NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • Contact Us
English (US)
NL Dutch
FR French
IT Italian
JP Japanese
DE German
US English (US)
ES Spanish
  • Home
  • AutoElevate Knowledgebase
  • New to AutoElevate? START HERE

macOS Support & Elevated Sessions

Learn how to elevate your macOS user credentials to gain higher levels of access and functionality on your device in this informative session.

Written by Owen Parry

Updated at September 12th, 2026

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

  • AutoElevate Knowledgebase
    New to AutoElevate? START HERE AutoElevate Features & Troubleshooting Managing Rules in AutoElevate Integrations for AutoElevate AutoElevate FAQ Selling AutoElevate
  • CyberFOX Password Manager Knowledgebase
    Using CyberFOX Password Manager Administrating CyberFOX Password Manager Legacy Password Boss
  • CyberFOX DNS Filtering
    Getting Started with DNS Filtering DNS Filtering Concepts Network Requirements for DNS Filtering DNS Filtering Company and Location Setup Managing your DNS Filtering Policies Using Roaming Clients for DNS Filtering DNS Filtering Reports & Logs DNS Filtering Troubleshooting
  • Marketing Toolkit
    MSP Marketing & Education Toolkit CyberFOX Brand Guidelines
  • Changelogs for Autoelevate and Password Boss
  • CyberFOX Product Roadmap
  • Current Status
+ More

Table of Contents

Overview Install the macOS Agent How Elevated Sessions Work End-User Instructions Technician Instructions Approving or denying a request Viewing or cancelling a session Role Permissions Elevated Session Activity Logs Existing Addigy Customers Current Features Uninstallation Hostnames Troubleshooting Viewing diagnostic logs Stopping and starting the agent manually The Mac does not register after installation "User info could not be sent" Security Notes Related Articles

Overview


The AutoElevate macOS agent lets technicians temporarily elevate a user's account from Standard to Administrator on a Mac. The user asks from the AutoElevate menu-bar app, the request appears in the Admin Portal, and a technician approves or denies it. An approved session lasts for the time the technician chooses, so users can finish admin-level tasks without holding permanent admin rights.

Supported systems: the AutoElevate macOS agent is designed for and supported on macOS 14 (Sonoma) or later.

 

 

Install the macOS Agent


Installation is covered in full in macOS Agent Installation. In short:

  • From the Admin Portal, go to Settings → General Info.
  • Under Mac Agent, click Download to download the PKG file.
  • For a manual installation, run the PKG and enter your License Key, Company Name and Location Name when prompted.
  • To install through your RMM tool, go to Companies and click View next to the company. Open View Installer Information next to the location, then click For Mac Installation → Copy Command. This is the recommended method for anything beyond a handful of machines.

No portal setting needs to be enabled first, and Addigy is not required. Once installed, the Mac appears on the Computers grid alongside your Windows machines, identified by its Platform column.

Note: UAC settings, Blocker Mode, Technician Mode and service-restart actions apply to Windows devices only. Set Elevation Mode does now apply to Macs — it belongs to application elevation rather than to sessions, and is covered in Rule-Based Application Elevation on macOS (Beta).

 

How Elevated Sessions Work


An approved session gives the user administrator permissions on their account for the time the technician selected. Access is not limited to a single application or installation, and approving a session does not create a rule — every session request is decided on its own.

Looking for rule-based application elevation? Approving an application ahead of time, so that it elevates without a live request, is a separate capability — see Rule-Based Application Elevation on macOS (Beta). A rule elevates one application rather than the account, so the user stays a standard user, where a session grants account-level administrator rights for its duration. It is available on the beta agent channel only and does not change how the sessions described here behave.

 

The session clock starts when the technician approves the request, not when the user's Mac receives the approval. If the Mac is offline or asleep at that moment, some or all of the session time may pass before the user can use it.

When the session reaches its time limit, the account returns to Standard and the menu-bar app shows a notice. A session ended early by the user or a technician ends without that notice.

