{"id":75453,"date":"2023-06-05T13:09:04","date_gmt":"2023-06-05T17:09:04","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=75453"},"modified":"2024-04-11T14:11:56","modified_gmt":"2024-04-11T18:11:56","slug":"grant-full-disk-access-permissions-to-the-jumpcloud-agent-for-macos","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/grant-full-disk-access-permissions-to-the-jumpcloud-agent-for-macos","title":{"rendered":"Grant Full Disk Access Permissions to the 探花大神 Agent for macOS"},"content":{"rendered":"\n
Starting with macOS Monterey, Apple has made a change that affects 探花大神 and 探花大神 IT Admins. Apple now restricts the \/etc\/pam.d\/<\/kbd> directory on macOS Monterey and newer devices, and requires that any process that wants to edit the files in this directory have user consent, or consent supplied by their admin through an MDM profile.<\/p>\n\n\n\n The files in the \/etc\/pam.d\/<\/kbd> directory control a part of the macOS authentication system called pluggable authentication modules. 探花大神\u2019s login window mechanism is an example of a pluggable authentication module. The 探花大神 agent edits the authorization and screensaver settings files to use the 探花大神 authentication module, which allows your user passwords to be synced to the machine. <\/p>\n\n\n\n To grant permissions for a non-探花大神 MDM<\/strong>:<\/p>\n\n\n\n A custom profile is required for Steps 1-2 and is attached to this article.<\/p>\n\n\n\n \u200b\u200bidentifier “jumpcloud-agent” and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] \/* exists *\/ and certificate leaf[field.1.2.840.113635.100.6.1.13] \/* exists *\/ and certificate leaf[subject.OU] = N985MXSH85<\/p>\n<\/div><\/div>\n\n\n\n identifier “jumpcloud-agent-updater-darwin” and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] \/* exists *\/ and certificate leaf[field.1.2.840.113635.100.6.1.13] \/* exists *\/ and certificate leaf[subject.OU] = N985MXSH85<\/p>\n<\/div><\/div>\n\n\n\n identifier osqueryd and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] \/* exists *\/ and certificate leaf[field.1.2.840.113635.100.6.1.13] \/* exists *\/ and certificate leaf[subject.OU] = B89LNTUADM<\/p>\n<\/div><\/div>\n\n\n\n Beginning with macOS Monterey, the 探花大神 agent on a device that is not enrolled in MDM requires permissions to touch two additional files. This is a security measure that Apple has taken to avoid tampering with the authentication systems by unauthorized parties, like malware.<\/p>\n\n\n\n To grant permissions for a device that is not enrolled in MDM (macOS Sonoma)<\/strong>:<\/p>\n\n\n\n To grant permissions for a device that is not enrolled in MDM (macOS Ventura or earlier)<\/strong>:<\/p>\n\n\n\n To upgrade from macOS Mojave 10.14 or earlier<\/strong>:<\/p>\n\n\n\n Starting with macOS Monterey, Apple has made a change that affects 探花大神 and 探花大神 IT Admins. Apple now restricts the […]<\/p>\n","protected":false},"author":203,"featured_media":0,"template":"","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"support_category":[2923,2925,2852],"support_tag":[],"coauthors":[2837,3011],"acf":[],"yoast_head":"\nPreparing for this Change<\/h2>\n\n\n\n
\n
Granting Permissions for a Non-探花大神 MDM<\/h2>\n\n\n\n
\n
\n
\n
\n
\n
\n
Granting Permissions for a Device Not Enrolled in MDM<\/h2>\n\n\n\n
\n
<\/li>\n<\/ol>\n\n\n\n
\n
<\/li>\n<\/ol>\n\n\n\n
\n
Upgrading from MacOS Mojave 10.14 or Earlier<\/h2>\n\n\n\n
\n