Skip to main content

macOS Software and Profiles

Deliver one harmless file to one Mac

For a first result, deliver a uniquely named, non-sensitive PDF to the Desktop on one approved test Mac. Use a file such as FileWave-Evaluation-Readme.pdf containing only a sentence identifying it as test content. Do not package a user's existing document. This exercise needs the native FileWave Client; Apple MDM is a separate connection used for supported profiles and Apple-managed app workflows.

Your result is a PDF at the intended destination that you can open on the Mac. A saved Fileset, model number, or Fileset status alone is not enough.

Before you start

Complete the Mac branch of Apple Manual Enrollment or ADE Enrollment. Match the test Mac's identity, native Client version, and recent communication in Central. If the Mac is MDM-only, prepare and verify the native Client before attempting file-level delivery. Review the chosen release's requirements rather than using this page as an OS support list.

Confirm the Mac has no file with your test filename at the destination. Use an approved lab Mac whose user Desktops may receive this test file. The All Users > Desktop destination affects user Desktops on the selected Mac; it does not mean only the logged-in user's Desktop. The device target must still be exactly one Mac.

Review inherited groups and existing Deployments. A new Fileset inside an already deployed Fileset group can broaden the work unintentionally. Keep this Fileset in an unassigned evaluation group. Agree on removal before deployment.

Privileged execution is the default for installers and scripts. On macOS, FileWave can run them as root. The first PDF exercise deliberately has no installer, script, restart, network change, account change, or security payload. A later PKG/app evaluation needs a trusted source, compatibility and disk-space checks, restart review, and a vendor-appropriate uninstall plan.

1. Create and inspect the Fileset

  1. In Central Filesets, select New Desktop Fileset > Empty and give it an evaluation name.
  2. Open the Fileset's Fileset Contents. If necessary, clear Hide unused folders to reveal destinations. Navigate to Users > All Users > Desktop, and add only your uniquely named test PDF there.
  3. Select the PDF and open Get Info > Verification. Explicitly choose Download If Missing for this exercise: verification restores the file if it is missing but does not replace an edited copy. Removal of this file-level Deployment removes the file, so it must not become a user's working document.
  4. Review initial-overwrite options and the exact destination. Do not rely on a default to protect an existing same-named file; use a collision-free test name. Review Fileset properties for unexpected scripts, restart settings, or additional content.
  5. Select Apply and close the editors. Wait for upload to finish. A Modified marker means pending work needs review and publication, not that the Mac already received the file.

2. Target and publish the test

In Deployments, create a named evaluation Deployment containing only this Fileset and only the verified Mac (or a group verified to contain just that Mac). Use + beside Clients for the Mac and + beside Filesets for the test PDF Fileset. Review the resulting count and identity, exclusions, and content. Expand Options, choose Direct Installation, and leave optional scheduling unset for this test. Select OK to save. The shared editor is explained in Fileset Creation and Deployment. Keep Kiosk self-service out of this first test.

Save the Deployment. Review shared pending work with the other administrators before Update Model. A test target does not make the model commit private. The Update Server Model dialog is confirmation only, not a pending-change preview. Record the resulting model number as publication evidence; device completion is the next check.

3. Verify at Central and at the Mac

Open the test Mac's Filesets Status tab and locate this Fileset. Read its status and any error; compare communication timestamps with your publication time. Active shows FileWave's recorded state, not independent application health. A script Success result would likewise not prove an app currently works.

At the Mac, confirm the uniquely named PDF appears on the intended Desktop and open it. Check its contents match the test document. Record the device identity, file path, observation time, and relevant Fileset status. A recent Client Last Connect is not the same event as inventory Last Connected. Do not press Verify as a passive refresh: it can process installation, removal, and repair work from the Client's manifest.

If the file is missing: check the exact target, Deployment activation, completed upload and Model Update, native Client connection, destination, permissions, and actual error. Wait for an offline Mac to reconnect before drawing conclusions. Do not switch to a fleet-wide group or deploy a privileged troubleshooting script to make the first exercise succeed.

