Swiss_Teacher wrote:
Another reason for not using MDM is we would like to use "DeepFreeze" by Faronics on our new Mac minis: DeepFreeze proves to be a perfect way for us to setup something like Apple's guest account: A "one-time" login that leaves no tracks and totally resets at each login, but can be initially setup by us.
It really isn't possible to clone a Mac system, or even an individual home directory, and hasn't been for years. Apple stores certain unique identifiers in the system Library folder and in the individual users' Library folders. So when you make a copy of those, they aren't unique anymore.
I discovered this when I tried to use Time Machine in the manner you describe and then I couldn't get iCloud Keychain to work. This will also break certain Continuity features. It's the kind of thing that seems to work great, and then, later on, you try some new feature, or an old feature you haven't tried before, and it doesn't work. It works fine for other people, and usually for people answering questions on this forum, but you can't get it work. In many cases, the problem is some unsupported configuration like this that you setup years before.
If you read Faronics description of DeepFreeze for Mac, you'll notice that it has less features than the product for other systems. It focuses heavily on restoration to a known good configuration. Every time I search for the word "clone" on the site, it's always next to a Windows screenshot. I think this feature would likely be useful in the environment you describe, but just don't try to use it to make any clones.