macOS Support & Elevated Sessions
Learn how to elevate your macOS user credentials to gain higher levels of access and functionality on your device in this informative session.
Table of Contents
Overview
The AutoElevate macOS agent lets technicians temporarily elevate a user's account from Standard to Administrator on a Mac. The user asks from the AutoElevate menu-bar app, the request appears in the Admin Portal, and a technician approves or denies it. An approved session lasts for the time the technician chooses, so users can finish admin-level tasks without holding permanent admin rights.
Supported systems: the AutoElevate macOS agent is designed for and supported on macOS 14 (Sonoma) or later.
Install the macOS Agent
Installation is covered in full in macOS Agent Installation. In short:
- From the Admin Portal, go to Settings → General Info.
- Under Mac Agent, click Download to download the PKG file.
- For a manual installation, run the PKG and enter your License Key, Company Name and Location Name when prompted.
- To install through your RMM tool, go to Companies and click View next to the company. Open View Installer Information next to the location, then click For Mac Installation → Copy Command. This is the recommended method for anything beyond a handful of machines.
No portal setting needs to be enabled first, and Addigy is not required. Once installed, the Mac appears on the Computers grid alongside your Windows machines, identified by its Platform column.
Note: UAC settings, Blocker Mode, Technician Mode and service-restart actions apply to Windows devices only. Set Elevation Mode does now apply to Macs — it belongs to application elevation rather than to sessions, and is covered in Rule-Based Application Elevation on macOS (Beta).
How Elevated Sessions Work
An approved session gives the user administrator permissions on their account for the time the technician selected. Access is not limited to a single application or installation, and approving a session does not create a rule — every session request is decided on its own.
Looking for rule-based application elevation? Approving an application ahead of time, so that it elevates without a live request, is a separate capability — see Rule-Based Application Elevation on macOS (Beta). A rule elevates one application rather than the account, so the user stays a standard user, where a session grants account-level administrator rights for its duration. It is available on the beta agent channel only and does not change how the sessions described here behave.
The session clock starts when the technician approves the request, not when the user's Mac receives the approval. If the Mac is offline or asleep at that moment, some or all of the session time may pass before the user can use it.
When the session reaches its time limit, the account returns to Standard and the menu-bar app shows a notice. A session ended early by the user or a technician ends without that notice.
End-User Instructions
Standard users request temporary admin privileges from the AutoElevate menu-bar app:
- Click the AutoElevate fox icon in the macOS menu bar.
- In Request Admin Access, enter an explanation under What do you need to do?, then click Request.
- The panel displays Awaiting approval. If you no longer need access, click Withdraw Request.
- Once admin access starts, the panel shows how much time is left. Click End Session to finish early.

If the request is denied, the panel displays Not approved. Nothing changed.
When the session reaches its time limit, the panel displays a notice. This notice is not shown when you or a technician ends the session early.
Technician Instructions
Approving or denying a request
- When a pending request arrives, open the Requests grid in the Admin Portal and click the eye icon to review it. Elevated Session requests show a Request Type of Session.
- To approve, click Approve, then select how long the user will have admin privileges. Choose 1, 2, 3, 4 or 5 minutes, or 10 to 60 minutes in 5-minute increments.
- To deny, click Deny.
Note: The session time starts when the technician approves the request. If the Mac is offline or asleep, some or all of that time may pass before it receives the approval.
Note: Requests still served through the Addigy integration have a floor of 10 minutes — the shorter options are hidden, because the server rejects an Addigy approval below that. Requests served by the AutoElevate agent can use the full list.
Viewing or cancelling a session
- Open the Computers grid and click the eye icon on the Mac to open its Computer details.
- Go to Elevated Sessions to see the Mac's session history and any session in progress.
- To end a session early, select it and choose Cancel from the Actions menu.
Role Permissions
The following controls are available for macOS Elevated Sessions in the Admin Portal:
- Administrator, Downstream Admin, Technician (Level 2) and Technician (Level 3) — view, approve, deny and cancel sessions.
- Technician (Level 1) and Read Only — view sessions. The Approve, Deny and Cancel controls are not shown.
Note: Company Access limits which companies a user can work with. For the full role matrix, see Web Admin Portal Overview.
Elevated Session Activity Logs
The agent writes a log for each elevated session. To open activity logs from the macOS agent, you will need administrator access on the Mac:
- Go to
/private/var/log/temp-admin. The folder is hidden in Finder — press ⌘ + Shift + . to show hidden files, and again to hide them when you are done. - Copy the .tar.gz file to a folder you can work in, then double-click it to extract.
