. The table below gives the value for your MDM. -
MIN_VERSION— the oldest version you accept, for example2026.10.0. Leave it empty to accept any installed version. A newer version always passes, so devices that updated themselves are left alone.
current, outdated, missing, or
damaged — the app is there but is not the signed AgenShield app, or the
agenshield command is missing.
agenshield-install-check.sh
Pre-install
Exits non-zero with the reason when the Mac cannot run AgenShield. It changes nothing either way.agenshield-preinstall.sh
Post-install
Waits up to 90 seconds for AgenShield to answer, then writes its status to the MDM log. It exits non-zero only when the package’s files are missing after the install; a status that is not yethealthy is reported, not failed.
agenshield-postinstall.sh
Where each script goes
Workspace ONE
Resources → Apps → Native → Internal → Add → Application File, upload the package, and open the Scripts tab. Paste the install check withMODE="installcheck" into Install Check Script, and the other two into
Pre-Install Script and Post-Install Script.
Without an install check, Workspace ONE decides from the package receipt alone —
and a receipt survives the app being deleted, so a Mac with a removed
AgenShield.app still counts as installed. The install check catches that.
Munki
Add the scripts to the package’s pkginfo asinstallcheck_script (with
MODE="installcheck"), preinstall_script and postinstall_script. Munki uses
the install check in place of its receipt and installs checks.
Iru (formerly Kandji)
Library → Add Library Item → Mac Custom App, upload the package, and choose the Audit and enforce installation type. Paste the install check withMODE="audit" as the audit script — Iru runs it at every check-in, including
before the first install. Add the other two as the pre-install and post-install
scripts. A failing pre- or post-install script makes Iru run the item again at
the next check-in, which is why the post-install script only fails when the
package’s files are missing.
Jamf Pro
- Settings → Computer Management → Extension attributes → New: data type
String, input type Script, paste the install check with
MODE="attribute". - Create a smart group where that attribute is not
current, and scope the package policy to it. Macs drop out of the group once their next inventory reportscurrent. - In the package policy, add the Scripts payload — the pre-install script with priority Before and the post-install script with priority After — and Maintenance → Update Inventory, so the Mac leaves the smart group as soon as the install finishes.
14.0 and Architecture
Type arm64, so unsupported Macs never receive it.
Intune
Intune detects packages by bundle ID rather than by script. In Apps → macOS → Add → macOS app (PKG):- Detection rules: included app bundle ID
com.frontegg.AgenShield, and set Ignore app version to Yes. With No, Intune reinstalls whenever the installed version differs from the uploaded one — including every time AgenShield updates itself. - Program: paste the pre-install and post-install scripts. A failing pre-install script reports the app as failed and Intune retries at a later check-in. Intune reports the install as successful whatever the post-install script returns, so read its output in the device’s management agent log.
Addigy
In the Smart Software item, add a Condition for Install of type custom script, keep Install if return value is 0 ticked, and paste the install check withMODE="installcheck". Addigy has no separate pre- or post-install script
slots, so scope the item to macOS 14 or later on Apple silicon instead.
Jamf Now, Mosyle, JumpCloud and Intune line-of-business apps
These install the package without script hooks. Report install state from your MDM’s app inventory (bundle IDcom.frontegg.AgenShield), and scope the
assignment to Macs on macOS 14 or later with Apple silicon. For Intune
line-of-business apps, set Ignore app version to Yes for the reason
given above. If you want a status line in your MDM, run the
post-install script on its own as a root command after the install.
Any other MDM
Ask your MDM two questions:- For its detection or check script, does exit
0mean “install needed” or “installed”? “Install needed” isMODE="installcheck"; “installed” isMODE="audit". If it collects inventory values instead, useMODE="attribute". - What does it do when a post-install script fails? If the answer is “retry”, “reinstall” or “uninstall”, keep the post-install script as it is — it already fails only when the package’s files are missing.
If nobody is signed in
Installing at the login window or during Setup Assistant is supported. AgenShield installs, enrolls from the profile and starts protecting the Mac straight away. Extension approval completes at the first sign-in, and so does network inspection — see Network inspection is not active after a managed install. The post-install script says so in its output; it is not a failure. AgenShield keeps its enrollment and history through later installs: when the next install or update runs with someone signed in, it carries everything over to that user, and an update installed at the login window leaves it where it is.Verify
On a target Mac:Next
MDM enrollment
What each payload does and how a device joins your fleet.
Install campaigns
Where the package and profiles come from, and how to pin a version.