Transcript
Okay, so it's... Yeah, enrollment options. So, Setup Manager, we will start. Setup Manager Hardware is a nice monitoring tool for it. Going over Firefall software updates and the fairly new one, Managed Migration Assistant. Coming then later to Platform SSO. I think it's an interesting topic, this. And going also to the authenticated guest mode and tap to log in. And end up with a nice, also really new tool, Setup Checklist. And with this, I will hand it over. You only got one clicker. We have to share clickers here. Yeah. Setup Manager was shown earlier in the keynote, which was really nice, but we will go a bit more in depth here. It's a tool that we built internally out of self-defense. We were using other tools like DEP Notify, Shell Scripts to coordinate the enrollment. And at some point, we were like, well, there has to be a better way. So, that's how Setup Manager started out. There's a whole lot of different steps in the enrollment if you look at it closely. We have the enrollment itself, the approval of the management with automated device enrollment. Then there may or may not be a few steps in Setup Assistant. Then we get to the user creation, which is a very critical part. And in the end, we want – this is the goal, right? The productivity, to get the user to productivity as quickly, but also with a good experience as we can deliver. And we have tools to support that. Setup Manager supports and jumps in right after enrollment and installs apps and configurations and other things, including security tools. And we can have the compliance benchmark starting to run here right after enrollment. So, the device is secured, and you are getting the telemetry before the user even logs in for the first time, before the user even creates their account. Then, in user creation, we can use Jamf Connect, obviously, to create the user. We can use the built-in Setup Assistant just to create a local user. This depends on the workflow you want to use. But, of course, Apple now provides us the option to do platform SSO with the identity provider at the very first user creation right after enrollment. And then, once the user gets to their desktop and actually wants to start working, we have a tool to support that. They can use Self Service Plus to manage and update and do optional installs and some other self-help steps in there. So, we have tools all across the way to do these things. This is the general user experience that everybody calls Zero Touch, which I always think is a bit of a misnomer because the user does a lot of touching and clicking along the way. Its IT does not have to touch the device. We can drop ship the device to their home office or give it to their desk, and they control the entire experience. But there is a break in here that we can leverage and use, and we can say, well, this first part, this can be done by a tech. This can be done by somebody who is not the user, and it saves them a lot of time because this is the part that takes a lot of time, especially if you're installing Microsoft Office. And I'm not even mentioning Adobe or other tools here. So, this pre-provisioning step, that can be done by a different user. We like to call this Single Touch, but our friends in the Windows world call it pre-provisioning, and so that they recognize it, I use that too. So, what does this look like? This is a bit more involved than what you saw earlier in the demo. It also doesn't have the nice 3D animation, which I think was very cool, but it's not real. We're at the screen that all of you know. I clicked the enroll button, part of automated device enrollment. At this point, the device is reaching out, getting the information it needs to connect to the server, connecting to the server. You may have noticed in Mac OS 26 and higher that this is taking longer than you were used to before, and we will actually get into the detail on why this is taking a bit longer now later on in the session. It has to do with the simplified platform SSO, whether you're using it or not. But it is downloading all the profiles, it is downloading the setup manager package, and in our example, the company portal package, which is the platform SSO app that we are going to use to actually create the user. It is downloading and installing all of this, and you can see the small progress that Apple gives us in the background. And as soon as the setup manager package is downloaded and installed, setup manager kicks in and actually covers up setup assistant. Setup assistant is still there waiting in the background, doing its thing, but we are doing setup manager at the top. It waits for Jamf to figure out all the things. It actually runs an inventory update, a recon before it starts. There's a few things here. We can see the network status. We can see that network relay is up. There will be more information about how to secure a network with network relay later. I have about this Mac with enough information to identify the machine. I also see the elapsed time, which can be a good help for the user. If you hold the option key while clicking there, you get even more information. Download speed is also there, so you can see if a user is complaining, hey, this is taking forever, or you're on a really slow home network. I'm sorry, this will just take a while. We're downloading a lot. This is actually the real setup that I'm also using for the demo, and we have to install quite a few pieces of software here, which