Deploy Flowstate Desktop for Mac with MDM
This guide is for IT. Flowstate Desktop for Mac works with or without device management. With MDM, people get no extension prompts. They only sign in and trust the certificate. Without it, each person completes the three setup steps.
You can use Jamf, Kandji, Intune or another MDM tool that supports configuration profiles.
Before you begin
- Your Macs run macOS 14 or later.
- Your security and compliance teams have approved what’s captured. See Data residency and what’s captured.
- Your network lets Macs reach Flowstate. See Troubleshooting.
1. Download the installer
2. Prepare the profile
Ask your Flowstate contact for the sample profile, flowstate-mac.mobileconfig. It has two payloads.
| Payload | Type | What it does |
|---|---|---|
| System extension policy | com.apple.system-extension-policy | Approves the Flowstate network extension, inc.flowstate.mac.netproxy, for Team ID VC94Q6RPKS. macOS doesn’t ask the person to allow it. |
| Transparent proxy | com.apple.vpn.managed, with VPNType set to TransparentProxy | Creates the proxy configuration, so the person isn’t asked to add one. |
You don’t need a web content filter payload.
Then:
- Generate fresh
PayloadUUIDvalues withuuidgen. - Change the organisation name.
You can split the two payloads into two profiles. They don’t depend on each other.
3. Deploy
- Upload the profile to your MDM and scope it to your pilot Macs.
- Deploy the Flowstate package so the app lands in
/Applications. - Check one pilot Mac. Open Flowstate. The network extension is already on, so the person only signs in and trusts the certificate. After that, Flowstate runs from the menu bar.
- Widen the scope to every Mac.
What people still do
- Sign in. Each person signs in with their own Flowstate account, once.
- Trust the certificate. macOS needs the person’s approval to trust a user-installed certificate. To skip this step, push the Flowstate certificate authority with a
com.apple.security.rootpayload. Your Flowstate contact can send the public certificate before rollout. After the extension is on and the app has run, it’s also at~/Library/Application Support/Flowstate/ca.pem.
Remove Flowstate
- Take the Macs out of the scope of the profile and the package.
- Delete the app.
- If the extension or certificate stays behind, remove them in System Settings and Keychain Access.