 

End-User Instructions


Standard users request temporary admin privileges from the AutoElevate menu-bar app:

  1. Click the AutoElevate fox icon in the macOS menu bar.
  2. In Request Admin Access, enter an explanation under What do you need to do?, then click Request.
  3. The panel displays Awaiting approval. If you no longer need access, click Withdraw Request.
  4. Once admin access starts, the panel shows how much time is left. Click End Session to finish early.

AutoElevate menu-bar panel before a request, showing Request Admin Access and This Mac

If the request is denied, the panel displays Not approved. Nothing changed.

When the session reaches its time limit, the panel displays a notice. This notice is not shown when you or a technician ends the session early.

 

Technician Instructions


Approving or denying a request

  1. When a pending request arrives, open the Requests grid in the Admin Portal and click the eye icon to review it. Elevated Session requests show a Request Type of Session.
  2. To approve, click Approve, then select how long the user will have admin privileges. Choose 1, 2, 3, 4 or 5 minutes, or 10 to 60 minutes in 5-minute increments.
  3. To deny, click Deny.

Note: The session time starts when the technician approves the request. If the Mac is offline or asleep, some or all of that time may pass before it receives the approval.

Note: Requests still served through the Addigy integration have a floor of 10 minutes — the shorter options are hidden, because the server rejects an Addigy approval below that. Requests served by the AutoElevate agent can use the full list.

Viewing or cancelling a session

  1. Open the Computers grid and click the eye icon on the Mac to open its Computer details.
  2. Go to Elevated Sessions to see the Mac's session history and any session in progress.
  3. To end a session early, select it and choose Cancel from the Actions menu.

 

Role Permissions


The following controls are available for macOS Elevated Sessions in the Admin Portal:

  • Administrator, Downstream Admin, Technician (Level 2) and Technician (Level 3) — view, approve, deny and cancel sessions.
  • Technician (Level 1) and Read Only — view sessions. The Approve, Deny and Cancel controls are not shown.

Note: Company Access limits which companies a user can work with. For the full role matrix, see Web Admin Portal Overview.

 

Elevated Session Activity Logs


The agent writes a log for each elevated session. To open activity logs from the macOS agent, you will need administrator access on the Mac:

  1. Go to /private/var/log/temp-admin. The folder is hidden in Finder — press ⌘ + Shift + . to show hidden files, and again to hide them when you are done.
  2. Copy the .tar.gz file to a folder you can work in, then double-click it to extract.
  3. Open the extracted .log file in TextEdit or another text viewer.

Note: Logs are generated after the session ends and may take a little time to appear. The files are owned by root and readable by administrators. They contain selected system-log entries and session metadata, not a complete transcript of the user's actions.

 

Existing Addigy Customers


Addigy is not required to install or run the macOS agent. If your organization already uses the Addigy integration, the setting that manages it is Settings → Agent Customizations & Behavior → Legacy Addigy Integration (previously macOS Support).

Uninstalling AutoElevate leaves the Addigy agent and the Mac's MDM enrollment in place — see Uninstallation below.

 

Current Features


The following are available today for macOS Elevated Sessions:

  • Pending request handling, with approve or deny
  • Request explanation field
  • End-user notifications on approval, denial and session end, in the menu-bar app
  • Portal view of the Elevated Sessions list (Computer details → Elevated Sessions). The captured session log itself is still read from the Mac — see Elevated Session Activity Logs above
  • Notifications in the Admin Portal and the mobile app, and mobile app support
  • Email Adapter support to receive emails when requests are made
  • Ticketing system integrations
  • Move and Delete actions for Mac computers
  • Auto-updating agent (see macOS Agent Installation → Keeping Agents Updated)

Still in progress:

  • Request security checks
  • Remove Admin Privileges — currently a Windows-only action
  • Portal view of the activity captured during a session; the session list is in the portal today, the captured log contents are still retrieved from the Mac
  • Application elevation on the stable agent channel, and the request flow for an application that no rule matches — see Rule-Based Application Elevation on macOS (Beta)

 

Uninstallation


Remove the agent from the Admin Portal (delete the computer on the Computers grid) or from the Mac as an admin:

sudo "/Library/Application Support/CyberFOX/AutoElevate/uninstall"

Uninstalling AutoElevate leaves the Addigy agent and the Mac's MDM enrollment in place. AutoElevate first removes the temporary admin privileges it granted; if those privileges cannot be removed, the uninstall stops. For the full procedure, including bulk removal, see macOS Agent Installation → Uninstallation.

