Deploy with Fleet
1
Prepare
Have administrator access, an enrolled Mac running , and the vendor management agent where required. Download the Stable () Guardian Disabled PKG and complete the required configuration before upload.Expected result
The completed
Finish the rollout plan before adding the Fleet profile or package.
The completed
Silmaril-Managed.mobileconfig has passed validation, and the package is the Stable PKG.If this differsFinish the rollout plan before adding the Fleet profile or package.
2
Add the profile
Open Controls > OS settings > Configuration profiles and stay in the Mac’s current fleet. Choose Add profile and upload the completed
The profile row keeps PayloadIdentifier
Edit that existing row instead of adding a second identity. Keep the supplied PayloadIdentifier, PayloadDisplayName, UUIDs, and permissions.
Silmaril-Managed.mobileconfig. Fleet signs uploaded profiles.Do not move the host to another fleet. Do not broaden this profile to all hosts to work around unavailable targeting. Label-based targeting requires Fleet Premium. Confirm a supported target for the intended hosts before upload. If that target is unavailable, stop and establish a supported scoped rollout before uploading.For replacement, edit the existing row and keep both the same PayloadIdentifier and PayloadDisplayName, along with all supplied UUIDs and permissions.Expected resultThe profile row keeps PayloadIdentifier
dev.silmaril.mdm.managed and PayloadDisplayName Silmaril Managed, plus the supplied UUIDs and permission payloads.If this differsEdit that existing row instead of adding a second identity. Keep the supplied PayloadIdentifier, PayloadDisplayName, UUIDs, and permissions.
3
Confirm profile installation
Confirm the configuration profile is installed on the pilot hosts before distributing the app. For a later cohort, wait until those hosts show the profile installed before installing the package. Adding hosts to a label that already installs the package does not recreate that order.Expected result
Pilot hosts show the profile installed.If this differs
Wait for installation before adding or installing the package on those hosts.
Pilot hosts show the profile installed.If this differs
Wait for installation before adding or installing the package on those hosts.
4
Configure package installation
With Fleet software management and scripts enabled, open Software, stay in the current fleet, select Add software > Custom package, and upload the Stable PKG. Software cannot be added to All fleets.Match the package to the same devices that receive the profile. Where software labels are supported, use the same label as the profile.For a pilot, open Hosts > the Mac > Software > Library, find Silmaril under Available for install, and select Install. Check Status or device Activity. Use the linked automatic-install policy workflow for broader rollout. Use Fleet’s supported software/package status for deployment, then verify version , build , and Guardian Disabled inside Silmaril.Expected result
Package status shows the Stable PKG deployed to the same targets as the profile, and Silmaril shows that version, build, and Guardian Disabled.If this differs
A package added under All fleets is outside this guide. Fleet deployment status is only the package result. Continue to launch and verify before calling the endpoint protected.
Package status shows the Stable PKG deployed to the same targets as the profile, and Silmaril shows that version, build, and Guardian Disabled.If this differs
A package added under All fleets is outside this guide. Fleet deployment status is only the package result. Continue to launch and verify before calling the endpoint protected.
5
Launch and verify
Open Silmaril on a pilot Mac and complete endpoint verification. The profile supplies the connection values. Package success or a Managed label alone does not confirm protection.Expected result
Endpoint verification shows the app identity, a Managed connection, and fresh Protection activity from a new agent session.If this differs
Keep the rollout on the pilot. Use troubleshooting. Restart required means fully quit and reopen the affected agent, then start a new session.
Endpoint verification shows the app identity, a Managed connection, and fresh Protection activity from a new agent session.If this differs
Keep the rollout on the pilot. Use troubleshooting. Restart required means fully quit and reopen the affected agent, then start a new session.
6
Update or replace policy
For an update, deploy only the intended Guardian Disabled version and update supported app/package metadata at the same time. Replace the existing profile while preserving all supplied profile and payload identifiers, UUIDs, and permissions. Never invent identifiers to bypass a conflict. Removing managed keys restores saved local preferences. Removing the profile does not uninstall Silmaril.Expected result
The replacement profile keeps its supplied identity, and the installed app is the intended Guardian Disabled build.If this differs
Put the supplied identifiers back and verify on a pilot host. Removing managed keys returns those settings to any saved local value. Removing the profile leaves Silmaril installed.
The replacement profile keeps its supplied identity, and the installed app is the intended Guardian Disabled build.If this differs
Put the supplied identifiers back and verify on a pilot host. Removing managed keys returns those settings to any saved local value. Removing the profile leaves Silmaril installed.
7
Uninstall
Pause every Silmaril software install for the target Macs so Fleet cannot reinstall the app. Leave the fleet and other software in place.Removing a label does not uninstall the app.Run the shared Uninstall through MDM script as root with the affected user signed in, and retain the JSON receipt and exit code. Exit 2 reports remaining items to review. It does not identify Guardian residue.Follow the shared result-handling instructions and remove only the Silmaril profile when policy should no longer apply. Leave baseline assignments and controls in place. Do not remove the fleet.Upload the script in Controls > Scripts, select the Mac under Hosts, then use Actions > Run script. Inspect the result in the host activity feed. Use a manual run rather than recurring policy automation for this removal. The removal action for this guide is the shared script. An action that only deletes the app bundle leaves the rest of the documented cleanup undone.If this differs
Read that exit code before running the script again. Keep this run manual.
Read that exit code before running the script again. Keep this run manual.