Skip to content

pomme mdm

Enroll a VM in MDM from any state: create or finish it, finish retained SIP/AMFI work, prepare only the security enrollment needs, and enroll.

Repeat the same command to resume after a failure. Creation options apply only when the VM does not exist.

pomme mdm [FLAGS] [NAME] --profile PROFILE
Argument Description
NAME VM name. Uses POMME_VM_NAME when omitted.
Flag Description
--profile PROFILE Host path to the enrollment mobileconfig.
--guest-path GUEST_PATH Temporary absolute guest path for the profile.
--enrollment-mode ENROLLMENT_MODE Enrollment mode: supervised (user approved, default) or unapproved. Values: supervised, unapproved. Default: supervised.
--final-security FINAL_SECURITY SIP/AMFI after enrollment: restore (default) re-enables what enrollment disabled; disabled leaves it off. Values: restore, disabled. Default: restore.
-f, --force Allow owner creation and automatic login on a verified fresh VM without confirmation.
--dry-run Report the detected state and planned steps without changing the VM.
--skip-server-preflight Do not stop when the host cannot validate the MDM server’s certificate.
--from-template FROM_TEMPLATE If the VM is missing, clone it from this template.
--version VERSION If the VM is missing, install this macOS version, build, or latest.
--latest If the VM is missing, install the latest signed macOS. Same as --version latest.
--restore-image RESTORE_IMAGE If the VM is missing, install from this local IPSW.
--ipsw-device IPSW_DEVICE Apple silicon Mac identifier used to resolve --version.
--memory MEMORY Guest memory for a created VM (default 8GB).
--disk-size DISK_SIZE Disk size for a created VM (default 60GB; a template supplies its own).
--boot BOOT State of a created VM before enrollment, and after it: normal (default) or none. Values: none, normal, recovery.
--timeout TIMEOUT Time limit in seconds.

This command also accepts the common flags.


Generated from the help text of pomme 0.1.0 (2cde15f-dirty).