Deploying on macOS
On a Mac, some ElevateIQ features work the moment the agent is installed, and one feature (application allowlisting) needs a permission that is either pushed silently by your MDM or granted once by hand. This page tells you exactly what works where, so there are no surprises.
USB control works on any Mac, no setup
USB and SD/MMC device control needs no special Apple permission, no Full Disk Access, and no MDM. As soon as the ElevateIQ agent is installed and enrolled, blocked devices are blocked and the tray "request access" flow works, managed or not. Time-boxed admin elevation is the same: it works immediately with no extra setup.
This is a genuine advantage: most Mac security tools that do device control require the same heavyweight permissions as their app-blocking, so they cannot control USB on an unmanaged Mac at all.
Application allowlisting needs Full Disk Access
Blocking which apps are allowed to run uses Apple's Endpoint Security framework, which requires Full Disk Access for the ElevateIQ helper. There are two ways to grant it.
With an MDM (recommended, zero-touch)
If your Macs are enrolled in an MDM (Jamf, Intune, Kandji, Addigy, Mosyle, and so on), your admin pushes a single configuration profile (a PPPC profile) that pre-approves Full Disk Access and the background helper. The agent is fully functional on first boot, nothing for the end user to click, and the permission survives macOS upgrades automatically. This is the same model CrowdStrike, Microsoft Defender and ThreatLocker use on macOS.
Without an MDM (one-time guided setup)
No MDM is fine too. App allowlisting still works after a one-time setup the user does once, in order:
- Move ElevateIQ.app to the Applications folder.
- Open it. The menu-bar app registers the background helper.
- In System Settings → General → Login Items & Extensions, turn the ElevateIQ helper on.
- In System Settings → Privacy & Security → Full Disk Access, turn ElevateIQ on.
USB control and admin elevation do not need steps 3 and 4; they are already working. Only app allowlisting waits on Full Disk Access.
What each feature needs
| Feature | Full Disk Access | MDM | Works on an unmanaged Mac? |
|---|---|---|---|
| USB / SD device control | No | No | Yes, zero setup |
| Admin elevation (grant / revoke) | No | No | Yes, zero setup |
| Application allowlisting | Yes | For silent grant only | Yes, after the one-time setup |
Seeing readiness in the console
Each Mac reports its own status on check-in, so you can see at a glance which machines are ready and which still need setup:
- The Devices list shows small badges on each Mac: MDM (managed), FDA (Full Disk Access granted), and App control (allowlisting active).
- A device's Security tab has a macOS feature readiness panel explaining what is active and what each pending feature needs.
- The Devices macOS filter lets you find, for example, every Mac that still needs Full Disk Access, or every unmanaged Mac.
A note on Apple's review
Application allowlisting on macOS depends on an Apple-granted Endpoint Security entitlement, which Apple reviews per developer. Until it is provisioned for your build, USB control, device control and admin elevation are fully available; app allowlisting turns on automatically once the entitlement and Full Disk Access are both in place.