Why is my Mac trying to force me to enroll with Expedia Group upon installation?
apple.stackexchange.com
apple.stackexchange.com
The closest we can tell is that he sent his MBP off to Apple for repair and they swapped the logic board with a refurb unit that was swapped from one of our machines. There is some internal tool that rewrites the serial number and apparently nobody ever overwrote the serial number on the removed unit.
So anyway, there's two legitimate MBPs out there with the same serial number, although ours is probably decommissioned by now (I believe it was a 2015).
Was a funny journey figuring out what the hell was going on, though.
How could that be possible?
Apple's internal systems won't allow a second motherboard/computer with the same serial to even pass the post-repair diagnosis.
It doesn't literally have to be from the same factory, as it could be any one of the dozens of factories or hundreds of repair depots.
I'm not sure how the "Diag" board would have ended up in the hands of a customer. We note that the part was opened and used.
When you install a blank motherboard, you need to key in the desired serial number. If you make a mistake, you are supposed to ask apple to re-ship a blank and you take an oopsie on your record.
Someone did the oopsie, but it validated so they either never noticed or didn't feel the need to call it in.
Why is "you made a typo entering a serial number, so we're going to hard brick an expensive component" legal, especially in an age where politicians say they care about the environment?
It's a repair process presumably done by a certified professional who should know there is no margin for error. I really can't imagine this kind of error causing more damage than, for example, users throwing full cups of coffee over their expensive laptops. Should we ban drinking coffee close to expensive laptops too then?
I never learned what caused the issue.
Someone at Expedia would've needed the receipt for this laptop to get it enrolled, or someone at Apple fat fingered the serial number and accidentally enrolled that person's laptop?
Just install Apple Configurator on an iPhone and hold the phone close to the laptop at initial boot. It will show a sort of QR code and when you scan it it’s attached.
The initial detection will only trigger when it is in the “choose locale” screen, just after the very first “choose language” screen.
If you go beyond “choose locale” it will not work, even if you go back a step, and even if you reboot.
Then in ABM change the MDM platform to whatever you want (your Jamf instance) and Bob’s your uncle
"How do you do this sort-of complex business process to a new apple device?"
"Oh just install this app on your phone, then hold the phone next to the computer when you turn it on. No, don't open the app. No, don't lock the phone. No, don't click anything on the computer, lest you go too far."
Weeks into my new job, the IT folks contacted me and asked "Uh, did you ever get your laptop?"
Are we now saying a central authority can simply brick or forcefully install software on any mac at any time given only the serial number? What the actual fuck!?
Is this an OS feature or part of the "secure enclave" (Are macs entirely useless now or can you install Linux and still trust the device)?
Apple can brick or install an update to your computer even without MDM. For MDM you can not be spontaneously enrolled. In the article the user didn't notice this had been done until he reformatted his device.
With Macs, it’s more closely tied to the hardware because of course they’re integrated.
With PCs, Intune and Autopilot are Windows features that depend on hardware, but hardware alone isn’t sufficient. You can install and run Linux or DOS all you want on an Autopilot enrolled device, but every time you boot Windows it will want to phone home.
It’s fairly carefully controlled. With a PC, serial number is not sufficient. You need a device specific hash that is not generated and that you can’t get until you turn on the computer at least once, so you need physical possession at some point in the workflow.
With Macs, Apple more completely manages those first stages of enrollment. Devices are enrolled when sold through a B2B channel, or when manually enrolled through Business Manager.
Either way, it would be difficult for an adversary to assume control of a device without authorization. Not impossible, surely, but it’s definitely a scenario these vendors have anticipated and worked to prevent.
The good news for device owners is that it adds complexity to resale of a stolen device.
The bad news is things like OP’s situation occur.
Even if Apple are "the good guys" (now), we know they can be compelled by governments to do things quietly (see the push notifications thing that came up recently). So simply having the ability to remotely push software or configuration changes to any machine targeted by just a serial number is a big security hole.
This is very disappointing...
Naturally, that's not great either, but it's not quite the same kind of "not great".
Essentially, the device phones home during setup, and asks Apple whether it’s in Apple Business/School Manager. If it is, and it’s assigned to an MDM, Apple will let it know the host name of that server to try and prompt the user to enroll into.
And once that's burned into the UEFI, I'd like it plastered all over; maybe as part of the boot logo "This device belongs to Expedia"; there will be no risk of someone buying the device (perhaps on the used market) and not realize they don't own it.
Of course, there should also be an un-enrollment option for when companies decommission devices so they can be reused instead of just trashed, but that's an environmental concern not a security one.
2) YES.
