We recently made a few critical updates to our agent for macOS. We’ll get into the details shortly, but the quick version is: if you are currently leveraging an MDM to deliver Kolide to your users, we recommend updating your policy with the information below.
Essentially, the agent is responsible for collecting all of the data about the individual devices in your fleet and communicating that data to Kolide. You can think of it as the piece of our service responsible for establishing the ground truth.
Three related changes happened in tandem:
- We started shipping an app bundle
- We changed the Apple account that signs the binary and package.
The new account is:
- The way to grant Kolide Full Disk Access has changed
Transitioning to an app bundle instead of the previously provided plain binary gives us the foundation for new features later this year. (Hint hint: keep in touch!) This was also a practical change as it keeps Kolide in line with platform expectations.
Full Disk Access is an important setting to enable because it allows Kolide to do the following tasks:
- To list other apps that also have disk access.
- To inspect system files that give us a better understanding of the device’s security.
- Look for evidence of plain text credentials in your downloads, documents, and desktop folders.
- Finally, to read the file name of our installation package to assist with user-to-device association.
Information and policies can be found in our documentation.
If you need assistance with these changes, please reach out to Support. Otherwise, we look forward to sharing more about the new features coming soon to Kolide in the next couple of months!