If you use an MDM tool to deploy the macOS ControlUp for Desktops Agent, use the following configuration profiles to grant permissions to the Agent and prevent prompts to the end user.
Jamf integration
If you use Jamf, you can use our Jamf integration to automatically upload the necessary configuration profiles and insallation scripts.
Download
| File | Display Name | Purpose |
|---|---|---|
TenantInfo.mobileconfig |
ControlUp Tenant Information | Delivers tenant URL, registration code, and device group so the agent can register with the ControlUp tenant |
Background.mobileconfig |
ControlUp Allow in Background | Lets ControlUp launch daemons/agents run in the background without user-facing "Background items added" prompts |
RemoteShellFullDisk.mobileconfig |
ControlUp Remote Shell Full Disk Access permission | Grants Full Disk Access to CoreAgent and UserAgent for Remote Shell commands and log/diagnostics collection |
RemoteControl.mobileconfig |
ControlUp Remote Control Permissions | Grants Accessibility silently and allows standard users to self-approve Screen Recording and Input Monitoring for Remote Control |
RemoteControlFullDisk.mobileconfig |
ControlUp Remote Control Full Disk Access permission | Grants Full Disk Access to the Remote Control widget and ScreenCapture app for file transfer and clipboard features |
FileBrowserFullDisk.mobileconfig |
ControlUp File Browser Full Disk Access permission | Grants Full Disk Access to the File Browser app so it can list/read TCC-protected folders |
WifiMonitorFullDisk.mobileconfig |
ControlUp WiFiMonitor Full Disk Access permission | Grants Full Disk Access to the WiFi Monitor app for reading Wi-Fi diagnostics and protected system logs |
NetworkFilterExtension.mobileconfig |
ControlUp Network Filter System Extension | Allows the ControlUp network system extension to load without user approval (must precede NetworkFilter) |
NetworkFilter.mobileconfig |
ControlUp Network Filter Capture Permissions | Activates the ControlUp socket-level network filter |
WebWatcherSafari.mobileconfig |
ControlUp WebWatcher → Safari AppleEvents | Allows ControlUp processes to send Apple Events to Safari so WebWatcher can read the active tab |
WebWatcherChrome.mobileconfig |
ControlUp WebWatcher → Chrome AppleEvents | Allows ControlUp processes to send Apple Events to Chrome so WebWatcher can read the active tab |
SurveyToaster.mobileconfig |
ControlUp Survey Notification Permission | Pre-approves banner/sound notifications for the Survey Toaster (User Sentiment/Surveys module) |