Bring Advanced Elevation Rules (file/publisher auto-approve) to the macOS agent
Greg Wilkins
The Windows agent supports Advanced Elevation Rules that auto-approve or auto-deny future UAC requests based on file path, file name, product name, MD5 hash, and/or publisher certificate — and those rules can be scoped to a single machine, a group, or the entire org. Once a rule exists, other users never even have to submit a request for that installer.
The macOS agent (now GA) currently only supports session-based elevation with manual technician approve/deny — there's no equivalent rule engine to auto-allow known-good installers/apps org-wide.
Request: bring file- and/or code-signing-identity-based auto-approve/deny rules to the macOS agent, matching the spirit of the Windows Advanced Elevation Rules (e.g., match on bundle ID, code signature/Team ID, notarization status, and/or path), scoped per-machine/group/org the same way.
This would close the biggest functional gap between the Windows and Mac agents and let MSPs actually reach "zero standing admin" on mixed fleets without turning Mac elevation into a 100%-manual-approval workflow.
Here's a draft ready to post on roadmap.cyberfox.com/autoelevate:
D
Daniel Rivera
Hi Greg — thanks for the detailed writeup. You've captured the gap exactly, and it's one we hear often.
Rule-based elevation for macOS is something we're actively exploring as part of looking at Mac/Windows agent parity. The criteria you mention — bundle ID, code signature/Team ID, notarization status, path — are exactly the kinds of macOS-native signals we're evaluating, since there's no direct UAC/publisher analog on macOS.
Related: the broader effort is tracked in the existing post "Mac agent: feature parity with Windows agent," which we've just moved to Under Consideration — worth following for updates there too.
No commitments or timeline to share yet, but your input here helps shape that evaluation, and we'll post updates as things progress.