4. Remove the test without removing user work

Confirm the file is still disposable, then remove the test Deployment from this Mac. Review and commit the resulting model change with the other administrators, wait for Client processing, and check that the PDF disappears from the intended destination. Keep a record if cleanup is pending because the Mac is offline. Do not delete shared Filesets or uninstall the Client just to remove one test file.

Download If Missing and Self-Healing file-level content is removed when its Deployment is removed; Ignore at Verify (Left Behind) content remains. Those file rules are not a universal PKG uninstall mechanism. PKG installers have no built-in uninstaller, and apps/scripts can create other data not represented in the Fileset. Review Fileset verification and safe removal before using either on real content.

Choose the next content type deliberately

Need Route and important limit
Vendor installer outside the App Store Import a trusted PKG using New Desktop Fileset > MSI / PKG or drag it into Filesets. Native-installer contents do not gain file-level Self-Healing. Verify the actual installed app/version and launch, and provide a tested uninstall route.
App Store app Prepare Apple MDM and Apps and Books, then review token/license and app-management settings. The native Client alone is not the Apple licensing/enrollment setup.
Files or a self-contained app bundle Inspect the destination and per-file verification behavior. An app dragged from a DMG may need moving to Applications inside the Fileset; do not assume its source path was appropriate.
Apple configuration settings Use a supported MDM profile payload. Test one approved payload, review defaults and removal consequences, and verify the installed profile plus effective setting. Do not start with network or security restrictions.
Customized installation captured from a machine Fileset Magic is an advanced capture workflow. Use a clean disposable capture Mac/VM and a separate test restore, not your daily workstation. Review captured data for secrets, licensing, and unrelated background changes.

Self-updating app caveat: Self-Healing may restore packaged files over an app's own updates. Download If Missing may be appropriate when the vendor's updater owns changes, but it still removes managed files when the Deployment is removed. Review both update and uninstall behavior before applying it to an app.

The optional sections retain the detailed import, licensing, verification, and snapshot examples. Older screenshots show previous Central/Admin interfaces, not current build or runtime acceptance evidence. The historical Applications>FileWave>FileWave Admin (root).app launch path is preserved for owner review; do not invent a renamed executable path or use it without confirming it exists in your installed release.

Optional detail and preserved examples

Optional profiles and trusted PKG import

Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.

macOS Filesets


The native FileWave Client can deliver files, app bundles, installers, and scripts. Apple MDM provides supported profile and Apple-management workflows. Installers and scripts run with elevated privileges by default; review restart, compatibility, storage, and removal behavior before a pilot. This is not an unlimited compatibility or capacity promise.

After preparing content, use Fileset Creation and Deployment for target review, saving, shared Model Update, and device-result checks.

Manage macOS settings using Profiles


Use Apple-supported MDM profile payloads for macOS settings. Test one approved payload at a time, especially network settings, and review all configured defaults and removal effects before combining payloads. Parameterized Profiles can insert inventory values with %custom_field% (generic notation only, not a complete field token; select a real variable such as %custom_field.asset_tag% and verify its resolved value); check the resolved value on the test device before wider use.

  1. Open FileWave Central and navigate to "Filesets".
  2. Click "New Desktop Fileset" from the black menubar and select "Profile".
  3. Name the Profile from within the "General" section and review other settings.
  4. Select your desired Profile Payload and verify it is compatible with your intended operating system.
    • Each Profile Payload is organized by supported platform, as indicated by the section heading.
  5. "Configure" the Profile Payload with any required fields.
  6. "Save" changes.
  7. You should now see your Profile Fileset in the "Filesets" view.
    • The Fileset will be labeled as "Modified" indicating pending changes that have not yet been committed.
  8. Review the Fileset and its scoped Deployment, save, then coordinate Update Model to publish shared pending changes. Verify the device result separately.

Profile General 2.png

Network Profile 2.png

Create a PKG Fileset


For vendor software not distributed through the App Store, a trusted PKG is a useful native-installer route. Its installed contents do not receive FileWave file-level Self-Healing. Verify the installed application and its launch separately, and prepare a vendor-appropriate uninstall plan.

