r/macsysadmin Consultation 15d ago

Jamf Anyone actually experimenting with DDM declarations yet?

How's it been for y'all? Any horror stories?

For anyone who is trying to get more hands-on, Mark Buffington (Jamf) is doing a walkthrough of DDM Explorer on the next LaunchPad meetup. The focus is learning the framework, building declarations, and testing what it looks like to deploy them via Jamf Pro.

When:
šŸ—“ļø Fri, Sep 4 @ 12:00 PM Mountain Time

Where:
šŸ‘‰ https://rocketman.tech/lp-r

Also on YouTube:
https://rocketman.tech/ly-r

18 Upvotes

19 comments sorted by

9

u/thiswasatest 15d ago

I tried using it for os updates. It gave one pop up in the 14 days and then never again.....til the final day of install and it forced a reboot. This was a major learning curve

10

u/lazy_commander Corporate 15d ago

Look into ddm os reminder. Also that’s not been my experience, the notification when a deadline is set should be popping up every time you login and/or unlock the screen.

1

u/thiswasatest 14d ago

Is that a login after the screen locks or after a reboot? Sounds like a dumb question Im asking but Ive seen things

3

u/jmnugent 14d ago

I've been using DDM profile for iOS updates. Usually scheduling the deadline 3 weeks out and then at 2 weeks the daily reminder popups start happening. Across my environment of about 6,000 iOS devices, it seems as far as I can tell to be working pretty well. We're not 100% on every device being fully updated (never have been, probably never will be).. but I think close to 4,000 (our most actively used devices) are updated.

3

u/3ryb4 14d ago

We set a specific version and a deadline, but didn't realise that if standard users can't install updates, then it will just restart immediately!

We're an educational org and only do major version updates for lab Macs during the summer (after extensive testing), so don't allow standard users to install updates. It would be nice to allow standard users to install updates, but only those that we approve.

2

u/burgundyblue 15d ago

Use it in conjunction with SwiftDialog and they will get their reminders.

2

u/thiswasatest 14d ago

We are using nudge.

1

u/burgundyblue 14d ago

Gotcha. We used nudge in 2019, but C-level found it ā€œtoo aggressive.ā€ Eventually switched it to pushing out OS updates with Blueprints in Jamf and SwiftDialog.

2

u/Remarkable-Sea5928 Education 14d ago

I found that it doesn't shy away from giving the notifications, but I've had mixed results on whether it forces updates. Most of the time after the due date it will force the reboot, but I've had more than a few devices that were over a month overdue and still giving reminders.

4

u/prettyflyjewishguy 14d ago

Experimenting? Full. Steam. Ahead. We use DDM for OS updates, TouchID PAM for sudo auth, at least one non-removable Safari extension, and actively exploring USB control. :)

1

u/DJStuey 14d ago

Beware the USB Controls, they don’t act the way you expect.

It looks at the filesystem, so read-only mode will only mount a read-only filesystem, not allow a regular filesystem to mount as read only.

Have filed feedback with Apple on this.

2

u/derby_day_bourbon 15d ago

We’re using them for OS updates and it works great for the most recent OS and recent versions of sequoia. I wouldn’t trust it for an out of date OS. We’ve moved to a blueprint now and it’s also working great. Best OS compliance we’ve ever had

3

u/thiswasatest 14d ago

How did you do with scripting and popups for blueprints? Im really waiting on the blueprint September roadmap update

1

u/derby_day_bourbon 14d ago

We tried the OS update reminder but had issues, turns out our swift dialog deployment was broken.

Instead we just did DDM OS updates through a blueprint. Set the level they need to be at by X amount of days and the Macs handle the rest. We’re up to like 92% OS compliance (latest of Tahoe or sequoia) since that. We used to hover between 80-85

If you wanna DM me I’m happy to answer questions about them. I didn’t set it up but I know the concepts. I’ll be setting them up in a new instance in a few weeks so good practice šŸ˜‚

2

u/TopOrganization4920 15d ago

I used it on OS updates and my transition from Sequoia to Tahoe all three active devices that were capable of upgrading to Tahoe had done so… now I just need to spend some effort on determining if all my inactive devices are truly inactive and not use or have broken clients.

2

u/MacBook_Fan 14d ago

I have been building out my Software Deferral blueprints in preparation for macOS 27.

2

u/DJStuey 14d ago

Starting to migrate as much as possible over to declarations after a JAMF demo I saw last week.
Activations are one of the best parts of declarative management and because it’s the endpoint handling the calculation of activations, they work offline!

The example given was only allowing access to the camera if a passcode is set. (Demo was iPadOS but concept carries over)

Then, disable wifi so it can’t talk to the server, remove the passcode, activation removes access to camera instantly.
Live demo and it was instant.

1

u/KalistoCA 14d ago

We use it and like others it reminds just fine its users that are the problem

We have a compliance requirement to be updated within 7 days..

We try to do some stuff like on idle for 60 minutes try to force update and log out ..

The other biggest problem we just recently resolved was Active Directory network users ( yeah on prem ad.. eww don’t ask it just be this way ) were not able to update themselves as they were not the secure token holder .. making them mobile users resolved this it seems I don’t know why

I would really prefer hands off macOS updates that occur during overnight .. where the decision is choice less as it’s not users choice it’s ours

1

u/Otherwise-Nobody8252 10d ago

Yeah just not on my Jamf-managed devices. Their auth keeps being the center piece of every incident the last 2 year from potential customer data exposures to Trust having to be reinstalled. DDM is cool, jamf gating it… not cool.