Use this guide to configure your Mobile Device Management (MDM) tool to deploy Linewize Connect silently on managed macOS devices running Connect for macOS v4.
Note
To deploy Connect on macOS Sequoia devices, follow this guide.
You must have access to Configuration in Linewize Filter.
You must have Administrator permissions to complete the deployment steps.
Download the Linewize Configuration profile file.
Generate the customer PLIST.
Warning
Do not install the Connect for macOS v4 agent on users’ devices before creating and deploying a Configuration Profile and Mobile Config.
Steps
Download and install the Rosetta policy before deploying or upgrading Connect for macOS. If you don’t install the Rosetta policy first, you will see the installation prompt.
The Connect app installer can't detect the school's configuration, so standard users must grant permission for each feature on devices without Privacy Preferences Policy Control (PPPC). To use Classroom Manager features, apply PPPC configurations via MDM to user devices so standard users can approve screen recordings.
Configure PPPC profile
Standard users may be notified to approve the fc-system-service_darwin-amd64 application. You must configure the PPPC MDM configuration correctly.
Identifier |
/Applications/FamilyZone/MobileZoneAgent/bin/fc-system-service_darwin-amd64 |
Code Requirement |
identifier "fc-system-service_darwin-amd64" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "5S77G864UH" |
App or Service |
ScreenCapture |
Access |
Allow access |
classroom.plugin
Setting name |
Required Configuration |
|---|---|
Identifier |
/Applications/FamilyZone/MobileZoneAgent/bin/classroom.plugin |
Code Requirement |
identifier classroom and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "5S77G864UH" |
App or Service |
ScreenCapture |
Access |
Allow Standard Users to Allow Access |
If the PPPC is deployed successfully, the Screen & System Audio Recording permissions are turned on for Fc-system-service_darwin-amd64. You can check this in System Settings > Privacy & Security > Screen & System Audio Recording.
For the latest steps for configuring the PPPC profile, check your MDM’s documentation:
Jamf Pro -Privacy Preferences Policy Control
FileWave -macOS Privacy Preferences Payload
Microsoft Intune -macOS device settings in Microsoft Intune
Mosyle -Consult the vendor documentation
Apply PPPC Profile
See your MDM’s documentation for instructions to apply PPPC MDM configuration:
Jamf Pro -Privacy Preferences Policy Control
FileWave -macOS Privacy Preferences Payload
Microsoft Intune -Assign device profiles in Microsoft Intune
Mosyle -Consult the vendor documentation
Warning
Turn off Parental Controls in your MDM profile before deploying Linewize Connect. Parental Controls can interfere with filtering and block connections, such as Microsoft 365 login.
Configure the MDM tool using Jamf Pro
In Jamf Pro, select Computers > Configuration Profiles, then select Upload.
In the Upload window, select Choose File, then select the Linewize Configuration Profile file, then select Upload.
Important: After you upload the file, Jamf will show an error; follow the steps below to remove it.In the Options list, go to App-To-Per-App VPN Mapping.
In the Display Name field, enter Linewize VPN.
In the Options list, go to VPN > VPN Type, then select the VPN Type drop-down menu > Per-app VPN.
Select the Automatically start Per-App VPN connection checkbox.
Return to App-to-Per-App VPN Mapping, then select Per-App VPN > Family Zone Proxy.
Go to Restrictions > Preferences, then select Restrict items in System Preferences.
Select Disable selected items.
Select Network.
Select Save.
Deploy the Configuration Profile to your devices.
Manually configure the configuration profile settings
Only manually configure the Configuration Profile if you can’t use the Linewize generic Configuration Profile.
Configure App-To-Per-App VPN Mapping
Some MDM providers (e.g. Jamf Pro) require an additional App-To-Per-App VPN Mapping profile. Use the settings below to fill in the App-To-Per-App VPN Mapping details.
Field |
Entry |
Identifier |
com.familyzone.macappproxy |
Server |
Family Zone Proxy |
Provider Bundle Identifier |
com.familyzone.macappproxy |
User Authentication |
Password |
Password |
opendoor |
Provider Type |
App Proxy |
Designated Requirement |
anchor apple generic and identifier "com.familyzone.macappproxy" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists / or certificate 1[field.1.2.840.113635.100.6.2.6] / exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "5S77G864UH") |
Connection Name |
Family Zone Proxy |
VPN Type |
Per-App VPN |
Connection Type |
Custom SSL |
Configure System Extension
You must manually create the System Extension profile. Most MDM providers do not support uploading system extension profiles.
Allowed System Extension Types |
Allowed System Extensions |
Display Name: Network Extension |
Display Name: Network Extension |
Team Identifier: 5S77G864UH |
Team Identifier: 5S77G864UH |
Network Extension: Tick the checkbox |
Bundle ID:
|
(Alternative step) Upload Family Zone Root CA
Use this as an alternative step if the configuration profile is not compatible with your MDM.
Download the Family Zone Root CA certificate and upload it into your MDM.
Save and deploy the configuration profile
Follow your MDM’s instructions to save and deploy the configuration profile.
Download the Linewize configuration profile file and manually configure the Linewize generic configuration profile if it doesn’t work with your MDM type.
Go to Linewize Filter > Configuration > Agent Downloads.
Select Download PLIST. The PLIST will pre-fill the customer info into a PLIST file called com.qoria.connect.Application.plist.
Note
For parent-child configuration, please download the PLIST from the parent appliance.
You can deploy the PLIST manually or via MDM (Jamf Pro).
Manual deployment (individual deployment)
On the MacBook, go to Finder > Go > Go to Folder.
Select or double-click /Library/Preferences.
Add the PLIST to the /Library/Preferences folder.
MDM deployment via Jamf Pro
In Jamf Pro, navigate to the Computers tab > Configuration Profiles and select New.
-
On the Options tab > General section, complete the following fields:
Name - Add a profile name.
Description - Add an optional description.
Category - Set to None.
Level - Computer Level.
Distribution method - Install automatically
Expand Application and Custom Settings, select Upload, and click Add.
-
Fill in the details as:
Preference Domain : com.qoria.connect.Application
Property List: Add the PLIST
Important
Ensure the PLIST matches the details for the specific appliance or device.
Go to the Scope tab and add the scope for the deployment,
Select Save. The PLIST file should appear in the /Library/Managed Preferences folder.
-
Deploy the Connect for macOS .pkg file to your MacBooks, if it hasn’t already been installed.
Note
You can download the Connect for macOS installer from Linewize Filter > Configuration > Agent Downloads.
-
Verify the agent is installed correctly by going to Settings > Network.
Ensure:FZ DNS Proxy is Running.
FZ App Proxy is Connected.
Family Zone Proxy is Not Connected.
-
If the agent did not install correctly, ensure:
The Connect tray app is running.
A FamilyZone folder is on the device. If no folder exists, reinstall Connect.