  1. Open FileWave Central and navigate to "Filesets".
  2. Drag-n-drop your desired PKG directly into the "Filesets" view.
    • Or...
  3. Select "New Desktop Fileset" from the black menubar.
  4. Click "MSI / PKG" and select your desired PKG.
  5. You should now see your PKG Fileset in the "Filesets" view.
    • The Fileset will display in red text while it is being uploaded to the FileWave Server. Upload progress can be viewed from the bottom bar of the FileWave Central. 
    • The Fileset will be labeled as "Modified" indicating pending changes that have not yet been committed.
  6. Review the Fileset and its scoped Deployment, save, then coordinate Update Model to publish shared pending changes. Verify the device result separately.

PKG Fileset.png

Optional Apps and Books license allocation

Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.

Deploy VPP Filesets to macOS


Apple Apps and Books distributes App Store applications through its licensing and MDM workflow. Use a reviewed Deployment for the app Fileset. The optional reservation controls below divide license allocation; they do not prove app installation.

If you have not already, please review this section on the guide to learn more about how to sync VPP into FileWave and create VPP application Filesets.

Reserve VPP Licenses for Fileset

You can duplicate a VPP Fileset even when all its licenses come from a single VPP Token. This lets you divide license allocation for the same VPP application across separate Filesets and organize them into different groups. For example, if you purchase 10 Slack licenses through one VPP Token, you can allocate 5 to Development and 5 to QA, using a separate Fileset for each group's Deployment.

  1. Open FileWave Central and navigate to "Filesets".
  2. Duplicate your desired VPP Fileset.
  3. Double-click on one instance of the VPP Fileset.
  4. Check the box for "Reserve a maximum of" and fill out the maximum licenses available for that instance of the VPP Fileset.
  5. Repeat Step 3 & 4 for the other instance of the VPP Fileset, otherwise that instance may reserve the remaining available licenses. Reservation is not proof of installation; review actual allocation before deployment.
  6. Place each Fileset in an approved group and use a reviewed Deployment to target the intended devices. Group changes can expand deployment scope.

Slack Reserve Licenses.png

File verification, Desktop destinations, and app bundles

Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.

Deploy a file or folder with Self-Healing


File-level delivery can enforce a packaged copy or leave user changes intact, depending on Verification settings. Review both repair and removal behavior before choosing a policy. These options apply to managed files, not arbitrary third-party installer output.

Verification options

FileWave's "Verification" options allow you to granularly specify how each file in a Fileset deployment will behave. You can also set the "Verification" settings from a Fileset's Properties that will apply to all files within a given Fileset.

Historical timing note: The reboot and “24 hours (default)” timing in the older bullets below is not a guarantee of the current Client default. Confirm the configured verification interval for your release. A manual Verify can process other pending manifest work; it is not a passive refresh. The repair and removal behavior, rather than an assumed interval, is the reason to choose each option.

  • Self-Healing = Re-downloads file if modified or deleted upon device reboot, 24 hours (default), or manual "Verify". Removes files if Fileset disassociated.
  • Download If Missing = Re-downloads file if deleted upon device reboot, 24 hours (default), or manual "Verify". Removes files if Fileset disassociated.
  • Ignore at Verify (Left Behind) = Does not monitor file modification or re-download. Leaves files intact if Fileset disassociated.

Fileset Properties.png

PDF Get Info.png

Deploy PDF to every user's Desktop

  1. Open FileWave Central and navigate to "Filesets".
  2. Select "New Desktop Fileset" from the black menubar.
  3. Click "Empty" and name the Fileset accordingly.
  4. Double-click on the new Fileset to open the "Fileset Contents".
  5. Uncheck "Hide unused folders" if enabled.
  6. Navigate to "Users > All Users > Desktop".
  7. Drag-n-drop PDF file into the "Desktop" folder.
  8. Select the PDF and click "Get Info" from the menubar.
  9. Navigate to the "Verification" tab and select your desired Verification preference.
  10. Click "Apply" to save changes and Close the "Get Info" window and Fileset Contents window.
  11. You should now see your PDF Fileset in the "Filesets" view.
    * The Fileset will be labeled as "Modified" indicating pending changes that have not yet been committed.
  12. Review the Fileset and its scoped Deployment, save, then coordinate Update Model to publish shared pending changes. Verify the device result separately.

