Full Disk Access (PPPC)
Last updated 7 days ago
Starting with macOS Ventura (13), updater apps need an additional privacy control to allow them to update or delete other apps and SystemPolicyAllFiles needs to be granted. The Catalog Agent and Catalog App (or parent processes) need this permission to be able to update all types of apps.
Create Configuration Profile
Catalog Agent
macOS 13 and later
anchor apple generic and identifier "nl.root3.catalog" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists / or certificate 1[field.1.2.840.113635.100.6.2.6] / exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "98LJ4XBGYK")Privileged Helper Tool
anchor apple generic and identifier "nl.root3.catalog.helper" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists / or certificate 1[field.1.2.840.113635.100.6.2.6] / exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "98LJ4XBGYK")Example
PPPC - Full Disk Access - App Catalog.mobilecon
2.3 KB
Due to an issue on the documentation platform, example Configuration Profiles are renamed from .mobileconfig to .mobilecon. Please change the extension after you downloaded the profile