You can now deploy certificates without user affinity to macOS devices. This will makes things a lot easier to make the device compliant and can connect to WIFI or VPN, without users affinity.
Out of the box experience have just been smoother for the macOS.
