pmg setup install --system once to put administrator-owned shims first on the machine PATH.
The MDM scripts README in the PMG repo is the source of truth. Scripts and supported MDMs are updated there first.
pmg cloud sync after setup. On Windows, this runs for logged-on users only. A successful sync adds the device to Endpoint Hub without waiting for a package manager event.
To use Cloud sync, you need an API key and Tenant ID from app.safedep.io/settings/api-keys. To repeat the sync without installing or configuring PMG again, pass --cloud-sync-only to the install script. Use this option only for users who already have PMG and cloud sync enabled. Run the normal installer to configure new users. On Windows, run it after those users sign in to store their Cloud credentials.
Supported MDMs
Jamf, Mosyle, and Kandji use the macOS scripts. JumpCloud and Intune also support Linux and Windows deployments. Use multi-file scripts when your MDM can ship sibling files, or standalone scripts when it accepts one script per policy.Scripts
- Multi-file (Jamf, JumpCloud, Intune Win32 apps): deploy the shared lib for your platform alongside the install or uninstall script. The entry scripts source the shared lib at runtime and fail without it.
- Standalone (Intune): use a prebuilt installer, or generate one with managed config and optional Cloud credentials embedded, then upload that one script.
config.yml beside the scripts or embed it with the standalone generator’s --config option. Keep your other policy settings in the file. The installer replaces the managed config with the bundled file.
On Windows, Cloud credentials must be accompanied by a config with cloud.enabled: true. This applies to runtime and embedded credentials. The system install always creates a managed config, which pmg config set cloud.enabled true cannot change. On macOS and Linux, the installer enables sync automatically when credentials are supplied and no managed config exists. If you supply a managed config, set cloud.enabled: true in it.
For Windows standalone scripts with runtime credentials, keep --config and omit --embed-cloud-credentials when generating the installer. See Globally Managed Configuration.
A successful MDM install status does not confirm Cloud sync. If a Windows endpoint does not appear in Endpoint Hub, check
pmg config get cloud.enabled and run pmg cloud sync in a logged-on user’s session with credentials configured. Cloud login and sync failures do not fail the normal installer.pmg setup cert install). On macOS this needs interactive Keychain authorization, so it cannot run through MDM: have each user run it in their own session when needed. On Linux, PMG’s ephemeral CA is usually enough. Run pmg setup cert install --system as your normal user only if a tool needs a persistent CA in the system trust store. Windows package managers use the injected ephemeral CA, except Go, which needs a user-run pmg setup cert install.
Next steps
Jamf
Multi-file scripts for macOS. Pass Cloud credentials as script parameters.
JumpCloud
Multi-file scripts for macOS, Linux, or Windows.
Intune
Standalone scripts for all three platforms, or a Windows Win32 app.

