Help Center/Deploying on macOS

Deploying on macOS

On a Mac, some ElevateIQ features work the moment the agent is installed, and one feature (application allowlisting) needs a permission that is either pushed silently by your MDM or granted once by hand. This page tells you exactly what works where, so there are no surprises.

USB control works on any Mac, no setup

USB and SD/MMC device control needs no special Apple permission, no Full Disk Access, and no MDM. As soon as the ElevateIQ agent is installed and enrolled, blocked devices are blocked and the tray "request access" flow works, managed or not. Time-boxed admin elevation is the same: it works immediately with no extra setup.

This is a genuine advantage: most Mac security tools that do device control require the same heavyweight permissions as their app-blocking, so they cannot control USB on an unmanaged Mac at all.

Application allowlisting needs Full Disk Access

Blocking which apps are allowed to run uses Apple's Endpoint Security framework, which requires Full Disk Access for the ElevateIQ helper. There are two ways to grant it.

With an MDM (recommended, zero-touch)

If your Macs are enrolled in an MDM (Jamf, Intune, Kandji, Addigy, Mosyle, and so on), your admin pushes a single configuration profile (a PPPC profile) that pre-approves Full Disk Access and the background helper. The agent is fully functional on first boot, nothing for the end user to click, and the permission survives macOS upgrades automatically. This is the same model CrowdStrike, Microsoft Defender and ThreatLocker use on macOS.

Without an MDM (one-time guided setup)

No MDM is fine too. App allowlisting still works after a one-time setup the user does once, in order:

  1. Move ElevateIQ.app to the Applications folder.
  2. Open it. The menu-bar app registers the background helper.
  3. In System Settings → General → Login Items & Extensions, turn the ElevateIQ helper on.
  4. In System Settings → Privacy & Security → Full Disk Access, turn ElevateIQ on.

USB control and admin elevation do not need steps 3 and 4; they are already working. Only app allowlisting waits on Full Disk Access.

What each feature needs

FeatureFull Disk AccessMDMWorks on an unmanaged Mac?
USB / SD device controlNoNoYes, zero setup
Admin elevation (grant / revoke)NoNoYes, zero setup
Application allowlistingYesFor silent grant onlyYes, after the one-time setup

Seeing readiness in the console

Each Mac reports its own status on check-in, so you can see at a glance which machines are ready and which still need setup:

  • The Devices list shows small badges on each Mac: MDM (managed), FDA (Full Disk Access granted), and App control (allowlisting active).
  • A device's Security tab has a macOS feature readiness panel explaining what is active and what each pending feature needs.
  • The Devices macOS filter lets you find, for example, every Mac that still needs Full Disk Access, or every unmanaged Mac.

A note on Apple's review

Application allowlisting on macOS depends on an Apple-granted Endpoint Security entitlement, which Apple reviews per developer. Until it is provisioned for your build, USB control, device control and admin elevation are fully available; app allowlisting turns on automatically once the entitlement and Full Disk Access are both in place.