Documentation Get help

Deploy Flowstate Desktop for Mac with MDM

This guide is for IT. Flowstate Desktop for Mac works with or without device management. With MDM, people get no extension prompts. They only sign in and trust the certificate. Without it, each person completes the three setup steps.

You can use Jamf, Kandji, Intune or another MDM tool that supports configuration profiles.

Before you begin

1. Download the installer

2. Prepare the profile

Ask your Flowstate contact for the sample profile, flowstate-mac.mobileconfig. It has two payloads.

PayloadTypeWhat it does
System extension policycom.apple.system-extension-policyApproves the Flowstate network extension, inc.flowstate.mac.netproxy, for Team ID VC94Q6RPKS. macOS doesn’t ask the person to allow it.
Transparent proxycom.apple.vpn.managed, with VPNType set to TransparentProxyCreates the proxy configuration, so the person isn’t asked to add one.

You don’t need a web content filter payload.

Then:

  1. Generate fresh PayloadUUID values with uuidgen.
  2. Change the organisation name.

You can split the two payloads into two profiles. They don’t depend on each other.

3. Deploy

  1. Upload the profile to your MDM and scope it to your pilot Macs.
  2. Deploy the Flowstate package so the app lands in /Applications.
  3. Check one pilot Mac. Open Flowstate. The network extension is already on, so the person only signs in and trusts the certificate. After that, Flowstate runs from the menu bar.
  4. Widen the scope to every Mac.

What people still do

  • Sign in. Each person signs in with their own Flowstate account, once.
  • Trust the certificate. macOS needs the person’s approval to trust a user-installed certificate. To skip this step, push the Flowstate certificate authority with a com.apple.security.root payload. Your Flowstate contact can send the public certificate before rollout. After the extension is on and the app has run, it’s also at ~/Library/Application Support/Flowstate/ca.pem.

Remove Flowstate

  1. Take the Macs out of the scope of the profile and the package.
  2. Delete the app.
  3. If the extension or certificate stays behind, remove them in System Settings and Keychain Access.