×
×
×
×

Configure Mac Pre-Requisites

Before deploying an application control policy to Mac endpoints, two system-level permissions must be granted: a System Extension approval and Full Disk Access for the Application Control driver.

Prerequisites
The Mac agent is downloaded automatically on policy deployment. Complete both prerequisites below before policy enforcement can begin on macOS endpoints.

Configure prerequisites manually

Follow these steps on each Mac endpoint if you are not using an MDM solution to push the permissions profile.

Step-by-step: System Extension and Full Disk Access

When a policy is deployed to a Mac endpoint, a pop-up listing the required prerequisites appears automatically on the device.

Prerequisite pop-up listing System Extension Request and Full Disk Access Request on Mac

  1. In the pop-up, tap Enable Access next to System Extension Request, then select Open System Settings.

    Enable Access button for System Extension Request in the prerequisite pop-up

  2. In the Privacy & Security section, tap Allow to load Application Control from system software.

    Privacy & Security settings showing the Allow button to load Application Control from system software

  3. Enter your credentials when prompted to authorize the change.

    macOS credential prompt requesting administrator password to authorize the change

  4. The System Extension Request is now enabled.

    System Extension Request marked as enabled in the prerequisite pop-up

  5. Back in the pop-up, tap Enable Access next to Full Disk Access Request. A list of applications requiring access appears.
  6. Enable access for Application Control Driver from the list.

    Full Disk Access list showing Application Control Driver with the toggle enabled

  7. Enter your credentials when prompted to authorize the change.

    macOS credential prompt requesting administrator password to authorize the change

  8. The Full Disk Access Request is now enabled. Both prerequisites are complete.

    Full Disk Access Request marked as enabled in the prerequisite pop-up

Configure prerequisites using an MDM solution

If you manage Mac endpoints through a Mobile Device Management (MDM) solution, deploy the pre-configured profile instead of configuring each device manually.

Deploy the pre-configured profile

Download the pre-configured profile and deploy it to the Mac endpoints that will be managed through Endpoint Central.

Pro-tip
If the pre-configured profile does not work with your MDM solution, upload it manually using the technical details below to configure both prerequisites yourself.

System extension request — MDM configuration values

  • Allowed Extension CategoriesEndpoint Security extension
  • Team IdentifierTZ824L8Y37
  • Extension Bundle Identifiercom.manageengine.appctrl.driver

Full disk access request — MDM configuration values

  • Identifier TypeBundle ID
  • Identifiercom.manageengine.appctrl.driver
  • Static Code ValidationYes
  • Code Sign Requirementanchor apple generic and identifier "com.manageengine.appctrl.driver" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = TZ824L8Y37)

Preventing users from disabling the Endpoint Security Extension (Optional)*

  • NonRemovableSystemExtensions
  • Key - TZ824L8Y37
  • Value - com.manageengine.appctrl.driver
Note
You can configure the required MDM profiles before deploying the policy. However, end users cannot manually grant the required permissions before the policy is deployed. They can only configure those permissions after the policy deployment, and this applies only to permissions that must be granted manually.
Preventing Disable of Endpoint Security extension

* Supported on macOS 15 Sequoia and later.

 

Related