we're not going to wait for here. We will let that continue in the background, and it will be ready for us later when we continue. Yeah, and a fairly nice interface. It really didn't feel like it's a third-party cluttered interface, so it feels like it's a part of a setup system. Let's see what we can customize here, because it didn't have to look like that. First of all, you can put your company logo on top of it if you want, and you can also change the title, like welcoming or in your language that you want. You can also exchange the whole banner. Just put a company picture inside it, for example. On the message text, you see also we are greeting like on your new MacBook Air, so you can also use variables within that context as soon as they are available. Coming to the actions, it's policies mainly, policies running software installations, settings, but also, like we see here, Edge Keynote, we can deploy BPP apps, apps from our Jamf app catalog, and so on. Speaking on the interface, it's actually translated to 12 languages. There are coming new ones. I think at the moment, work is on Japanese and Chinese, and that's also done by volunteers. If you're interested to contribute to it, just contact Armin, or maybe if you found a mistake in your native language, we're happy to change. But speaking about this process, a lot of things can happen, break within enrollment, especially if you're testing and starting with a new tool. So logging things and seeing what goes wrong is really important, and so there's a big part in for logging also. So, so far, we focused on what it looks like for the user, and that's, of course, very important. We want to show this UI for the user. It should be simple. It should give them an idea of what's happening. It should be localized. But we also build this tool for ourselves, as I said earlier, so we also want to provide a lot of information for the admin, and one of the ways we provide a lot of information of what is going on during the enrollment is by logging. Setup Manager has a live log built in. You can hit Command-L to show the live log window. You have to click once to activate the window because that's the weird thing about Apple that we can't activate the window. Once in Setup Manager, hit Command-L. You will get this live log window. It will show the Setup Manager log live. It will also show the install log, the Jamf log, and information about profiles being installed. And because it's nice to have this not in three separate or four separate tabs, the relevant information out of the Jamf log and the install log will also be replicated in the Setup Manager log. It will also be logged to the unified system log and a file on disk, because in the end it's very easy to grab a log file and send it to support or to me if you don't see in the log what's going on. But this gives us a timeline of all the things and installations that are happening even if they're not controlled by Setup Manager because most of the time it's the stuff that is not controlled by Setup Manager that is giving us trouble. This is an amazing debugging tool, and we can see a lot of what is going on. Another thing that Setup Manager does that is transparent to the user is send out webhooks. It sends out a webhook when it starts and a second webhook when it finishes if you configure it that way. And in that webhook information is a lot of data about the workflow, all the information about the device, the computer ID, when did the workflow start, when did it finish, how long did it take. And we also get information about all the actions and whether they failed or succeeded. It comes in as a Java blob. We have dedicated webhooks for Slack and Teams because those are very common. This is a message in Teams that we can see. No, this might be Slack. I'm confused. One of the two. And they look pretty much the same. And we can use webhooks to do that. But there's also a generic webhook with a JSON blob, and we've used this together with middleware, but we've also seen that this is a bit complicated for many people to set up themselves. So Rob Potvin here, he built a tool called Setup Manager HUD, and he's very upset right now because this is an old video, and he's updated the interface since then. But still, he's working on a tool called Setup Manager HUD, Heads Up Display, where you can receive these webhook information blobs from Setup Manager. So you can see, I installed this many devices, were enrolled last week, and we had a failure rate on certain policies or not. Hopefully, you don't have a failure rate, but of course, for the demo, we have to show it. And if suddenly a certain action starts failing frequently, you might want to look into what's going on there. So Setup Manager HUD, it's a Cloudflare container that you can just deploy with one click. We are working on putting this in Jamf Concepts, and it should be out really, really soon. I'm really excited about this one. Free Cloudflare. Yeah, unless you have a really, really huge deployment, you should stay in the free range of what Cloudflare charges you for that, or you can use the container and deploy it somewhere else. So Setup Manager, the pre-provisioning workflow is an option. You can design it in a way that it works with full zero-touch, as we are used to, but also with pre-provisioning workflows. Very useful for MSPs or IT departments that work as MSPs in their organization. Very interesting for regulated industries. You