- Open the extracted .log file in TextEdit or another text viewer.
Note: Logs are generated after the session ends and may take a little time to appear. The files are owned by root and readable by administrators. They contain selected system-log entries and session metadata, not a complete transcript of the user's actions.
Existing Addigy Customers
Addigy is not required to install or run the macOS agent. If your organization already uses the Addigy integration, the setting that manages it is Settings → Agent Customizations & Behavior → Legacy Addigy Integration (previously macOS Support).
Uninstalling AutoElevate leaves the Addigy agent and the Mac's MDM enrollment in place — see Uninstallation below.
Current Features
The following are available today for macOS Elevated Sessions:
- Pending request handling, with approve or deny
- Request explanation field
- End-user notifications on approval, denial and session end, in the menu-bar app
- Portal view of the Elevated Sessions list (Computer details → Elevated Sessions). The captured session log itself is still read from the Mac — see Elevated Session Activity Logs above
- Notifications in the Admin Portal and the mobile app, and mobile app support
- Email Adapter support to receive emails when requests are made
- Ticketing system integrations
- Move and Delete actions for Mac computers
- Auto-updating agent (see macOS Agent Installation → Keeping Agents Updated)
Still in progress:
- Request security checks
- Remove Admin Privileges — currently a Windows-only action
- Portal view of the activity captured during a session; the session list is in the portal today, the captured log contents are still retrieved from the Mac
- Application elevation on the stable agent channel, and the request flow for an application that no rule matches — see Rule-Based Application Elevation on macOS (Beta)
Uninstallation
Remove the agent from the Admin Portal (delete the computer on the Computers grid) or from the Mac as an admin:
sudo "/Library/Application Support/CyberFOX/AutoElevate/uninstall"Uninstalling AutoElevate leaves the Addigy agent and the Mac's MDM enrollment in place. AutoElevate first removes the temporary admin privileges it granted; if those privileges cannot be removed, the uninstall stops. For the full procedure, including bulk removal, see macOS Agent Installation → Uninstallation.
Hostnames
If you set granular outbound firewall rules for client networks, allow outbound traffic on port 443 to the hostname the macOS installer downloads from:
apollo.autoelevate.comThis is the host in the Mac install command the Admin Portal generates, and it is already one of the standard AutoElevate service hostnames the agent uses (api.autoelevate.com, api-long.autoelevate.com, msp.autoelevate.com, apollo.autoelevate.com, juno.autoelevate.com, mercury.autoelevate.com, voyager.autoelevate.com, orion.autoelevate.com). The complete, maintained list is in Firewall Whitelisting (AutoElevate). AutoElevate itself does not require any Addigy hostnames.
Troubleshooting
Viewing diagnostic logs
Open Console and filter by the subsystem com.cyberfox.AutoElevate. To view the last 15 minutes of logs from Terminal, run:
sudo /usr/bin/log show --last 15m --style compact \
--predicate 'subsystem == "com.cyberfox.AutoElevate"'Note: Some diagnostic details may be hidden for privacy. For logs from an elevated session, see Elevated Session Activity Logs above.
Stopping and starting the agent manually
sudo launchctl bootout system "/Library/LaunchDaemons/com.cyberfox.AutoElevate.plist"
sudo launchctl bootstrap system "/Library/LaunchDaemons/com.cyberfox.AutoElevate.plist"The Mac does not register after installation
- Missing License Key, Company Name or Location Name: during a new installation, the installer asks you to enter any missing information. Installation cannot complete without these values. If you are deploying through an RMM tool, use the Mac installation command from the Admin Portal.
- Wrong License Key: installation may finish, but the agent cannot register with AutoElevate if the license key is invalid. Re-run the installer with the correct key. Check the diagnostic logs if registration still fails.
"User info could not be sent"
Just after a user logs in, a request can fail with this message. The agent reports which account is at the console on its periodic state ping, so for a short window immediately after login the server does not yet know who is signed in and cannot attach a request to them. Wait for the next check-in and try again. The interval is set by the server, so the wait is typically under a minute but is not a fixed value.

Security Notes
- An approved session is account-level admin access. For its duration the user can do anything a local administrator can, not only the task described in the request. Keep durations short and review session history in Computer details → Elevated Sessions.
- Sessions do not create rules. Each request is decided individually; approving one does not grant future access.
- Session time is counted from approval, so a request approved while the Mac is offline or asleep may yield little or no usable time.
- Activity logs are admin-only and contain selected system-log entries rather than a full record of the user's actions.