Deploying on macOS
On a Mac, most ElevateIQ features work the moment the agent is installed. One feature (application allowlisting) additionally needs the background helper approved, which your MDM can push silently or a user can turn on once. This page tells you exactly what works where, so there are no surprises.
USB control works on any Mac, no setup
USB and SD/MMC device control needs no special Apple permission, no Full Disk Access, and no MDM. As soon as the ElevateIQ agent is installed and enrolled, blocked devices are blocked and the tray "request access" flow works, managed or not. Time-boxed admin elevation is the same: it works immediately with no extra setup.
This is a genuine advantage: most Mac security tools gate device control behind the same approvals as their app-blocking, so they cannot control USB on an unmanaged Mac at all.
One exception: drives connected to a virtual machine
If a USB drive is connected directly into a running virtual machine (Parallels Desktop, VMware Fusion, or similar), the Mac itself never sees that drive as storage, so ElevateIQ cannot block, approve, or mount it. The VM has taken the device. This is a limitation of how macOS hands USB devices to virtual machines, and it applies to every Mac device-control product, not just ElevateIQ.
To bring the drive under policy, release it from the VM (in Parallels: Devices > USB & Bluetooth, and uncheck the drive) or shut the VM down, then re-plug it. Once the Mac itself owns the drive, the normal block and request-access flow applies.
Application allowlisting needs the helper approved
Blocking which apps are allowed to run uses Apple's Endpoint Security framework. The only approval it needs is for the ElevateIQ background helper itself: no Full Disk Access prompt, and no privacy permission for the end user to hunt through. There are two ways to approve the helper.
With an MDM (recommended, zero-touch)
If your Macs are enrolled in an MDM (Jamf, Intune, Kandji, Addigy, Mosyle, and so on), your admin pushes a single configuration profile that pre-approves the background helper. The agent is fully functional on first boot, nothing for the end user to click, and the approval survives macOS upgrades automatically. This is the same model CrowdStrike, Microsoft Defender and ThreatLocker use on macOS.
Without an MDM (one-time guided setup)
No MDM is fine too. App allowlisting still works after a one-time setup the user does once, in order:
- Move ElevateIQ.app to the Applications folder.
- Open it. The menu-bar app registers the background helper.
- In System Settings → General → Login Items & Extensions, turn the ElevateIQ helper on.
USB control and admin elevation do not wait on that last step; they are already working the moment the agent is enrolled. Only app allowlisting needs the helper turned on.
What each feature needs
| Feature | Helper approval | MDM | Works on an unmanaged Mac? |
|---|---|---|---|
| USB / SD device control | No | No | Yes, zero setup |
| Admin elevation (grant / revoke) | No | No | Yes, zero setup |
| Application allowlisting | Yes | For silent approval only | Yes, after the one-time setup |
Seeing readiness in the console
Each Mac reports its own status on check-in, so you can see at a glance which machines are ready and which still need setup:
- The Devices list shows small badges on each Mac: MDM (managed) and App control (allowlisting active).
- A device's Security tab has a macOS feature readiness panel explaining what is active and what each pending feature needs.
- The Devices macOS filter lets you find, for example, every Mac where app control is not yet active, or every unmanaged Mac.
A note on Apple's Endpoint Security entitlement
Application allowlisting on macOS depends on an Apple-granted Endpoint Security entitlement, which Apple reviews per developer. ElevateIQ has been granted it, so it ships in the agent: there is nothing for you to request or wait on. Allowlisting turns on once the background helper is approved, either by MDM profile or the one-time setup above.