We develop an endpoint security agent that customer IT deploys and manages via MDM on supervised, ADE-enrolled Macs. The agent requires Accessibility permissions to perform core security functions.
Historically, IT provisioned this via the PPPC payload which granted Accessibility as a managed control without end-user interaction. In macOS 27 this path for Accessibility has been removed. The documented replacement — the Privacy key in com.apple.configuration.app.settings — is consent-based: on a supervised device it presents the user a consolidated prompt with "Allow" preselected, which the user may decline.
We are seeking guidance on the supported approach for macOS 27 GA:
On a supervised macOS 27 device, is there a supported mechanism for an MDM-managed, code-signature-verified application to be provisioned with Accessibility as a managed security control, without depending on individual end-user consent? (i.e. an equivalent to what PPPC provided for enterprise-managed endpoints.) If the consent-based com.apple.configuration.app.settings Privacy declaration is the only path, what is Apple's recommended approach for enterprise-mandated security agents that must have Accessibility to function — including handling the case where a user declines or dismisses the prompt?
We have also filed this as an enhancement request via Feedback Assistant (FB23531820).
Environment for context: macOS 27 supervised via Automated Device Enrollment, managed by Jamf Pro.
We have also filed this as an enhancement request via Feedback Assistant (FB23531820).
Thanks!
We have also logged this feedback via Feedback Assistant: FB24264150
Ditto.
IMO this is the right path forward for this.
There’s no doubt that this change was deliberate. It also seems that it’s broken a number of well-trodden device management paths. The best way to let the relevant engineering team know about those issues is via Feedback Assistant.
Have you folks tried this with the just-released macOS 27.0b5? In some other context I’ve learnt that it has significant changes in this space, and I’m not sure whether those also impact this issue.
Share and Enjoy
—
Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"