Why is the Extra Username and Password Dialog Box Required?Īs mentioned above in the Changes with Apple Silicon Hardware section, on the Apple Silicon architecture a new concept is introduced by Apple called Volume Ownership. This is a bug in macOS and will be fixed in a future release to reflect the same experience from macOS Monterey.įor more information, please see Allow Standard Users to Use the Full macOS Installer via Privilege Management for Mac. For more information, please see Delta Update Process (Ventura). Privilege Management for Mac does not control this dialog.Įnd users can update macOS with delta updates without issue and we go through this process below with examples.Įnd users will encounter issues when using the full-installer, because a user who is both a local administrator and who has a secure token (volume owner) is required to approve the installation.īe aware that when applying a delta update on macOS Ventura, for example when upgrading from 13.0 to 13.1, the username and password dialog box displays that it requires the credentials for an administrative user. During the user-initiated software update, the end user is prompted for an additional username and password dialog, which is presented by macOS. Once this is shown, they can update the OS. At that point they are offered the delta installer, which is approximately 6GB. If an end user is offered only the full installer, the user can quit the System Preferences application and relaunch it. If the update being presented to the user is shown as a 12GB or larger, this implies that the update is going to attempt to download the macOS full installer package as opposed to a delta update. Privilege Management for Mac does allow policy control to allow standard users to install delta or minor updates through the System Settings / System Preferences app but not the full installer. For Kandji, Configuring Managed OS for macOSĮnd users ultimately want to update the macOS version on their hardware, and with Privilege Management for Mac installed this is still possible, although there are some caveats.For JAMF, macOS Upgrades and Updates Using a Mass Action Command.One advantage of managing software updates in this way is that organizations are not beholden to the vigilance of their end users to ensure that the latest security patches are applied.įor more MDM provider specific guidance, please see: Official guidance from Apple is that organizations managing multiple Mac devices use their MDM provider to manage and schedule OS updates. Apple-Recommended Method for Updating macOS Devices This is necessary so that different volumes on local storage used during the software update process can be unlocked to allow the update data to be written to them.įor more information, please see Use secure token, bootstrap token and volume ownership in deployments. This change has affected the software update mechanism because updates now require these credentials. At the time of writing, any user on the system with a secure token is considered a volume owner by macOS, regardless of whether they are a local administrator. On the Apple Silicon architecture, Apple has introduced a new concept called Volume Ownership. ![]() Allow Standard Users to Use the Full macOS Installer via Privilege Management for MacĪpple Changes with Apple Silicon Hardware.Apple Recommended Method for Updating macOS Devices.Apple Changes with Apple Silicon Hardware. ![]() Install macOS Updates On Apple Silicon Hardware
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |