Home / Companies / Fleet / Blog / Post Details
Content Deep Dive

The power of collaboration: an admin-rights audit trail for every Mac

Blog post from Fleet

Post Details
Company
Date Published
Author
Henry Stamerjohann
Word Count
1,370
Company Posts That Month
3
Language
-
Hacker News Points
-
Post removed?
No
Summary

SAP Privileges 2.6.0, the Mac Admins osquery extension, and Fleet’s agent added coordinated support for auditing macOS administrator-rights changes within roughly a week. Privileges enables temporary, self-service elevation for standard users and now uses Apple’s Endpoint Security framework to record every administrator grant or removal, including the responsible process, providing more detail than earlier generic change detection. Administrators can access this history locally through PrivilegesCLI, while the new privileges_events osquery table makes the same data available as SQL-queryable rows across an entire fleet, including changes made outside Privileges through System Settings or scripts. Deployment requires enabling the Privileges system extension and granting Full Disk Access, ideally through MDM configuration profiles, while existing osquery apps and system_extensions tables can report the app’s installation, version, and extension status.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.