Skip to main content
Resolve the relevant state below for Stable (build ), then repeat endpoint verification.

No Managed label

Confirm the completed device or system profile was delivered to that Mac, the scope includes it, and the imported custom payload contains the intended application setting. Expected result
API URL, API key, and any other forced settings show Managed in Silmaril.
If this differs
A profile that is merely assigned, or a payload that lost the application settings on import, will not show Managed. Export the stored profile and compare it with the completed Silmaril-Managed.mobileconfig. Jamf can change an unsigned import. Direct installs store a typed key in the login Keychain and do not show Managed unless a profile is also installed.

Needs attention

Fix the type, value, or dependency using the 17-key reference, then replace the profile while preserving its identity. Expected result
After the corrected profile is installed, the setting leaves Needs attention and shows Managed.
If this differs
Invalid managed input does not fall back to a saved local value. Check required pairs, especially a forced API key with a forced valid HTTPS API URL, accepted modes shadow, warn, or block, and known agent identifiers. Keep every supplied identifier and UUID.

Connection failed

Customer IT confirms the exact supplied URL and credential in the profile, replaces the profile if either is wrong, checks network reachability, and asks Silmaril to confirm the deployment values. Expected result
The profile contains the URL and key Silmaril supplied for this deployment, and the first-run connection screen reports Firewall connection verified when that screen is displayed.
If this differs
Replace the profile with the corrected URL and key together. Use the values supplied for this deployment. Template placeholders are not valid credentials.

Restart required

Fully quit and reopen the affected agent, then start a new session. Expected result
Current activity appears in Protection using the new policy.
If this differs
An agent that was only backgrounded is not the restart this state requires. Quit it fully, open it again, and start a new session before judging Protection.

Notifications missing

Confirm Notifications is enabled in Silmaril and in macOS System Settings > Notifications. Expected result
Both the Silmaril preference and the macOS notification permission allow notifications.
If this differs
silmaril.protectionNotificationsEnabled controls the app preference only. macOS notification permission is separate. The universal template includes a notification payload, and that payload still does not replace the macOS authorization check.

Applying persists

Relaunch Silmaril, confirm the latest profile is installed, then contact Silmaril Support if the state remains. Expected result
After relaunch, the setting finishes applying and shows Managed.
If this differs
Confirm the latest completed profile is the one installed, then contact Silmaril Support. Leaving the Mac on Applying means that setting is not confirmed.