Apple's new El Capitan feature SIP (System Integrity Protection) aka "rootless" will have some interesting impacts that will impede workflows for administrators.
- If you Netboot across subnets, you will no longer be able to use bless. Apple's view is if someone can target a machine to boot to a non 10.11 OS, they can bypass SIP. This will prevent any unathorized boot methods.
- You will be able to write to certain privileged folders through the use of a package signed with a valid Apple Developer code signing certificate.
More soon on SIP if I can find the right engineer.