Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

[Intune] Deploying a .pkg file to MacOS clients where a configuration.json is required?


Recommended Posts

Posted

We want to deploy FreshWorks' discovery agent to MacOS clients. The problem is the .pkg file comes with an associated configuration.json file containing parameters that I assume need passing to the installer (AccountURI and RegistrationKey), and I can't see a way of providing that information to intune? I can load in the pkg no problems, but that's it. 

 

I've seen some chatter about using pre/post-install scripts, but nothing that actually explains how to do it. Alternatively, I've seen discussions around using application configuration profiles, but those only seem to be applicable for mobile clients (iOS, iPadOS and Android). 

 

Anybody got a hookup to a decent guide that explains how to achieve this? Or know if it's even possible? Macs, er.. ain't my strong point.

 

Posted

claudeai says
 

DEPLOYING THE FRESHSERVICE DISCOVERY AGENT TO macOS WITH INTUNE
================================================================


THE PROBLEM
-----------
The FS-Agent.pkg comes with a configuration.json file. That file holds
the AccountURI and RegistrationKey. Intune has no option to pass these
to the installer.


THE SOLUTION
------------
You don't need to pass anything to the installer.

Let the PKG install as normal. Then use an Intune post-install script
to write the config file to the place the agent actually reads it from:

    /Library/Freshservice-Agent/Freshservice-Discovery-Agent/conf/Configuration.json

The agent runs as a LaunchDaemon from:

    /Library/LaunchDaemons/freshservice.agent.daemon.plist


STEPS IN INTUNE
---------------
1. Go to Apps > macOS > Add.

2. Choose "macOS app (PKG)".
   (Do NOT use "Line-of-business app". Only the PKG type supports
   pre-install and post-install scripts.)

3. Upload FS-Agent.pkg.

4. On the scripts step, paste the script below into the
   POST-INSTALL script box. It runs as root.

5. Assign to a test group first.


POST-INSTALL SCRIPT
-------------------
Replace the JSON section with the exact contents of the
configuration.json file Freshservice gave you. Key names are
case-sensitive, so copy and paste rather than retyping.

------------------------- START OF SCRIPT -------------------------
#!/bin/zsh
CONF_DIR="/Library/Freshservice-Agent/Freshservice-Discovery-Agent/conf"
PLIST="/Library/LaunchDaemons/freshservice.agent.daemon.plist"

mkdir -p "$CONF_DIR"

# Paste the exact contents of your configuration.json below
cat > "$CONF_DIR/Configuration.json" <<'EOF'
{
  "accountUri": "https://yourtenant.freshservice.com",
  "registrationKey": "YOUR-KEY-HERE"
}
EOF

chmod 644 "$CONF_DIR/Configuration.json"

# Restart the daemon so it picks up the config and registers
if [[ -f "$PLIST" ]]; then
  launchctl bootout system "$PLIST" 2>/dev/null
  launchctl bootstrap system "$PLIST"
fi
exit 0
-------------------------- END OF SCRIPT --------------------------


TESTING ON A MAC
----------------
Before a wide rollout, install on one test Mac and confirm:

1. The config file is in place and correct:
       sudo cat /Library/Freshservice-Agent/Freshservice-Discovery-Agent/conf/Configuration.json

2. The daemon is running:
       sudo launchctl list | grep freshservice

3. The device appears in Freshservice.

If the conf path is different on your agent version, update the
CONF_DIR line in the script to match.


SECURITY NOTE
-------------
The registration key sits inside the script, so anyone with Intune
app admin rights can read it. This is usually acceptable, but worth
knowing.


FALLBACK OPTIONS
----------------
If the post-install script method gives you trouble:

Option A - Repackage
  Build a new PKG with the JSON already placed in the right folder,
  using Composer, pkgbuild, or Whitebox Packages. Upload that to
  Intune instead.

Option B - Shell script
  Deploy an Intune macOS shell script that runs "installer" itself
  and then writes the config file.

Both work, but the PKG + post-install script method is the cleanest,
and Intune still handles detection through the package receipt.

Posted (edited)

I'm hesitant to just slap AI vibecode into our Entra without fully understanding what it does - macs/bash really isn't my forte

Don't suppose it gave you an actual source for that that I could read up a bit more on it? 

 

Edit: Another member has kindly broken down/sense checked the script, and that's worked. Much appreciated.

(Still wish we had an actual source though, they deserve the credit.. 😛) 

Edited by Garacesh
  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...