Mac Enrollment
Before you enroll macOS devices, make sure you have an Apple Push Certificate set up in your Dashboard organization.
Access Rights
By default, Systems Manager will grant administrators the maximum amount of control available when applied to your Apple devices upon enrollment. However, in certain bring-your-own-device (BYOD) environments where the device is personally owned, device owners may not want administrators having this level of control over their personal devices.
Systems Manager can be customized to meet the needs of different deployment models by changing the permissions of what can be retrieved from or sent to the device. It is important to note that Access Rights must be set before devices are enrolled; changes made after enrollment will only take effect if a device is re-enrolled.
Access rights limitations can be found in Configure > General. See the article here for more info
On-device Enrollment
If you have a Dashboard account set up with an EMM network, you can find instructions under Systems Manager > Manage > Add devices, or follow along the steps below.
Note that are two methods for Mac enrollment: Agent or Profile. Either one can be used for enrollment, but since each enables a different subset of features, both should be utilized when possible to access all available MDM features.
Agent Installation
The agent now supports automatic and remote installation through the Apps page, which does not require manually executing the .pkg on the end device. See this article for more information.
- 
    Navigate to Systems Manager > Manage > Add devices > macOS. 
- Click the Download button. An agent, .pkg will download or .dmg for 4.1.4+. Note that this installer will enroll devices into the Systems Manager network it was downloaded from.
Command Line Options
Command line installation of the macOS agent is no longer supported (but remember, if the macOS device is enrolled with the enrollment profile first the agent can be installed from the SM > Apps page).
Version 3.8.3 +
The SM agent must be deployed via manual UI installation or pushed via Systems Manager > apps after the management profile has been installed.
- After the download is complete, double-click the installer
- When the installer begins, click Continue
  
- Read the Software License and click Continue.
  
- Click Agree to accept if prompted.
- Click Install to perform a standard installation.
  
- Enter the user's device password when prompted. Click Install Software
  
- Enter the Network ID or Network Enrollment String of the target Systems Manager network the device should enroll to.  Click Enroll
  
- Confirm the name of the Systems Manager network and click Continue
  
- After the installation has completed, click Close. Choose to move the installer to the Trash or keep it in its current location.
- Once the installation has finished, your Mac device will show up under Monitor > Clients in Dashboard as soon as it has an Internet connection.
Troubleshooting Agent Installer
During agent installation, installation may fail. To retrieve logging for troubleshooting or for Meraki support, the macOS installer log is located in the machine's /var/log/install.log file. To avoid navigating system directories, this file can be copied to the current user's desktop using the following terminal command:
cp /var/log/install.log ~/Desktop
Profile Installation
- 
    Navigate to Systems Manager > Manage > Add devices > macOS. 
- 
    From the device, open enroll.meraki.com 
- Enter your network ID, where XXX-XXX-XXXX is the network-specific ID.
- Press Register.
    - If using SM Enrollment Authentication then follow the prompts accordingly. For more information view the Enrollment Authentication article here.
 
- In the profile that appears, press Install, then Install again to confirm.
Apple Automated Device Enrollment (ADE)
Through integration between Systems Manager and Apple, you can automatically have devices enroll into Systems Manager and install the management profile both over the air and out of the box. For more information about configuring and using Apple ADE, please view the following page.
Additional Enrollment Methods
Endpoint Management Enrollment SSID
You can also use SM Sentry to force iOS, Android, Windows, and Mac devices to enroll in Systems Manager for an efficient mass deployment or BYOD. When enabled on a given SSID for a Cisco Meraki wireless access point, Sentry facilitates the secure and rapid onboarding and deployment of SM to mobile devices. For more information on Endpoint management enrollment, please visit the following page.
Other Options
You can also send device enrollment information to your users via email, by navigating to MDM > Add devices > macOS. This method also allows you to pre-configure a tag to be applied upon registration.
Considerations for Apple Silicon Macs
Non Intel-based macOS devices, such as the M1 chip macOS devices, require some additional considerations while deploying via MDM:
- The 'Reduced Security' state must be enabled for advanced payloads to work, such as Kernel Extensions.