can have your security tools in place and configured before the user is even created. For education, we have a different set of workflows that I didn't show in detail, but you can build full hands-off workflows. We can't say zero-touch because that's been used for something else. Full hands-off workflows with auto-advance and Setup Manager, where you really just send the wipe command to a classroom full of Macs, and they restart, and everything happens automatically without a tech having to move from device to device. You can build these kinds of workflows as well with Setup Manager. It works with Jamf Pro and Jamf School. All you need is the package in the pre-stage and a configuration profile in the pre-stage, and you can get all the information at jamf.it slash setupmanager or at concepts.jamf.com. Coming to the enrollment options. So enrollment options are things which are not built into Setup Manager. They are built into Setup Assistant. So basically speaking about these five things, some of them are really new. One of them are really, really new, the Managed Migration Assistant. And yeah, let's dive in. Auto-advanced. The feature was initially developed for Apple TVs to set them up in the conference room, but later on then also goes to Mac. And for a MacBook, you would obviously need an Ethernet connection, so a dongle to connect it. And it can click automatically through all these steps about the process. If somebody is sitting in front of it, do not touch it, because as soon as you're touching the mouse or the keyboard, it will stop, and you have to run manually through it. It will not break, but yeah, the auto mode will stop. Minimum OS. So if we are speaking about new things, mostly the thing is you need the latest OS for it. So you want to enroll a device, you may ship it maybe directly from the vendor, but then you didn't have the latest OS on it, and you cannot use the enrollment tool if you want to use. And what we can, or what minimum OS version can do, it's basically you can set up the latest major based on the device and so on, so that it's kind of a door-bouncer. So if it didn't have the correct OS that you have specified, it will get bounced back and have to do the upgrade. The nice thing, it works in conjunction with auto-advanced, so you can really completely automate the process if you have it wherever in a lab or something. And I would recommend to have a caching server. I have also one in my home lab, too. This can speed up the process if you're mass-deploying things. Obviously, you would not deploy a caching server in the home office of an employee, but yeah, it really is great if you're updating a lot of devices. Firefox, not new, but somewhat new in enrollment, but not a lot of customers are using it, actually. Directly within enrollment. I hope you're using Firefox at all. What's really great is you can directly have the device encrypted from the startup, and that's a screen it will show to the user. There's the option to show the key to the user. I would not do that because what users are tending to do if they are presented with an important key while in enrollment, maybe make a picture, print it out, put it in the bag, so the thief will directly have the MacBook in the key. Not the best option, but it is stored directly in the Jamf database. When you need it, you can access it every time. But as you see here, it's only a continue button. There's no cancel button. So it's not optional. It's mandatory then. And yeah, it does not need a lockout or restart like we know it. So it's directly startup from the enrollment on. Managed Migration Assistant. That's the really new one. Just mentioned last week in the What's New in IT video from Apple. And we all know the hassle. Migration Assistant is great. Everybody who's working longer with Apple and stuff, it's great to transfer all your data from one to the new device. And it works really great, but not really if you have a managed device. So we all know the hassle, what's happened then. It's migrating all the old management to the new device. And then, yeah, it's chaos. There were work around it, but it was not really nicely directly integrated into the system. And with the Managed Migration Assistant, we can choose which data gets transferred to the new device, and we can exclude things. And the nice thing is also the part where it's crashed with the management identity. It's well done in it, and it will work. How we can configure it? As it's a new feature, it's DDM. This is how it looks like in the future, because that's a screenshot from the new version, which will come out in some weeks. And there we can set up all the components we need. But I would like to step a bit from the past and show you another tool that we have on the concept page and how we can do it actually today if we want. That's the DDM Explorer, a tool that's also built of one of our engineers. It's directly connecting to the GitHub of Apple to show all available declarations. And here we can create our declarations. Like, for example, we are going to the Migration Assistant. Switch it on that we want to manage it. We can then also, like mentioned, exclude some accounts, like the Jamf admin or maybe a second one, the local admin that you still have on your device so that the user cannot migrate them over as their user. We can also exclude some passes like the download folder so that we did not get all the download thresholds to the new