Legacy MDM script migration
This page is for an existing generated-script assignment. New deployments use the signed OS package:
This page is for an existing generated-script assignment. New deployments use the signed OS package:
Migrate
- Freeze the recurring legacy Code/IDE installer at its current group.
- Deploy the metadata-only computer profile, universal package, and root-only After-install token-staging script to a separate migration group.
- Require package receipt, running service,
enrollment_state=enrolled,hook_matrix.config_json=true, a valid device credential, expected hook coverage, and a fresh live Activity event. - Disable the old Code/IDE installer before expanding the package assignment.
- Keep only package-matched status and remediation helpers as recurring MDM checks.
Do not run a legacy installer and the package as competing primary installers. Self-test proves local reachability; it does not prove that an AI agent loaded a pre-execution control.
The universal reconciler replaces AgentKeeper-owned entries and preserves customer hook entries. Keep the separately deployed Cowork plugin and its assignment; the universal package does not install, migrate, or remove Cowork. Validate Cowork through its own setup guide.
Was this page helpful?