From ed9e3ced13731dba644504dc856db991f46cb1f1 Mon Sep 17 00:00:00 2001 From: royklo <76492458+royklo@users.noreply.github.com> Date: Tue, 14 Jul 2026 21:10:40 +0200 Subject: [PATCH] Remove deprecated OneDrive Open at Login setting; add replacement script The OpenAtLogin managed preference is deprecated and a no-op since OneDrive sync app 24.113, so the KFM policy was silently doing nothing for this setting. Managed Login Items can only allow/lock a login item, not enable it - the only supported mechanism is OneDrive's own /createloginitem command (26.027+), which must run as the signed-in user. - Remove "Open at login" from MacOS - OIB - Microsoft OneDrive - U - Known Folder Move (both IntuneManagement and NativeImport exports), renumber setting IDs, bump policy to v1.1 - Add MACOS/Scripts/Enable-OneDriveOpenAtLogin.zsh: idempotent user-context script that enables the login item once via /createloginitem (adapted from microsoft/intune-my-macs#39) - Update MACOS/CHANGELOG.md and SETTINGSOUTPUT.md Co-Authored-By: Claude Fable 5 --- MACOS/CHANGELOG.md | 14 +++++ ...Drive - U - Known Folder Move - v1.1.json} | 30 ++-------- ...Drive - U - Known Folder Move - v1.1.json} | 17 +----- MACOS/SETTINGSOUTPUT.md | 14 ++--- MACOS/Scripts/Enable-OneDriveOpenAtLogin.zsh | 57 +++++++++++++++++++ MACOS/Scripts/README.md | 21 +++++++ 6 files changed, 103 insertions(+), 50 deletions(-) rename MACOS/IntuneManagement/SettingsCatalog/{MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0.json => MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1.json} (94%) rename MACOS/NativeImport/{MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0.json => MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1.json} (91%) create mode 100755 MACOS/Scripts/Enable-OneDriveOpenAtLogin.zsh create mode 100644 MACOS/Scripts/README.md diff --git a/MACOS/CHANGELOG.md b/MACOS/CHANGELOG.md index ff92994..e6f9b55 100644 --- a/MACOS/CHANGELOG.md +++ b/MACOS/CHANGELOG.md @@ -1,5 +1,19 @@ # OIB MacOS Change Log +# MacOS v1.1 - 2026-07-14 + +## Added +### Scripts +**Enable-OneDriveOpenAtLogin** (suggested policy name: `MacOS - OIB - Microsoft OneDrive - U - Open at Login - v1.1`) +* New user-context shell script (in the new `MACOS/Scripts` folder) that enables the OneDrive login item via OneDrive's `/createloginitem` command (OneDrive 26.027+), replacing the removed "Open at login" setting below. The script is idempotent: it no-ops until OneDrive >= 26.027 is installed, performs the enable exactly once, then a per-user marker keeps every later run a no-op. It works together with the Managed Login Items in "MacOS - OIB - Microsoft OneDrive - D - Service and Access", which allow and lock the login item but cannot enable it. See `MACOS/Scripts/README.md` for deployment settings. Adapted from [microsoft/intune-my-macs PR #39](https://github.com/microsoft/intune-my-macs/pull/39). + +## Changed/Updated +### Settings Catalog +**MacOS - OIB - Microsoft OneDrive - U - Known Folder Move** (v1.0 → v1.1) +* Removed the setting "Open at login". The underlying `OpenAtLogin` managed preference is deprecated and has been a no-op since OneDrive sync app 24.113, so the policy was silently doing nothing for this setting. A Managed Login Items payload can't replace it either, as it can only allow/lock a login item, not enable one. OneDrive start-at-login is now handled by the new `Enable-OneDriveOpenAtLogin` script above. + +--- + # MacOS v1.0 Release - 2024-09-02 As per PR [#35](https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/pull/35) by @ugurkocde diff --git a/MACOS/IntuneManagement/SettingsCatalog/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0.json b/MACOS/IntuneManagement/SettingsCatalog/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1.json similarity index 94% rename from MACOS/IntuneManagement/SettingsCatalog/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0.json rename to MACOS/IntuneManagement/SettingsCatalog/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1.json index 68f0294..da9115c 100644 --- a/MACOS/IntuneManagement/SettingsCatalog/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0.json +++ b/MACOS/IntuneManagement/SettingsCatalog/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1.json @@ -9,7 +9,7 @@ "description": "", "lastModifiedDateTime@odata.type": "#DateTimeOffset", "lastModifiedDateTime": "2024-08-30T10:17:13.6247849Z", - "name": "MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0", + "name": "MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1", "platforms@odata.type": "#microsoft.graph.deviceManagementConfigurationPlatforms", "platforms": "macOS", "priorityMetaData": null, @@ -17,7 +17,7 @@ "roleScopeTagIds": [ "0" ], - "settingCount": 