Big Changes to Our macOS Agent

Emily Hill
March 12th, 2023

We recently made a few critical updates to our agent for macOS. We’ll get into the details shortly, but the quick version is: if you are currently leveraging an MDM to deliver Kolide to your users, we recommend updating your policy with the information below.

What Does the Kolide Agent Do?

Essentially, the agent is responsible for collecting all of the data about the individual devices in your fleet and communicating that data to Kolide. You can think of it as the piece of our service responsible for establishing the ground truth.

What Changed for macOS

Three related changes happened in tandem:

  1. We started shipping an app bundle
  2. We changed the Apple account that signs the binary and package. The new account is: X98UFR7HA3
  3. The way to grant Kolide Full Disk Access has changed

Transitioning to an app bundle instead of the previously provided plain binary gives us the foundation for new features later this year. (Hint hint: keep in touch!) This was also a practical change as it keeps Kolide in line with platform expectations.

Full Disk Access

Full Disk Access is an important setting to enable because it allows Kolide to do the following tasks:

  • To list other apps that also have disk access.
  • To inspect system files that give us a better understanding of the device’s security.
  • Look for evidence of plain text credentials in your downloads, documents, and desktop folders.
  • Finally, to read the file name of our installation package to assist with user-to-device association.

Full Disk Access via MDM Policy Deployment

Information and policies can be found in our documentation.

If you need assistance with these changes, please reach out to Support. Otherwise, we look forward to sharing more about the new features coming soon to Kolide in the next couple of months!

Share this story:

More articles you
might enjoy:

Inside Kolide
How to Run Osqueryi With Kolide Launcher Tables
Fritz Ifert-Miller
Inside Kolide
How We Securely Autoupdate Osquery at Kolide
How to Manage Osquery With Kolide Launcher and Fleet
Watch a Demo
Watch a Demo