Apple update approach 'not realistic' in enterprise, but login 'shim' gets thumbsup
- Reference: 1655721908
- News link: https://www.theregister.co.uk/2022/06/20/jumpcloud_survey/
- Source link:
JumpCloud provides identity services, which is why chief strategy officer Greg Keller zeroed in on the feature, which his company details further in its latest IT trends report.
The result, said Keller, was "an even more powerful login experience into these devices."
[1]
Despite the new feature (which JumpCloud said had been flagged up in previous iterations of WWDC, showing a level of openness perhaps rarely associated with the usually secretive Cupertino company) "we were anticipating some new deeper API hooks that didn't materialize" and a "broadening of Apple Business Manager."
[2]
[3]
For enterprise users seeking to manage fleets, those hooks are important. Although tooling in the Windows world might struggle with zero-touch deployments, doing the same with Apple hardware presents less of a challenge.
Maintaining the machines, however, is a different story. Apple's approach is to ask the user to confirm their identity before anything can be done to a system.
[4]
"In situations like that, this is where Apple demonstrates they don't have a deep appreciation of the enterprise," said Keller. It's OK for consumers, but not realistic in the enterprise, he said. "Windows," he added, "is infinitely better in the that regard … it's 35+ years of Microsoft understanding how IT teams work in the enterprise."
[5]
Greg Keller Pic: JumpCloud
To be fair to Apple, the [6]Bootstrap Token functionality would be a possible approach, but it could hardly be desribed as an elegant solution.
Principal product manager for Apple at JumpCloud, Tom Bridge, noted that "The Bootstrap Token ... only has utility when it comes to the forcible install of updates, not in user-lead experiences.
"Apple's experience for forcible install," he continued, "leaves a lot to be desired from a user experience perspective, as there's little to no warning, and no way to cancel, and frequently no way to save your work before your apps are force quit, your login session is terminated, and your data can be lost.
"It's painful, and could have resume-generating consequences for your IT practitioner if this happens to the C-Suite users without a whole lot of hand-holding."
[7]
Ouch.
"We want to do this only [as] a LAST resort, and we'll support this in the coming months, not just for forcible updates, but also for major version updates of macOS."
[8]The Register spoke Bridge earlier this year about the challenges of patch management and, it appears, the product has struck a chord with customers who, according to Keller, "just hit the proverbial Buy Now button."
Later this year browser and third party update management is due to be added to the suite.
Nearly 4 in 10 IT managers made users responsible for clicking 'update' on patches
Looking at JumpCloud's Q2 2022 SME IT trends report, security remains a focus, with 59.4 percent of the more than 1,000 IT decision-makers that responded describing it as their "biggest concern," followed by device management at 48.1 percent.
Considering Keller's comments above, 39.4 percent made users responsible for patch management (or at least clicking the update button when prompted,) which suits the Apple view of the world.
[9]The march of Macs into the enterprise: Demand is on the increase
[10]Intune out of tune after an Android 12 update? Help's coming
[11]Microsoft admits Samsung phones under Intune mobile device management are dropping out of compliance
[12]EU digital rules must consider anti-competitive licensing terms, say cloud sellers
The vast majority of administrators also reckoned that remote workers were better at following best security practices now than they were at the same time last year.
A majority (62.6 percent) also regarded passwordless authentication as priority (although just over half felt it was still more an industry buzzword.)
As well as metrics showing remote and hybrid working starting to drop a little in favor of full time office work (47.1 percent are back in the office full time compared to 40.1 percent a year ago) the report also showed up some intriguing geographical differences. 15.2 percent of UK admins disagreed that they were happier in their job versus 9.7 percent of US counterparts. And more UK administrators had suffered budget decreases.
Both UK and US IT decision-makers... 'tend to overwork'
Keller noted that both UK and US IT decision-makers were similar: "we tend to overwork, believe it or not," he said before wondering if the more reserved psyches of UK workers might be resulting in a "Don't bother me, I'm in the hurt box" mentality and the resulting differences in overall happiness.
A tricky one, and the impact of the last few years on IT teams will continue to reverberate for several years to come.
As JumpCloud looks to expand beyond keeping an eye on identity and patch management, the survey also threw up the phrase "tool sprawl" and noted that 38.2 percent of teams use three or more tools to manage the employee lifecycle. It said 43.7 percent of employees need six or more accounts just to get their jobs done.
And as for hardware? Device diversification appears to be on the increase. While over 40 percent of respondents expected their Windows device count to increase, just over 30 percent reckoned macOS devices would also be on the rise.
Windows devices also accounted for a higher proportion of breakdowns (at 68.1 percent compared to 58.2 percent) while macOS fell from 24.6 to 20.2 percent. ®
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrCZqXqjsemhEVcXxJv2IQAAAI8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrCZqXqjsemhEVcXxJv2IQAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrCZqXqjsemhEVcXxJv2IQAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrCZqXqjsemhEVcXxJv2IQAAAI8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://regmedia.co.uk/2022/06/15/greg_keller.jpg
[6] https://support.apple.com/en-gb/guide/deployment/dep24dbdcf9e/web
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrCZqXqjsemhEVcXxJv2IQAAAI8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/02/03/jumpcloud_patches/
[9] https://www.theregister.com/2022/04/04/apple_silicon_enterprise/
[10] https://www.theregister.com/2022/03/08/android_12_intune/
[11] https://www.theregister.com/2021/11/12/intune_compliance/
[12] https://www.theregister.com/2021/10/26/microsoft_oracle_cloud_costs/
[13] https://whitepapers.theregister.com/
Re: "Apple demonstrates they don't have a deep appreciation of the enterprise"
So, it's a little more nuanced than that. Admins have the flexibility of when updates are installed, even including the scheduling of updates. JumpCloud are new to MDM to I'd give their comments a little latitude
However, surely it's better than, "I'll just reboot windows before this important ca,,,,,, WTF? Why are you installing updates that you didn't tell me about NOW?!"
Re: "Apple demonstrates they don't have a deep appreciation of the enterprise"
@Pascal
I run my business on Macs and, like you, also for personal use. I have just looked (in system preferences/software update v12.4) and automatic updates has to be switched on, and even then you have various choices.
TL:DR, you choose when to update not Apple.
Cheers... Ishy
Doesn't seem to be the case from the article.
And if you have to go check your OS settings to ensure that you do not lose work, well I'm not impressed.
But don't worry, Borkzilla's AutoPatch is sure to bring us much entertainment in not so long.
Re: "Apple demonstrates they don't have a deep appreciation of the enterprise"
If you're a company with more than a few machines you will want to make sure that security patches are installed in a timely manner, ie. in a manner that you control but reduces the surface for attacks. You can only do this with some kind of management software. Users may still have some control but if, say a week after you've approved and depoyed patches, they still haven't updated, it may be time to have a word: it's a company resource and the risks are to the company.
WSUS will at least give you information about the OS but you'll generally need something more comprehensive to include all the standard software.
Link?
Shouldn't there be a link to the report the company is touting?
Apple permissions
-> Apple's approach is to ask the user to confirm their identity before anything can be done to a system.
That might be one reason why Apple is less susceptible to malware generally than the Windows insecurity model. I'm not suggesting that Apple is perfect, they have plenty of problems. But compared to Windows it's Apples and windows.
"Apple demonstrates they don't have a deep appreciation of the enterprise"
Ouch.
That said, I'm sorry but even as an individual user, I don't appreciate the idea of losing everything I am working on because somebody else decided I have to update now .