The power of collaboration: an admin-rights audit trail for every Mac
Blog post from Fleet
SAP Privileges 2.6.0, the Mac Admins osquery extension, and Fleet’s agent added coordinated support for auditing macOS administrator-rights changes within roughly a week. Privileges enables temporary, self-service elevation for standard users and now uses Apple’s Endpoint Security framework to record every administrator grant or removal, including the responsible process, providing more detail than earlier generic change detection. Administrators can access this history locally through PrivilegesCLI, while the new privileges_events osquery table makes the same data available as SQL-queryable rows across an entire fleet, including changes made outside Privileges through System Settings or scripts. Deployment requires enabling the Privileges system extension and granting Full Disk Access, ideally through MDM configuration profiles, while existing osquery apps and system_extensions tables can report the app’s installation, version, and extension status.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.