PDF Fileset.png

PDF Get Info 2.png

Deploy .app to macOS Applications folder

Since FileWave can deploy content at the file-level, we can also deploy an entire macOS ".app" directly to the macOS Applications folder and enable Self-Healing. This method is useful if you don't have the original PKG or the software is distributed within a DMG containing just the ".app".

  1. Open FileWave Central and navigate to "Filesets".
  2. Select "New Desktop Fileset" from the black menubar.
  3. Click "App / Folder" and select your desired ".app".
  4. Double-click the Fileset and verify the ".app" is in the "Applications" folder.
    • FileWave is context aware and will automatically add ".app" to "Applications" folder if it was originally in the "Applications" folder on the Admin machine.
    • If the ".app" comes from a location other than "Applications", such as a DMG, drag it into the "Applications" folder within the Fileset.
  5. Optionally, right-click the Fileset and click "Properties", choose your desired Verification preference, and "OK" to save changes.
    • You may consider using "Download If Missing" if the software is set to automatically update (ex: Chrome) to prevent software and FileWave from conflicting.
  6. You should now see your ".app" Fileset in the "Filesets" view.
    • The Fileset will be labeled as "Modified" indicating pending changes that have not yet been committed.
  7. Review the Fileset and its scoped Deployment, save, then coordinate Update Model to publish shared pending changes. Verify the device result separately.

App Fileset.png

App Fileset Properties.png

Advanced Fileset Magic capture — release/path review required

Historical reference for owner validation only. Do not execute commands, apply the old capability split, or launch a privileged capture from this section without a release-specific approved procedure. Hosted users perform no Server shell work.

Capture customized software installations using Fileset Magic


If an application's installer does not support the provisioning or customization your organization needs, Fileset Magic offers a file-level capture workflow. It uses a series of Snapshots from a "build" machine to capture a customized software installation for deployment with Self-Healing enabled. The customizations may include software preferences, licensing, updates, and shortcuts.

Advanced capture only: use a clean disposable capture Mac/VM, minimize unrelated activity, and review each captured difference. Confirm the historical root-app launch path against the installed release before executing this procedure. No capture or restore test was performed for this guide revision.

  1. Open "Applications>FileWave>FileWave Admin (root).app" and navigate to "Assistants > Fileset Magic".

  2. Select "Create Snapshot".

  3. Select the "Scan Volume".

  4. Select the "Scan Type".

  5. Wait for the File scan to complete.

  6. Install your desired software without proceeding in Fileset Magic.

    • Open, update, license, and customize your software.
  7. Click "Continue" to proceed in the Fileset Magic window.

  8. Select the disk volume where the snapshot was taken.

  9. Wait for Fileset Magic to scan the selected volume and compare file changes.

  10. View the File differences and select only what is necessary for the newly installed application.

    • Background macOS activity may be captured. Exclude unrelated changes, credentials, private keys, personal data, and machine-bound licensing before importing the Fileset.
  11. Choose either to Save or Export the Fileset.
  12. Wait for the Fileset to be uploaded to the FileWave Server.
  13. Verify your Fileset Contents within the FileWave Central.

1

macOS Fileset Magic Create Snapshot.png

2macOS Fileset Magic Select Scan Volumes.png

3

macOS Fileset Magic Select Scan Type.png

4

macOS Fileset Magic Scan.png

5

macOS Fileset Magic Install Software Now.png

6

macOS Fileset Magic Skype for Business.png

7

macOS Fileset Magic Create Fileset from Snapshot.png

8

macOS Fileset Magic Scanning for Differences.png

9

macOS Fileset Magic File Comparison.png

10

macOS Fileset Magic Save or Export Fileset.png

11

macOS Fileset Magic Fileset Import.png

12

macOS Fileset Magic Fileset Contents.png