Fleet with MDMLegacy scripts

Legacy MDM script migration

This page is for an existing generated-script assignment. New deployments use the signed OS package:

This page is for an existing generated-script assignment. New deployments use the signed OS package:

Migrate

  1. Freeze the recurring legacy Code/IDE installer at its current group.
  2. Deploy the metadata-only computer profile, universal package, and root-only After-install token-staging script to a separate migration group.
  3. Require package receipt, running service, enrollment_state=enrolled, hook_matrix.config_json=true, a valid device credential, expected hook coverage, and a fresh live Activity event.
  4. Disable the old Code/IDE installer before expanding the package assignment.
  5. Keep only package-matched status and remediation helpers as recurring MDM checks.

Do not run a legacy installer and the package as competing primary installers. Self-test proves local reachability; it does not prove that an AI agent loaded a pre-execution control.

The universal reconciler replaces AgentKeeper-owned entries and preserves customer hook entries. Keep the separately deployed Cowork plugin and its assignment; the universal package does not install, migrate, or remove Cowork. Validate Cowork through its own setup guide.