Live data from Hacker News

Show HN: MicroMDM – Open Source MDM Server for Apple Devices

micromdm.io

11–20 of 48 posts

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#11
post #9
post #3

Earlier quoted context omitted.

The server is only meant for enterprise deployments. It would be pretty hard to do this on a personal level because you need to apply for an enterprise account with Apple, and request a very specific push certificate option.

Anyone can get a push certificate, it's not just businesses, https://identity.apple.com/pushcert/

MDM push notifications require to be signed by a special certificate, which is only available upon request.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#12
post #7
post #6

This seems like the kind of thing Apple should be offering on their own already. But ultimately you're not going to see many enterprises adopt an Apple-only MDM unless they just love vendor lock-in to the most expensive vendor. Negativity aside, I applaud the effort. The MDM space is messy and crowded with bloated products. I hope these guys can at the very least pop the bubble a bit.

Apple has absolutely no desire to go into the device management business. They make the devices, they don't provide IT departments with any in house tools, the entire macOS management ecosystem has risen from a need and it's a mish mash of different vendors / open source tools / approaches to skin the cat that is device management.

Apple is actively trying to sell me MDM services. So they may not be in the business of making it easy, but they're certainly in the business of making money on it.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#13
post #8
post #2

I'm curious do any HN readers manage their personal devices through MDM with their own profiles, and what benefits are you seeing from that?

There are HN readers who are Directors of IT at their place of employment

That wasn't the question.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#14
post #7
post #6

This seems like the kind of thing Apple should be offering on their own already. But ultimately you're not going to see many enterprises adopt an Apple-only MDM unless they just love vendor lock-in to the most expensive vendor. Negativity aside, I applaud the effort. The MDM space is messy and crowded with bloated products. I hope these guys can at the very least pop the bubble a bit.

Apple has absolutely no desire to go into the device management business. They make the devices, they don't provide IT departments with any in house tools, the entire macOS management ecosystem has risen from a need and it's a mish mash of different vendors / open source tools / approaches to skin the cat that is device management.

They already took a baby step in by acquiring TestFlight. It's a more dev/QA-centric product, but it overlaps with MDM. Google is already in the MDM space for Chrome devices. Apple has already been remarkably successful in the enterprise space despite seemingly never going after it. Vendors like Square are deploying thousands of iPads to retail spaces. I think there's a huge opportunity there.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#15
post #3
post #2

I'm curious do any HN readers manage their personal devices through MDM with their own profiles, and what benefits are you seeing from that?

The server is only meant for enterprise deployments. It would be pretty hard to do this on a personal level because you need to apply for an enterprise account with Apple, and request a very specific push certificate option.

Setting up Mobile Device Management itself is not particularly onerous, it's definitely best practice to create a new Apple ID for that purpose, however. A technical individual can already do this easily enough with the freely-available Meraki MDM. The Device Enrollment Program I believe is more complicated and inaccessible to individuals (haven't dealt with this personally), and is quickly becoming a prerequisite for many of the more invasive and useful capabilities, like the kext signing and deployment mentioned on the MicroMDM homepage.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#17
post #3

Earlier quoted context omitted.

The server is only meant for enterprise deployments. It would be pretty hard to do this on a personal level because you need to apply for an enterprise account with Apple, and request a very specific push certificate option.

Setting up Mobile Device Management itself is not particularly onerous, it's definitely best practice to create a new Apple ID for that purpose, however. A technical individual can already do this easily enough with the freely-available Meraki MDM. The Device Enrollment Program I believe is more complicated and inaccessible to individuals (haven't dealt with this personally), and is quickly becoming a prerequisite fo…

Meraki MDM is not free anymore AFAIK. But if you signed up while they offered the 100 free devices plan it's still valid.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#18
post #6

This seems like the kind of thing Apple should be offering on their own already. But ultimately you're not going to see many enterprises adopt an Apple-only MDM unless they just love vendor lock-in to the most expensive vendor. Negativity aside, I applaud the effort. The MDM space is messy and crowded with bloated products. I hope these guys can at the very least pop the bubble a bit.

One of the few remaining services in macOS Server (discussed elsewhere on HN today) is Profile Manager, an Apple-developed MDM server. Given that it requires a static public IP and only runs on macOS, there's a pretty small niche that even could use it. The MicroMDM site describes it as the 'reference' or 'proof-of-concept' MDM server, "depending on how jaded you are about it".

I think Apple is happy with the current state of MDM servers--several good 3rd-party options, both self-hosted and cloud.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#19
post #2

I'm curious do any HN readers manage their personal devices through MDM with their own profiles, and what benefits are you seeing from that?

I manage our devices at work but not my personal devices.

If you have a lot of devices (think 10+) I guess it could be useful to keep them aligned. It could also be useful as training on how to centrally manage devices.

But I would not recommend using a MDM unless you have a specific reason. Personal devices that you have physical control over are easy to manage locally on the device. Adding a MDM also adds another attack vector, if the MDM is compromised all your devices are at risk.

Re: Show HN: MicroMDM – Open Source MDM Server for Apple Devices

#20
post #12
post #7

Earlier quoted context omitted.

Apple has absolutely no desire to go into the device management business. They make the devices, they don't provide IT departments with any in house tools, the entire macOS management ecosystem has risen from a need and it's a mish mash of different vendors / open source tools / approaches to skin the cat that is device management.

Apple is actively trying to sell me MDM services. So they may not be in the business of making it easy, but they're certainly in the business of making money on it.

Isn’t that their pro-services offering where they monkeyed together a bunch of enterprise scripts for bugs/shortfalls Apple will never fix/implement? Last I checked, I think the only MDM “service” they offer is evaluating your situation as part of the enterprise package and no matter what telling you to use JAMF.
Post reply on HN