3) Part of ... not specifically the Secure Enclave but the whole system. Hardware, firmware and software. You cannot bypass it.
Funny how these "mixups" always seem to benefit the company trying to control the user.
Also I'm not really sure what benefit you're saying Apple even gets here. They have to waste time confirming all sorts of details so they don't unenroll a stolen device from MDM. Just seems like it's nothing but a pain for everyone involved.
Would the computer be "bricked" by this or could you wipe it and install a fresh copy of MacOS?
(Edited: the comments indicates this is no longer possible)
>>>>Easily skipped .....by blocking connection to enrollment server
Probably not the avg user or engineer (though giving engineers admin account on their local OS is common). But that's hard to predict because usually you'd want to enroll, so I don't often see people trying to avoid it. Usually it's because of a bug. In my experience if the MDM process is buggy then it's more likely to be bypassable.
Setting a firmware password and blocking boot to external drives makes it harder, but a lot of orgs don't do it.
Last instructions I saw and tested said "install Monterey with no internet connection, open terminal, sudo nano /etc/hosts, add these three entries, save, close, upgrade to Sonoma".
That fully disabled MDM/DEP on an M2 MBP. Not sure if it would periodically ping after install/upgrade, but is about as clean as it gets, and for now survives OS upgrades.
During OS install the enrollment will just happen; the user's acceptance is not required.
I did it a couple years ago on a last generation Intel-based MBP to troubleshoot a problem caused by a particular piece of software installed by our IT team who, for various reasons, were unable to assist.
Caveat: I don't know if this is possible anymore on Apple silicon-based Macs because they apparently "require an internet connection to get firmware and other information specific to the Mac model."[^1]
The trick was to:
1. Use a freshly created bootable installer volume.[^1] (If previously setup, management software will often inject itself into the existing Recovery volume).
2. Prevent it from connecting to the internet, including any previously connected WiFi network it might remember.
3. Get it through the installation and initial user creation without being able to connect to the internet.
After that, it didn't pester me until the next reinstall.
On an Apple Silicon Mac you may have to install Monterey first, which doesn't require internet, do some incantantions, and then you can upgrade to Sonoma with no issue, and DEP/MDM bypassed.
(I wouldn’t want a laptop with this feature, but I can imagine the sort of people that administer MDM asking for it.
I wouldn't. A previous owner or manufacturer should never be able to brick hardware against the current owner's wishes.
I’d agree if it applied to normal consumer laptops (even if opt-out) but that doesn’t seem to be the case here.
I think if Apple went out of business the service that's causing this problem wouldn't even function anymore, because I believe it relies on the MBP phoning home during the setup process and being informed that it belongs to the Expedia MDM group.
This would then be why fixing it requires a call to Apple, rather than being something you can do simply by wiping settings on the device itself. (However, I don't know whether this means that booting it in a Faraday cage, or just with the internet disabled, after wiping device settings would allow bypassing it.)
I would assume Expedia buys in bulk so it’s possible all the serials that were scanned in could have had one or several serials entered wrong.
Generally when you buy a batch/bulk order, the last four will be different than the initial 8 for several dozen machines in that batch.
We wrote it off and removed it from DEP for the poor guy. The student was long since gone and we had depreciated it anyway, so it wasn’t a huge loss. We realised not doing so was also potentially a reputation issue for the school also.
We’ve since tightened up leaving processes so this is unlikely to happen again.
The decommissioning process should generally catch these situations, but it’s not foolproof, and not all organizations have robust decom procedures. A lot of Macs are managed by like a University IT dept, but procured and released by individual departments, for example. The school of business might not bother to notify central IT that they’ve let go of a bunch of old equipment, for example, and if they do it’s in some outdated spreadsheet, so the machines don’t get released properly. Things like that.
I acquired one of those weird lil' mini PCs that are all the rage, from Minisforum. The BIOS UUID was, essentially, 1-2-3-4-5, if we omit all the zeros. That UUID somehow tripped a fresh Windows install into Autopilot mode on the box to some random company that enrolled a similarly "blank" UUID in. I was absolutely befuddled and laughing my ass off once I figured out what happened... after the shock wore off of sitting at a Miratech Azure AD login.
... then dug out an AMI utility to go re-roll the RNG on the UUID since the OEM didn't do it and reinstalled Windows again and all was well in the world.
You'll also find this happens when you get a Mini PC with a sticker telling you "if you cannot log into your personal account, please turn off WiFi and LAN, select the skip option, and then log in"...
All they need to do is boot a damn flash drive. `AMIDEWINx64 /su auto` for the win... also thanks to Lenovo for accidentally leaving that executable in some BIOS updates.
What a coincidence! That's the same combination I have on my luggage.