device. Maybe for some users it's not so good to do that, but it's more like an archive. And we can also make passes mandatory so that definitely the document folder and the desktop folder would get migrated to the system. And the last option is really interesting. We all know these annoying pop-ups like, hey, can Zoom access your camera? Can Teams go to your desktop? And so on. And with this, we can also ensure that also these privacy preferences get migrated to the new machine so the user for the software that he already did it do not have to do it again. So then we copy the JSON that we just created on the right side and go to our blueprints, create a new one, give it a name, manage migration. And in the component library, we are searching for the custom one. And if we put that into our blueprint, we can then just copy and paste the payload and the title to it and can deploy it. So this is a way how you can deal also with other new declarations that may be coming up in the future. So you can manage what gets migrated to the system. The new user gets MDM enabled, and it respects also the pre-staged account settings, like if it's getting an admin or a standard user. Coming to Platform SSO. This is the part everybody's here for, right? I'm going to tease you a bit further because Platform SSO itself isn't new, right? It's been around for a few years, and even more than that, it bases itself on the SSO extension, which has been around since Mac OS 10.15. Basically, the idea of the SSO extension back then was there is an identity provider app that is configured with a configuration profile, and any app that needs authentication, SSO authentication, can talk with the identity app, get a token, and then authenticate off to the service. Again, 10.15, this has been around for a while. I guess most people will be using this in one form or another. If you've configured this two years ago, well, three years ago at WWDC by now, for Mac OS 14, Apple introduced an extension to this, which they called Platform Single Sign-On, which extends the functionality to the login window. At the login window, the user can authenticate with their IDP credentials from whichever identity provider is configured in the Platform SSO profile, which is the same as the SSO profile with just a few more keys in it and settings, and it will set up the token in the identity app, so when I log in to Word or Outlook or a website that wants the SSO configuration, I don't need to log in again because I already did at the login window. The downside of this thing was I needed to have a local account and log in at least once and walk through the setup to make Platform SSO work in the future. I had this one-time setup that I needed to do. On a one-to-one device, it was really annoying, but on shared devices, it was even more annoying because it's something where the admin has to go in and touch. And then last year at WWDC... Oh, this is the summary. This is all the annoying things that I could do. I could have the password in the secure enclave, but I still needed that weird first account setup workflow. Often device and user registration were two parts of the same workflow, so I had to authenticate multiple times to set up my user and everything. So last year at WWDC, we got that missing piece, which was, yes, Platform SSO now works at setup. Apple calls this Platform SSO during automated device enrollment, but I've also seen simplified Platform SSO used a lot to explain this thing. And that means that in Setup Assistant, during the first enrollment, the IDP app actually kicks in. That's why we installed both Company Portal and Setup Manager in the pre-stage, because we need that IDP app there as soon as possible. And everything kicks in, and during the first setup, we get the Platform SSO experience without some weird extra workflows and steps. This needs to be supported by the identity provider. Right now, we have two of the major ones. Okta was out very early with 26.0. We at Jamf worked closely together with them to get this out early and working, so Okta Verify was one of the first. Microsoft took some time. But since May, since last month, their version of Company Portal, which supports this, is GA, so you can use this with Entra. We're going to use this with Entra today. Interestingly enough, there's two other solutions that can use Platform SSO or Simplified Platform SSO. From Tim Perfett at Tucanus, there's a tool called XPSSO, I think he wants to pronounce it X-PES-SO or something, which can serve as a proxy for Google authentication. Because Google is missing here on the big names, Google does not support either SSO or Platform SSO, but with XPSSO from Tucanus, you can proxy to Google if you want to do that. And there's an open-source solution called Keycloak for authentication, and the University of Oslo has built an open-source PSSO app that actually works really well. I've seen it demoed, and it's quite impressive that an open-source tool can do things that some of the majors have a hard time with. This is enough theory. Thomas will show us how it works. Yeah. So, fingers crossed. Do not use the Wi-Fi. No. We just finished Setup Manager, and if we continue, we are going back to Setup Assistant, and we are seeing the computer portals, so, like, PSSO from Entry ID. And if I hit Continue, I would just log in. It's always very exciting to watch somebody type live, but that's how you know it is live and real. Especially if I'm