Non existent Endpoint Security Entitlement

Hello there,

Today, after five months I have received an email from Developer Relations that "The entitlement for Endpoint Security has been assigned to your account". As you can see on the attached images, this supposed to be the Production Entitlement (I got the dev entitlement a while ago).

As far as I understand, I should be able to assign the entitlement in the "Identifiers>App IDs>App>Additional Capabilities". As you can see on my second screenshot, the UI only mentions "Development Developer ID" Distribution support.

Furthermore, when creating a "Developer ID" (or event Mac App Store) provision profile, I should eventually see an "Additional Entitlements" section to be able to choose the production Entitlement. I can't find the "Additional Entitlements" UI in any Cert / identifier / Profile combinations.

I tried Xcode 15's Automatic code signing as well, but it doesn't seem to do the trick. It totally seem as If I have never received the production entitlement.

I saw Quinn's advice in an old thread, that presumably the entitlement was misaligned to the wrong profiles(?), and in this case: "To correct this, you’ll need to get back in touch with the folks who granted you the entitlement."

I am devastated as I can be, I waited for this day like it was christmas. I was pinging the "endpoint-review . at . apple.com" email address for months with no success. Then why would they answer to my n+1th email?

Anybody has any advice what to do? Which other email addresses should I try to ping? I still have 2 TSIs, but read earlier that they have no use in this regard.

Thank you in advance for everyone

Accepted Reply

Oh, hey, they improved the Additional Capabilities UI. Nice!

the UI only mentions "Development Developer ID" Distribution support

There’s an implied comma there; the capability can be used for Development and Developer ID signing. The missing options are Ad hoc (which is iOS only) and App Store (ES clients are not supported on the Mac App Store). So AFAICT you’re good to go.

Furthermore, when creating a "Developer ID" (or event Mac App Store) provision profile, I should eventually see an "Additional Entitlements" section to be able to choose the production Entitlement.

No. Endpoint Security uses the new process, which doesn’t involve an Additional Entitlements step. Rather, the capability flows from your App ID to your provisioning profile’s allowlist.

Contrast the new and old processes described in Using the Multicast Networking Additional Capability.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Replies

Oh, hey, they improved the Additional Capabilities UI. Nice!

the UI only mentions "Development Developer ID" Distribution support

There’s an implied comma there; the capability can be used for Development and Developer ID signing. The missing options are Ad hoc (which is iOS only) and App Store (ES clients are not supported on the Mac App Store). So AFAICT you’re good to go.

Furthermore, when creating a "Developer ID" (or event Mac App Store) provision profile, I should eventually see an "Additional Entitlements" section to be able to choose the production Entitlement.

No. Endpoint Security uses the new process, which doesn’t involve an Additional Entitlements step. Rather, the capability flows from your App ID to your provisioning profile’s allowlist.

Contrast the new and old processes described in Using the Multicast Networking Additional Capability.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Thank you for the quick answer, I will try to setup the profiles then.