15, + "settingCount": 14, "technologies@odata.type": "#microsoft.graph.deviceManagementConfigurationTechnologies", "technologies": "mdm,appleRemoteManagement", "id": "1ca2dd46-7a65-4006-aee0-9d1ab134f7d9", @@ -340,28 +340,6 @@ "@odata.id": "deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002713\u0027)", "@odata.editLink": "deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002713\u0027)", "id": "13", - "settingInstance": { - "@odata.type": "#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance", - "settingDefinitionId": "com.apple.managedclient.preferences_openatlogin", - "settingInstanceTemplateReference": null, - "choiceSettingValue": { - "@odata.type": "#microsoft.graph.deviceManagementConfigurationChoiceSettingValue", - "settingValueTemplateReference": null, - "value": "com.apple.managedclient.preferences_openatlogin_true", - "children@odata.type": "#Collection(microsoft.graph.deviceManagementConfigurationSettingInstance)", - "children": [ - - ] - } - }, - "settingDefinitions@odata.associationLink": "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002713\u0027)/settingDefinitions/$ref", - "settingDefinitions@odata.navigationLink": "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002713\u0027)/settingDefinitions" - }, - { - "@odata.type": "#microsoft.graph.deviceManagementConfigurationSetting", - "@odata.id": "deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002714\u0027)", - "@odata.editLink": "deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002714\u0027)", - "id": "14", "settingInstance": { "@odata.type": "#microsoft.graph.deviceManagementConfigurationSimpleSettingInstance", "settingDefinitionId": "com.apple.managedclient.preferences_kfmoptinwithwizard", @@ -372,8 +350,8 @@ "value": "%OrganizationId%" } }, - "settingDefinitions@odata.associationLink": "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002714\u0027)/settingDefinitions/$ref", - "settingDefinitions@odata.navigationLink": "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002714\u0027)/settingDefinitions" + "settingDefinitions@odata.associationLink": "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002713\u0027)/settingDefinitions/$ref", + "settingDefinitions@odata.navigationLink": "https://graph.microsoft.com/beta/deviceManagement/configurationPolicies(\u00271ca2dd46-7a65-4006-aee0-9d1ab134f7d9\u0027)/settings(\u002713\u0027)/settingDefinitions" } ], "#microsoft.graph.assign": { diff --git a/MACOS/NativeImport/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0.json b/MACOS/NativeImport/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1.json similarity index 91% rename from MACOS/NativeImport/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0.json rename to MACOS/NativeImport/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1.json index a8f9b09..f4eee0f 100644 --- a/MACOS/NativeImport/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0.json +++ b/MACOS/NativeImport/MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1.json @@ -4,11 +4,11 @@ "creationSource": null, "description": "", "lastModifiedDateTime": "2024-08-29T12:03:07.6652218Z", - "name": "MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0", + "name": "MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1", "platforms": "macOS", "priorityMetaData": null, "roleScopeTagIds": ["0"], - "settingCount": 15, + "settingCount": 14, "technologies": "mdm,appleRemoteManagement", "id": "a205fcca-770e-4470-a2dd-f83e61eae51b", "templateReference": { @@ -206,19 +206,6 @@ }, { "id": "13", - "settingInstance": { - "@odata.type": "#microsoft.graph.deviceManagementConfigurationChoiceSettingInstance", - "settingDefinitionId": "com.apple.managedclient.preferences_openatlogin", - "settingInstanceTemplateReference": null, - "choiceSettingValue": { - "settingValueTemplateReference": null, - "value": "com.apple.managedclient.preferences_openatlogin_true", - "children": [] - } - } - }, - { - "id": "14", "settingInstance": { "@odata.type": "#microsoft.graph.deviceManagementConfigurationSimpleSettingInstance", "settingDefinitionId": "com.apple.managedclient.preferences_kfmoptinwithwizard", diff --git a/MACOS/SETTINGSOUTPUT.md b/MACOS/SETTINGSOUTPUT.md index b862641..3d83779 100644 --- a/MACOS/SETTINGSOUTPUT.md +++ b/MACOS/SETTINGSOUTPUT.md @@ -42,7 +42,7 @@ - [MacOS - OIB - Microsoft OneDrive - D - Service and Access - v1.0](#section-17) - - [MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0](#section-18) + - [MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1](#section-18) - [MacOS - OIB - Updates - D - Update Configuration - v1.0](#section-19) @@ -1971,7 +1971,7 @@ ###### Table 30. Settings - MacOS - OIB - Microsoft OneDrive - D - Service and Access - v1.0 -

MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0

+

MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1

@@ -1983,7 +1983,7 @@ - + @@ -2011,7 +2011,7 @@
NameMacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1
Description
-###### Table 31. Basics - MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0 +###### Table 31. Basics - MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1 @@ -2072,16 +2072,12 @@ - - - -
True
Open at loginTrue
Prompt users to enable the Folder Backup feature (Known Folder Move) %OrganizationId%
-###### Table 32. Settings - MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.0 +###### Table 32. Settings - MacOS - OIB - Microsoft OneDrive - U - Known Folder Move - v1.1

MacOS - OIB - Updates - D - Update Configuration - v1.0

diff --git a/MACOS/Scripts/Enable-OneDriveOpenAtLogin.zsh b/MACOS/Scripts/Enable-OneDriveOpenAtLogin.zsh new file mode 100755 index 0000000..2de5e43 --- /dev/null +++ b/MACOS/Scripts/Enable-OneDriveOpenAtLogin.zsh @@ -0,0 +1,57 @@ +#!/bin/zsh +############################################################################################ +## +## MacOS - OIB - Microsoft OneDrive - U - Open at Login +## +## Enables the OneDrive login item via OneDrive's /createloginitem command (26.027+) +## so OneDrive launches automatically at login for the signed-in user. Needed because +## the legacy OpenAtLogin preference is deprecated (a no-op since sync app 24.113) and +## the Managed Login Items in "MacOS - OIB - Microsoft OneDrive - D - Service and Access" +## can only allow/lock a login item, not enable it. +## +## Adapted from microsoft/intune-my-macs PR #39 (MIT License, +## Copyright (c) Microsoft Corporation). +## +## Requirements: +## - Run script as signed-in user = Yes (open -a fails outside the user's Aqua session) +## - Execution frequency = every 15 min; idempotent - no-ops until OneDrive >= 26.027 +## is installed, runs the enable once, then a per-user marker keeps runs a no-op. +## +############################################################################################ + +set -u +ONEDRIVE="/Applications/OneDrive.app" +MINVER="26.027" # first OneDrive build supporting /createloginitem +MARKER="$HOME/Library/Application Support/OpenIntuneBaseline/onedrive-loginitem.done" + +log() { echo "[onedrive-openatlogin] $*"; } + +# Guard 0 - already registered on this account; keeps the 15-min cadence a cheap +# no-op that never re-launches OneDrive. Delete the marker file to force a re-run. +if [[ -f "$MARKER" ]]; then + log "Login item already registered (marker present) - no-op." + exit 0 +fi + +# Guard 1 - no-op until OneDrive is installed (the app install may lag this script). +if [[ ! -d "$ONEDRIVE" ]]; then + log "OneDrive not installed yet - no-op; will retry next run." + exit 0 +fi + +# Guard 2 - /createloginitem needs OneDrive >= 26.027. Older builds still honour +# the OpenAtLogin managed pref, so just no-op rather than launching the full app. +ver=$(defaults read "$ONEDRIVE/Contents/Info" CFBundleShortVersionString 2>/dev/null || echo "0") +ok=$(awk -v v="$ver" -v m="$MINVER" 'BEGIN{split(v,a,".");split(m,b,".");print (a[1]*100000+a[2] >= b[1]*100000+b[2])?1:0}') +if [[ "$ok" != "1" ]]; then + log "OneDrive $ver < $MINVER - /createloginitem unavailable; relying on OpenAtLogin pref. No-op." + exit 0 +fi + +# Enable the OneDrive login item. Fire-and-exit; does not launch the full sync +# client. Then drop the marker so Guard 0 no-ops every subsequent run. +open -a "$ONEDRIVE" --args /createloginitem +mkdir -p "${MARKER:h}" +print -r -- "registered OneDrive $ver at login" > "$MARKER" +log "Requested OneDrive login-item registration (OneDrive $ver); marker written." +exit 0 diff --git a/MACOS/Scripts/README.md b/MACOS/Scripts/README.md new file mode 100644 index 0000000..afe7bd0 --- /dev/null +++ b/MACOS/Scripts/README.md @@ -0,0 +1,21 @@ +# Scripts + +This folder contains scripts that supplement the MacOS OIB where a Settings Catalog policy cannot achieve the desired result. + +## Enable-OneDriveOpenAtLogin +### Purpose +The OneDrive "Open at login" (`OpenAtLogin`) managed preference is deprecated and has been a no-op since sync app 24.113, so configuring it via Settings Catalog silently does nothing. A Managed Login Items payload can't replace it either: per Apple, Managed Login Items only *allow*/lock a login item, they never *enable* one. The only supported mechanism is OneDrive's own `/createloginitem` fire-and-exit command (OneDrive 26.027+), which must run as the signed-in user. + +This script enables the OneDrive login item via `/createloginitem` so OneDrive starts automatically after the user signs in. It is guarded and idempotent: it no-ops until OneDrive >= 26.027 is installed, performs the enable exactly once, then a per-user marker file keeps every later run a no-op so the recurring schedule never re-launches OneDrive. + +It works together with the Managed Login Items configured in `MacOS - OIB - Microsoft OneDrive - D - Service and Access`: the script enables the login item, the policy keeps it allowed and locked on. + +### Usage +**Script type** - Shell script (macOS) +**Suggested name** - `MacOS - OIB - Microsoft OneDrive - U - Open at Login - v1.1` +**Assign to** - Users +**Script Settings:** +- Run script as signed-in user - Yes +- Hide script notifications on devices - Yes +- Script frequency - Every 15 minutes +- Max number of times to retry if script fails - 3