using normal other keyboard layout. Starting again. No. Our three attempts. Now it's working. Yeah, so, we are logged in, and now creating the local password here. Choose a simpler one here. And while this is creating it, just to mention why we are using a temporary password. You can use it. It's because we are sharing this environment for a lot of things here, and you can use whatever MFA, your provider that you're setting it up will use, so, just authenticate your apps or even to a hardware token, like you're used to. And we are creating a separate local password here, a local account for Secure Enclave, because this is a recommended way by Microsoft. It could also be a different recommended way by Okta or other providers, but this is what Microsoft is recommending for the PSSO setup. And I didn't touch ID. I hope I'm not sweating too much so it gets fast. It's impressive how fast it is. Done. Wow. I'm the light mode guy. Sorry. And we are not on the desktop. We have a nice welcome screen, which is a bit of a teaser for the next one. So the setup, the first user creation, aside from a bit of company portal UI that was in there, basically is part of the setup assistant workflow now and can be fully configured depending on what your identity provider does. In the Jamf Pro interface, as I said, these are just extensions on the original SSO profile, so if you have that setup, you need to go in there. There will be a few more keys in there, and the key one is to enable simplified setup for platform single sign-on, which is available on Mac OS 26 or later, and you have to give the bundle ID for the app that you want to use for the authentication here, and then, of course, you have to add that app installer to the pre-stage so it's there when setup assistant looks for it. Otherwise, you'll get a really nice error message. Not that that ever happened to me. There's a few great things that we've learned about debugging this. The first one is, and I said earlier, that the initial enrollment takes a bit longer, and there's a few reasons for this. One of them is we're installing company portal, which is quite a big package, actually, but the other thing is that there's more happening here, and Mac OS 26 changed when the bootstrap token gets escrowed into the device management service, and it does it much earlier now. It does it at enrollment. Before Mac OS 26, the bootstrap token gets created and is escrowed at user creation, which means that if we're in this weird interim time after enrollment but before the user is created on Mac OS 15 and something goes wrong and I want to wipe the machine from the server, I can't send that MDM command and I have to do a full do if you restore, which thankfully doesn't take that long anymore, but it's still more annoying than just sending a wipe command. So we have more flexibility here on Mac OS 26. You can send the wipe command much earlier, which is really nice. And if you have a managed local admin in pre-stage, which is not required anymore in Mac OS 26, but if you have one, you can quit out of setup assistant at the user creation. Say you messed up your PSSO deployment profile and it can't create the user, you can quit out of setup assistant at this point, log in with your local admin account and pull logs for debugging. Also very, very useful. Apple introduced something else at Mac OS 26, which is authenticated guest mode. It's kind of an extra option within simplified platform SSO, which means I can log in with my corporate credentials and it will create a temporary user account on my device. The data, the account are temporary. As soon as I log out, everything will be wiped from the device. So this is not for workflows that generate a lot of data on the device, probably not ideal for that. But for workflows where people are moving often from device to device, they're only logging into cloud services with a browser or with a local app, which we can do with the SSO token, this is a really great workflow. And tap to log in is an extension on this, where if you set up the Mac with an NFC card reader and your IDP is set up to log in with an NFC card reader, the user can walk up, tap their NFC card or their phone if that's set up, and it will log them into the Mac into a temporary authenticated guest mode session. There's a few customers who have this setup. Talk with our professional services. This is not trivial, but it's possible. Last week with WWDC, Apple talked about Platform SSO. They're working on it. There's new features coming in macOS 27 in the fall. We can require a Touch ID as well as the password for the user to log in. So this is two requirements to log in. The user has to provide the local password and Touch ID to log into a device for login and screen unlock. So we can enforce more security here once the devices are on macOS 26. Right now, for the FileVault unlock in macOS 26, we cannot require multi-factor authentication. With macOS 27, we will be able to do to require multi-factor authentication for the FileVault unlock, and you can use whatever your identity provider requires. And authenticated guest mode in macOS 27 will be able to support a FileVault at Mac, so the data on the Mac is also secured with macOS 26. Those two don't work together. So that is kind of our summary of features. Not all of these features are brand new. Some of them have been around for a while, but we've noticed that not everybody may be using them, and that's