MacOS Full Disk Access
closed
D
Dusty'la Auer'la
Per Huntress KB, full disk access is not needed in most scenarios, but it is needed if any investigations/verifications lead to user data locations.
I am requesting if it is possible to build into the Mac installer that Huntress would prompt for disk access. This would ensure all of our Mac agents are configured correctly and less likely to miss this on agent onboardings.
This would look similar to the attached CW Control install on MacOS.
Thomas Reed (Huntress)
closed
Wizard has shipped
J
James Stull
Thomas Reed (Huntress) this is wonderful, is their a way for us to trigger the wizard on already deployed agents just to make sure everything is setup properly?
Thomas Reed (Huntress)
James Stull You can see the status of your Mac agents directly in the portal, for all endpoints. If you click the link for endpoints not set up, it will list them all and their status (ie, what's been done and what still needs to be done). This is probably easier than opening the wizard on each one.
That said, at the moment, we haven't provided a way to pop the wizard open on an endpoint remotely, though that's something we plan to add. However, any remote management tools you have that would allow you to open an app on an endpoint would work - just open the Huntress app - or do the same manually if you're sitting in front of the machine.
If you have shell access to a machine, one way you could pop it open remotely is to run
open /Applications/Huntress.app
.J
James Stull
Thomas Reed (Huntress) Yeah my thought was just to have the end users walk through it, then I wouldn't have to on multiple devices. I really wish we could auto install it like we do on Windows. But Apple likes to make things a lot harder in the name of security.
Thomas Reed (Huntress)
James Stull Yup, we definitely want to support that use case. We didn't want to pop this open automatically on install, as that could result in a flood of e-mails from folks who don't know what Huntress is asking, "What is this popup? Is it malware?" :D
We'd like to provide a mechanism where you can kick this off after alerting your users/customers. We've also discussed the possibility of adding a way for you to add your own branding, to make it less scary for the end user.
J
James Stull
Thomas Reed (Huntress) Perhaps in the install script, if we could add a launch process in it to kick off the wizard with either a command line argument or automatically, ie: it checks permissions and if permissions are not correct then launches the wizard.
Love the idea of allowing us to brand the agent. It would be nice if we could add our contact info, logo, etc.
D
Dusty'la Auer'la
Is there any update on development for this? Per a June conversation, this was given a rough timeline of ~6 months.
Thomas Reed (Huntress)
Dusty'la Auer'la: I know it's been a while, but we've prioritized this and a new configuration wizard is rolling out now. When you get it, opening the Huntress app in the Applications folder will launch the wizard, and if any steps are needed it will walk you through what needs to be done.
A
Annie Ballew
Thank you for adding your input! This is definitely something we're looking into. Would love to explore full permissions workflow with you as well, not just as part of the agent installation but also in verifying the health/readiness across agents.