How to fix the Issues in the Monthly Izzy Reports

How to fix the Issues in the Monthly Izzy Reports

Device Signature Report:  These are the most important systems to fix.  These systems are on-line and have checked into Izzy in the last 7 days but can’t communicate with our MDM server. We can’t push anything to these systems from the MDM (Crowdstrike, MMFleet, some app updates, security and configuration settings, etc.) until the MDM Profile is renewed.

 

MDM Client Problems: These systems could have any one of the folliowing issues: An Expired MDM client, no Bootstrap token, or flagged as having no “MDM Capability”. If the system is no longer in use, please delete the izzy record. Otherwise, please follow the renew/bootstrap fix instructions.

 

Incorrectly Formatted Drive:  “Erase Mac” should be used when wiping and reloading a Mac.  In some cases, Disk Utility in Recovery was used to incorrectly “erase” a hard drive, creating a second — empty — Data partition.   This extra Data partition should be deleted to reclaim some extra disk space. 

 

System Integrity Protection (SIP) Disabled:  By default, Macs ship with SIP *enabled*.  SIP keeps the operating system files from being touched by unscrupulous malcontents.   If a system is on this report, it means SIP was intentionally disabled by somebody at some point.  This can be a security risk.  There are valid reasons for disabling SIP, but they should be few and far between, so you should check with the user of the computer to find out why they did that and if they do not need SIP disabled — you should enable it!

 

Unknown Izzy Check-ins:  These systems were claimed in Izzy and may still need to be built.  If they have been built, there may be an issue with Managed Software Center that would need to be fixed.  Please check with the Mac Team in Slack for further instructions if the system is already in operation.   If the system no longer needs to be built for some reason, please delete the Izzy record.

  • The Fix:  

  1. Build it.  

  2. If it was already built, ask Mac Team for assistance.  

  3. If no longer needed, delete from Izzy.

 

Scheduled Update Failures: These are systems on which the scheduled macOS update was attempted to be installed a number of times and failed to install for a variety of reasons.   Please check to see if the system is on the MDM Problem report and — if so — renew the profile.  Otherwise, if it is not, please reboot the computer and manually install the latest OS update. Delete the machine from Izzy if it is no longer in service.

 

No 6-month Check-in: This report is just a list of systems that have not checked into Izzy for the past 6 months or longer.  If they are no longer in service, please delete them from Izzy. Otherwise, you should find them, resurrect them and upgrade the OS.

 

Additional Report Info

If a computer only has “UM-Support” in the SecureToken field and the only values in the “Reported Admin Users” column are “UM-Support” and/or “jamfadmin” — those may be computers you built at one point and then put on a shelf and could be a lower priority to look at.   Those computers usually will not have a “BootStrap Token Escrowed” because the UM-Support account likely has not been logged into after build (which is normal behavior.).  Once UM-Support logs in, the Bootstrap Token should escrow and be reported as such after an Inventory runs.   However — we can only report on “admin” users — so if there are no admin users, it may be in use — with a problem still!

Unrelated to the MDM Client issues in the reports, if a computer does not have “UM-Support” as a SecureToken account — and it was not an “at-home” build — you may have problems running the MDM renew process because it requires running the process from an account that has a SecureToken.  In those cases, rebuild the computer or delete it from Izzy if the computer no longer exists – especially any systems that list “No Users” for the SecureToken account