okay. Sometimes things come out, and you're like, oh, I can't use this until all my devices are upgraded, and then you forget. So this is the reminder. Yeah, speaking of that, so we are fairly complete, and we have our enrollment. We have the user creation. We can just start productively working on the device, but maybe there is something missing because there are things you have to, yeah, set up then, or the user have to set it up, and that's why this new tool comes up, Setup Checklist. You all know these annoying pop-ups I just mentioned. They are quite good because we know there are other operating systems which do all that stuff without acknowledging that. So it's good, but it's really annoying to do that, and especially, for example, if you're in the first Zoom meeting, and then, sorry, I have to log out and log in again because I didn't have a screen sharing on or something. So most employers then tend to have somebody sit aside you when they're enrolling. For example, the last employer I had a nice re-enrollment. It was just powered by Jamf, but somebody from IT still has to walk me through some steps I have to do afterwards, and one of them was, for example, this, and you can also have a one-pager. Lay a PDF directly on the desktop was the first step the employee has to do, but it would be nice to automate all that stuff. So that's why we come up with checklists, setup checklists, which can guide the user to that process, to do all those things, check also if the user has done it, but long story short, I think best is to see it in a demo. So we're back to our screen where Thomas left us after creating a account with Platform SSO, and this is actually the first screen of setup checklist. In Mac OS Sequoia, Apple introduced the nice welcome screen with a nice background, and all of us immediately turned it off because it wasn't configurable. So we now have a configurable welcome screen. You can put whatever text you want there. You can change the font. You can change out the background if you want to. This is a configurable welcome screen, and if you don't like it, you can skip it too. It's not mandatory. Misha spoiled the joke with this music in the keynote, but I was very proud of having this as my sample for my demos, and then we submitted it for the keynote, and Misha was like, what movie do we put in there? And I'm like, leave that one in there. Katie will understand the joke, and then marketing will switch it out anyway. They kept it, which, you know, everybody here has gotten their flashback to, what was it, 2012 when Leopard and Snow, 2010 when Leopard and Snow Leopard were out there. You can put a movie in this screen. You can put a custom movie with or without sound. You can control whether the sound plays or not. You can just put an image in there if you want. It is all customizable. Then we choose the desktop. Obviously, the user gets immediate feedback. A thing I would like to point out is that this is a dynamic desktop, which automatically adjusts to light or dark mode, and that's shown here with the icon, but we're going to choose this one for now. This just gives the user a chance to personalize the machine, but we also maintain our branding, and it's like, this is a managed machine. This is a work machine, but here are some nice work desktops. Of course, you'll have to find somebody in your marketing department to create some nice desktops for you, but we can do that. We want to configure the dock, and there's tons of tools out there that we can use to configure the dock, but they all happen in the background, and the user doesn't really get a choice. Here we can give the choice to say leave the dock as it is, but just add the work items to it or replace the entire dock with the work items, and they get a nice preview. There's a third option here is we could add leave the dock as it is and give that as a choice to the user, so you can configure which options they see, which options they get, and most of all, you can configure what happens in your dock. When we click that, you will see that the dock restarts because we need to do that when we configure the dock, and other tools need to do that too, and if you do that in an automated way, the user will have, after enrollment, a few seconds, they will have this moment where the wallpaper flashes and the dock restarts, and they're like, whoa, what did I touch? In this case, they know. They just said replace the dock. They know what happens. It's a much better user experience. Then we get to the default browser. Mithra showed all of these so far earlier. We'll get to some new stuff in a moment, but the user at this point, macOS decides this is an important thing. The user has to approve the default browser, and the user can be sneaky and say, I want to keep Safari, but then the continue button doesn't highlight, and they really have to go back and say, OK, I'm going to use Chrome. We can configure the default app view in different ways. We can give the user multiple choices. I have two here. You can go five, six, seven, if you install that many browsers or many labs. In this case, we're using Outlook, and then in the next step, we are launching Outlook, and this is a spot where I have to talk a moment, but also step away from the machine because this is a live demo, so I'm really not touching anything here. Microsoft Outlook can be configured with a configuration profile to configure itself using the SSO token, so it picked