 

Hostnames


If you set granular outbound firewall rules for client networks, allow outbound traffic on port 443 to the hostname the macOS installer downloads from:

apollo.autoelevate.com

This is the host in the Mac install command the Admin Portal generates, and it is already one of the standard AutoElevate service hostnames the agent uses (api.autoelevate.com, api-long.autoelevate.com, msp.autoelevate.com, apollo.autoelevate.com, juno.autoelevate.com, mercury.autoelevate.com, voyager.autoelevate.com, orion.autoelevate.com). The complete, maintained list is in Firewall Whitelisting (AutoElevate). AutoElevate itself does not require any Addigy hostnames.

 

Troubleshooting


Viewing diagnostic logs

Open Console and filter by the subsystem com.cyberfox.AutoElevate. To view the last 15 minutes of logs from Terminal, run:

sudo /usr/bin/log show --last 15m --style compact \
  --predicate 'subsystem == "com.cyberfox.AutoElevate"'

Note: Some diagnostic details may be hidden for privacy. For logs from an elevated session, see Elevated Session Activity Logs above.

Stopping and starting the agent manually

sudo launchctl bootout system "/Library/LaunchDaemons/com.cyberfox.AutoElevate.plist"
sudo launchctl bootstrap system "/Library/LaunchDaemons/com.cyberfox.AutoElevate.plist"

The Mac does not register after installation

  • Missing License Key, Company Name or Location Name: during a new installation, the installer asks you to enter any missing information. Installation cannot complete without these values. If you are deploying through an RMM tool, use the Mac installation command from the Admin Portal.
  • Wrong License Key: installation may finish, but the agent cannot register with AutoElevate if the license key is invalid. Re-run the installer with the correct key. Check the diagnostic logs if registration still fails.

"User info could not be sent"

Just after a user logs in, a request can fail with this message. The agent reports which account is at the console on its periodic state ping, so for a short window immediately after login the server does not yet know who is signed in and cannot attach a request to them. Wait for the next check-in and try again. The interval is set by the server, so the wait is typically under a minute but is not a fixed value.

User info could not be sent alert

 

Security Notes


  • An approved session is account-level admin access. For its duration the user can do anything a local administrator can, not only the task described in the request. Keep durations short and review session history in Computer details → Elevated Sessions.
  • Sessions do not create rules. Each request is decided individually; approving one does not grant future access.
  • Session time is counted from approval, so a request approved while the Mac is offline or asleep may yield little or no usable time.
  • Activity logs are admin-only and contain selected system-log entries rather than a full record of the user's actions.

 

Related Articles


  • macOS Agent Installation
  • Rule-Based Application Elevation on macOS (Beta)
  • Firewall Whitelisting (AutoElevate)
  • Web Admin Portal Overview
  • AutoElevate Notify App for Mobile Devices
  • Client On-Boarding Guide
assistance apple

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Elevation Types
CyberFOX

PRACTICAL CYBERSECURITY FOR LEAN IT TEAMS

Platforms
  • Privileged Access Management
  • Password Management
  • DNS Filtering
  • SASE
Industry
  • Higher Education
  • K-12 Education
  • State and Local Government
  • Manufacturing
Company
  • About
  • Awards
  • Partnerships
  • Trust & Legal
  • Contact
  • Login
  • FAQ
  • Referral Program
  • Support
© 2026 CYBERFOX LLC ALL RIGHTS RESERVED | Privacy Policy | Terms of Service | Sitemap
Expand