Skip to main content
Most MDMs let you wrap a package with up to three scripts: an install check that decides whether a Mac needs the package, a pre-install script that runs just before it, and a post-install script that runs just after. This page explains what each one is for with AgenShield, gives you a script for each, and shows where each one goes in your MDM.
This page is for the package route — pushing the signed .pkg with the all-in-one profile, as described in If you cannot run a script. If you deploy with the install command, you need none of this: the command reports its own result.

What the package already does

Installing the package is all AgenShield needs. On its own, the package:
  • upgrades an existing install in place while protection keeps running — there is nothing to stop or remove first;
  • sets itself up for whoever is signed in and asks macOS to approve its extensions, which the profile makes silent;
  • enrolls the Mac with the token from agenshield.mobileconfig, and keeps trying every few minutes if the profile arrives after the package;
  • installs and starts even when nobody is signed in, and finishes extension approval at the first sign-in;
  • keeps itself up to date afterwards.
So none of the scripts on this page install, stop, configure or repair AgenShield. They only answer questions for your MDM.
Do not wrap the package with scripts that stop AgenShield before the install, edit its launch configuration, or move its data after it. They work against the package: stopping it first leaves the Mac unprotected for the whole install — and until someone intervenes if the install then fails — and moving its data can leave an enrolled Mac looking unenrolled.

What each script is for

All three are optional. Use the ones your MDM supports; the table below shows which.

The scripts

All three are read-only, run as root the way MDM scripts do, and use only tools that ship with macOS.

Install check

Set the two values at the top:
  • MODE — how your MDM reads the result. The table below gives the value for your MDM.
  • MIN_VERSION — the oldest version you accept, for example 2026.10.0. Leave it empty to accept any installed version. A newer version always passes, so devices that updated themselves are left alone.
Exit codes mean opposite things in different MDMs. With the wrong MODE, your MDM either skips every Mac that needs AgenShield or reinstalls it on every check-in.
The script reports one of four states: current, outdated, missing, or damaged — the app is there but is not the signed AgenShield app, or the agenshield command is missing.
agenshield-install-check.sh

Pre-install

Exits non-zero with the reason when the Mac cannot run AgenShield. It changes nothing either way.
agenshield-preinstall.sh

Post-install

Waits up to 90 seconds for AgenShield to answer, then writes its status to the MDM log. It exits non-zero only when the package’s files are missing after the install; a status that is not yet healthy is reported, not failed.
agenshield-postinstall.sh
What the status means:

Where each script goes

Workspace ONE

Resources → Apps → Native → Internal → Add → Application File, upload the package, and open the Scripts tab. Paste the install check with MODE="installcheck" into Install Check Script, and the other two into Pre-Install Script and Post-Install Script. Without an install check, Workspace ONE decides from the package receipt alone — and a receipt survives the app being deleted, so a Mac with a removed AgenShield.app still counts as installed. The install check catches that.

Munki

Add the scripts to the package’s pkginfo as installcheck_script (with MODE="installcheck"), preinstall_script and postinstall_script. Munki uses the install check in place of its receipt and installs checks.

Iru (formerly Kandji)

Library → Add Library Item → Mac Custom App, upload the package, and choose the Audit and enforce installation type. Paste the install check with MODE="audit" as the audit script — Iru runs it at every check-in, including before the first install. Add the other two as the pre-install and post-install scripts. A failing pre- or post-install script makes Iru run the item again at the next check-in, which is why the post-install script only fails when the package’s files are missing.

Jamf Pro

  1. Settings → Computer Management → Extension attributes → New: data type String, input type Script, paste the install check with MODE="attribute".
  2. Create a smart group where that attribute is not current, and scope the package policy to it. Macs drop out of the group once their next inventory reports current.
  3. In the package policy, add the Scripts payload — the pre-install script with priority Before and the post-install script with priority After — and Maintenance → Update Inventory, so the Mac leaves the smart group as soon as the install finishes.
Jamf does not document whether a failing Before script stops the package, so do not rely on the pre-install script alone. Also scope the policy to Operating System Version greater than or equal to 14.0 and Architecture Type arm64, so unsupported Macs never receive it.

Intune

Intune detects packages by bundle ID rather than by script. In Apps → macOS → Add → macOS app (PKG):
  • Detection rules: included app bundle ID com.frontegg.AgenShield, and set Ignore app version to Yes. With No, Intune reinstalls whenever the installed version differs from the uploaded one — including every time AgenShield updates itself.
  • Program: paste the pre-install and post-install scripts. A failing pre-install script reports the app as failed and Intune retries at a later check-in. Intune reports the install as successful whatever the post-install script returns, so read its output in the device’s management agent log.
Scripts need the Intune management agent at version 2309.007 or later.

Addigy

In the Smart Software item, add a Condition for Install of type custom script, keep Install if return value is 0 ticked, and paste the install check with MODE="installcheck". Addigy has no separate pre- or post-install script slots, so scope the item to macOS 14 or later on Apple silicon instead.

Jamf Now, Mosyle, JumpCloud and Intune line-of-business apps

These install the package without script hooks. Report install state from your MDM’s app inventory (bundle ID com.frontegg.AgenShield), and scope the assignment to Macs on macOS 14 or later with Apple silicon. For Intune line-of-business apps, set Ignore app version to Yes for the reason given above. If you want a status line in your MDM, run the post-install script on its own as a root command after the install.

Any other MDM

Ask your MDM two questions:
  1. For its detection or check script, does exit 0 mean “install needed” or “installed”? “Install needed” is MODE="installcheck"; “installed” is MODE="audit". If it collects inventory values instead, use MODE="attribute".
  2. What does it do when a post-install script fails? If the answer is “retry”, “reinstall” or “uninstall”, keep the post-install script as it is — it already fails only when the package’s files are missing.

If nobody is signed in

Installing at the login window or during Setup Assistant is supported. AgenShield installs, enrolls from the profile and starts protecting the Mac straight away. Extension approval completes at the first sign-in, and so does network inspection — see Network inspection is not active after a managed install. The post-install script says so in its output; it is not a failure. AgenShield keeps its enrollment and history through later installs: when the next install or update runs with someone signed in, it carries everything over to that user, and an update installed at the login window leaves it where it is.

Verify

On a target Mac:

Next

MDM enrollment

What each payload does and how a device joins your fleet.

Install campaigns

Where the package and profiles come from, and how to pin a version.