up the SSO token that we got from the platform SSO enrollment that Thomas did earlier, and once we go away from the privacy, we can see that, yes, it is configured. I'm seeing my email notifications. I can go into my Outlook and see that, yes, today is Jamf Nation Live. I hope I'm not late for that. So the combination of platform SSO and the right profiles and opening Outlook in the right moment just automatically configures everything for the users. Yes. Another thing that changed in 26.4, which is not so nice news for admins, is that Apple now requires the same approval that it does for the default browser for every default file type handler change. So if I want to switch to Acrobat Reader as the default PDF app on the system, the user will get this prompt. This started in 26.4. Security issue. Complain to the malware people who have been abusing this over the past few years. That made Apple think this is a required security step. The nice thing is with setup checklist, we can use this, and it's a much better user experience. Not sure why you would want to use Acrobat Reader over preview, but that's a different topic. And then we get to the screen sharing, the big one, right? We've all ran into this. You open Teams, and you want to share your screen, and you have to restart. You have to leave the session for a moment and come back. We can guide the user through doing the right thing right here. Setup checklist moves to the side. We have a small video that shows what they need to do. You could wait for multiple apps, not just Teams, if you have multiple apps where you would want to enable this entitlement on. The user, again, could choose to say, no, I'm not interested right now. What is this doing here? And we'll just come back up. So, again, the user has to do it at some point, and then the continue button highlights, and we can go to the next step, which is launching Teams. Again, there's these dialogues that pop up, but this is in context, and the user should, in this case, know better what to do. The experience in Teams is slightly different than in Outlook. I have to select the PSSO account that it auto-detected. I have to click once, but then it configures Teams, and I can go in here, and I can see there's a setup manager channel. I wonder what's in there. I talked earlier about the webhooks, and this user has access to the channel where the webhooks are posted to, so we can actually see the last enrollment of this device that was posted into the setup manager channel, and we can see that everything finished successfully. So, Teams is already there and fully configured. And then, in the end, we get a thank you screen. Again, you can configure that. Here we have a static image, but you could put another movie in there if you wanted to. And when we're done, we can hand it over to another app. It could be opening a website to your tech department or to your Mac help group or whatever you want to do as the next step. We generally think opening Self Service Plus is a good step here as the last step because then Self Service Plus, the user can do optional installs and other things. You can open to a certain category in here as well. Fairly complete. I think it's amazing. Definitely better than just this PDF on the screen. So, to have it in such an interactive way, when I saw it the first time, I was really impressed, and I hope to get out this music out of my head because that was awesome. Armin was showing it to me. The video starts. There was no sound, but I can hear it. Some of these workflows within that are a bit more complicated to set up, but there's a really interesting channel in the Mac App in Slack, so Jamf Setup Checklist. Check that out. A lot of people already sharing their workflows, how they are doing things like the Teams app or Outlook setup. And it's also translated. You see not so much languages like we have in Setup Manager, but if you're interested, volunteer. Get new languages in. And there's also new things to come in. They just worked on it, like, for example, accepting terms and conditions in that way. Yeah. So, we are fairly complete, I think. Should also be the only advice where the coffee machine is to found, but Jamf IT, Setup Manager, Jamf IT, Setup Checklist, check it out and start working with it. You can use one without the other. Checklist doesn't require Setup Manager or vice versa, but we think it's a very good combo and Platform SSO just fits right in. But if your provider doesn't do Platform SSO yet or if you still have to support Mac OS 15, then Jamf Connect fits in there in the middle, perfectly still as well. So, that brings us back to our overview from earlier. As I said, there's these steps during enrollment and we have a lot of tools that can enhance or supplement on each of these steps. Platform SSO from Apple is, of course, a very new, interesting development here. But all of these things together, the idea is that we have management, security, identity provider, everything is working together because these are, of course, requirements that we have to fulfill as the IT department. But we want to have these also work together in a way that is a really good user experience and gets the user to be productive earlier. We don't want to be the IT department of no, we want to be the IT department of go on, have fun. And with that, thank you very much. Thank you, Armin and Thomas, for that session. Unfortunately, we don't have any time for any Q&A.