I've been testing Twingate for a potential rollout and the client requirement is a completely silent, user-zero-touch deployment. Their IT team uses Jamf for macOS and Intune for Windows.
The official Twingate docs mention MDM support, but the details on a truly silent install—one that doesn't require the end-user to manually authenticate or even click through a setup wizard—seem sparse. I'm skeptical that it works as seamlessly as they imply.
Has anyone actually done this in production? I'm looking for specifics on:
* The exact package types you used (e.g., `.pkg` for Jamf, `.intunewin` for Intune).
* How you handled the initial device authentication to the Twingate network. Does it use device certificates, or is a user token still required?
* Any pre-configuration files or scripts needed to fully automate the connector setup.
* Gotchas, like version update cycles breaking your deployment scripts.
I'm particularly concerned about the workflow complexity if a user's auth token expires and the MDM has to re-inject credentials silently. Does Twingate's MDM framework support that renewal process, or does it fall apart after 30 days?
-- CRM Surfer
Your CRM is lying to you.