Scenarios
Before buying a used Mac
Check the serial number before you buy:
./unleash predict ABC12345678 # check serial against known org prefixes
./unleash check # is this Mac safe to wipe?
predict looks up the device serial against known MDM org prefixes.
If it matches JAMF, Mosyle, or another org, you know what you’re dealing with before you buy.
Recovery after Migration Assistant
- Fresh install macOS on a new Mac
- Migration Assistant copies your old data
- MDM appears within minutes of login
Fix: Boot to Recovery and run:
./unleash suppress
Or bypass if you need a new admin user. This removes the DEP markers,
user-level artifacts, and MDM preferences that MA transferred over.
This is the #1 case most other tools miss — Unleash handles it.
macOS update brought MDM back
- System update restores enrollment daemons automatically
- MDM block in
/etc/hostsis often preserved
Fix:
sudo ./unleash heal
Re-disables daemons and re-checks all layers. If you ran persist
before the update, this happens automatically on the next boot.
Buying a former office Mac
- The serial might still be in the company’s ABM
- Even after a clean wipe, connecting to Wi-Fi at Setup Assistant triggers enrollment
Strategy:
- Boot to Recovery without connecting to Wi-Fi
- Run
unleash bypassbefore the device ever phones home - Run
unleash persistandunleash whitelistso it stays clean - Only then connect to the internet
The serial stays in ABM forever — but as long as the device never connects with full protections removed, it will not re-enroll.
Used Mac that already has a user logged in
sudo ./unleash audit # check current state
sudo ./unleash harden # kill MDM processes immediately
sudo ./unleash whitelist # block MDM while keeping iCloud
sudo ./unleash persist # survive future updates
Setting up a new Mac before first boot
- Boot to Recovery without Wi-Fi
- Run
unleash init— interactive wizard - It will: suppress MDM, install persist, install whitelist, run audit
- Reboot, set up normally, MDM never bothers you
Org-provided Mac (must enroll on VPN only)
Some organizations require the Mac to enroll but only when connected to the corporate VPN.
sudo ./unleash vpn-kill
This installs a pf kill-switch that blocks MDM traffic when the device is NOT connected to the VPN tunnel. MDM can only communicate through the encrypted VPN connection.
After a full DFU/IPSW restore
A DFU restore erases everything but doesn’t remove ABM assignment.
- Restore via Apple Configurator 2
- Do not connect to Wi-Fi
- Boot to Recovery
- Run
unleash bypass - Run
unleash persist && unleash whitelist - Reboot and connect to the internet safely
Automated deployment (IT admins)
For deploying across multiple machines:
# Scripted bypass
./unleash suppress --log-file /var/log/unleash-deploy.log
# With persist + monitor
sudo ./unleash persist
sudo ./unleash monitor
# Audit report in JSON
sudo ./unleash report --json
# Discord alerts
sudo ./unleash discord-bot <token> <userId>