The MDM (profile + package) option appears on Deployment once the signed macOS package is available for your organization. Until then, install with the RMM script.
Get the profile and the package
- Open the client and go to Deployment. Set the seat cap and create or paste an enrollment key.
- In the install step, pick macOS, then MDM (profile + package).
- Optional: tick Hide “Background Items Added” notifications. See what the profile contains before you do.
- Choose Download mspilot-agent-<client id>.mobileconfig. The button is off until the key field holds a valid key.
- Choose Copy package link, or download the package from the link under the buttons.
- Deploy the profile and the package with your MDM. The steps for each MDM are below.
- Back on Deployment, choose I’ve deployed them from my MDM.
/Library/Logs/MSPilot/install.log and /Library/Logs/MSPilot/enroll-retry.log on a Mac, then retry.
The macOS choice is off when ImmyBot is the connected RMM (MSPilot’s ImmyBot installer is Windows only), so this method is not available there.
Use a dedicated enrollment key
Create a client key for the MDM and use it only there. Once the client is at its seat cap, machines that enroll with the key wait for approval instead of taking a seat. After rollout, revoke the key on Deployment. Enrolled Macs keep working, because they use their own device credential after enrolling, not the key. Your RMM scripts are untouched. A new Mac, or one that hits a rejected key, needs a valid key in the profile. To enroll more Macs later, create a new key and update the profile with it. In N-sight RMM, use Edit profile on the existing profile and choose to save and push the update. See Enrollment keys.What the profile contains
The profile is built in your browser, with the key inside it. It is one system-scoped configuration profile named MSPilot agent. It is not signed. Your MDM signs it when you upload it.
Apple accepts the Managed Login Items payload only on the device channel of a Mac whose MDM enrollment the user approved. Background items and their notifications are a macOS 13 feature.
The profile’s identifier is the same for every file you download for a client, so a new download replaces the old profile when you deploy it.
The package
The package ismspilot-agent-macos.pkg, signed with a Developer ID Installer certificate and notarized by Apple. It installs the agent into /Library/Application Support/MSPilot and then runs the same install and enroll as the RMM script. It installs no app into /Applications.
Deployment shows a versioned link:
/Library/Logs/MSPilot/install.log and later enrollment retries to /Library/Logs/MSPilot/enroll-retry.log.
Deploy the profile first
Install the profile before the package when you can. The package then enrolls the Mac as soon as it installs. If the package lands first, the agent waits for the profile.install.log shows pending_profile waiting for the io.mspilot.agent configuration profile. The enroll retry job checks every 15 minutes, so the Mac enrolls within 15 minutes of the profile arriving. You do not reinstall the package.
Steps for your MDM
- N-sight
- Intune
- Jamf Pro
- Kandji
- Mosyle
-
In N-sight RMM, go to Dashboards → Device Management for Apple → Profiles → Upload profile. Enter a profile name and upload the
.mobileconfig. - On the Devices tab, select the Macs, choose Install profiles, select the MSPilot profile, and choose Install.
- In the All Devices view, select the same Macs, right-click, and choose Task → Add. Under Maintenance, pick the Automated Task Install Application from URL. For the frequency, choose Manual, then run it on demand once, so it does not reinstall the package on a schedule.
- Command Line: the versioned package link from Deployment.
-
To change the key later, or after it was rejected, open the existing profile with Edit profile, upload the new file, and choose to save and push the update to the devices. Do not delete the profile and upload it again. That fails with
A profile with the same ID already exists.
When the key is rejected
The agent writes these lines on the Mac:managed_install_rejectedin/Library/Logs/MSPilot/install.logwhen the first package install hits the rejection, or in/Library/Logs/MSPilot/enroll-retry.logwhen a later retry does.managed_install_waiting_for_new_keyinenroll-retry.logon the retries after that.
- On Deployment, create a new key, or paste a valid one.
- Download the profile again.
- Replace the profile in your MDM and deploy the update to the Macs. In N-sight RMM, use Edit profile on the existing profile and choose to save and push the update.
GatewayURL matches your organization.