Skip to main content
Solved

Extension Attribute Script

  • September 9, 2026
  • 7 replies
  • 209 views

Forum|alt.badge.img+4

I am trying to create a EA to report the status of the the following key in the Clients.plist.  This is what I have so far but it is not reporting properly.  Any help is appreciated.  TY

 

#!/bin/bash

ABSlocationServices=$(sudo defaults read /var/db/locationd/clients.plist 2C4E4FD5-F029-XXXX-XXXX-XXXXXXXXXXXX:icom.absolute.ctesservice.ase:Authorized)

if [[ "$ABSlocationServices" == "True" ]]; then

    echo "<result>Enabled</result>"
else
    echo "<result>Disabled</result>"
fi

Best answer by mike_prather

#! /usr/bin/env zsh

LoggedinUser=$(/usr/bin/stat -f%Su /dev/console)

userGUID=$(dscl . -read "/Users/${LoggedinUser}" GeneratedUID | awk '{ print $2 }')

authStatus=$(defaults read /var/db/locationd/clients.plist $userGUID:icom.absolute.ctesservice.ase: | grep Authorized | awk -F ' = ' '{ print $2}')

if [[ ${authStatus} == "1;" ]]; then
Result="Enabled by user"
elif [[ ${authStatus} == "0;" ]]; then
Result="Disabled by user"
else
Result="Not set"
fi

echo "<result>$Result</result>"

 

7 replies

agungsujiwo
Forum|alt.badge.img+10
  • Valued Contributor
  • September 10, 2026

Have you tried running this script in Terminal
sudo defaults read /var/db/locationd/clients.plist 2C4E4FD5-F029-XXXX-XXXX-XXXXXXXXXXXX:icom.absolute.ctesservice.ase:Authorized

If so, what result did you get.

 


Forum|alt.badge.img+4
  • Author
  • Contributor
  • September 10, 2026

I get back
The domain/default pair of sudo defaults read /var/db/locationd/clients.plist 2C4E4FD5-F029-XXXX-XXXX-XXXXXXXXXXXX:icom.absolute.ctesservice.ase:Authorized) does not exist.

I know it exist as I can pipe out the results of that file but it is a system hidden file.

I am trying to report on  the  Authorized = True or False line ,  below.

 2C4E4FD5-F029-XXXX-XXXX-XXXXXXXXXXXX:icom.absolute.ctesservice.ase: = Dict {
        ReceivingLocationInformationTimeStopped = 810646720.000000
        BundleId = com.absolute.ctesservice.ase
        LocationTimeStopped = 810651648.000000
        PluginBundleIds = Array {
        }
        BundlePath = /Library/Application Support/Absolute/CTES/Components/HDC/Absolute Secure Endpoint.app
        ClientStorageToken = 
        Registered = true
        Executable = /Library/Application Support/Absolute/CTES/Components/HDC/Absolute Secure Endpoint.app/Contents/MacOS/Absolute Secure Endpoint
        Requirement = identifier "com.absolute.ctesservice.ase" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "8462WEET47"
        Authorized = true
    }


ErnieFy
Forum|alt.badge.img+6
  • New Contributor
  • September 10, 2026

defaults read will just read the domain (plist) and key (GUID string). The result can be a long list of data. 

The script will not need sudo.

Look for the string being present. Additionally make a statement in case the app is not installed and do not evaluate. Gave an example below.

#!/bin/zsh

if [[ ! -e "/Applications/Absolute/Installed.app" ]]; then
    echo "<result>Absolute not installed</result>"
    exit 0
fi

appAuthorized=$( defaults read /var/db/locationd/clients.plist 2C4... 2>/dev/null | grep "Authorized = 1" )

if [[ $appAuthorized = "    Authorized = 1;" ]]; then
    echo "<result>Enabled</result>"
    exit 0
else
    echo "<result>Disabled</result>"
    exit 0
fi

exit 0


mike_prather
Forum|alt.badge.img+3
  • New Contributor
  • Answer
  • September 23, 2026
#! /usr/bin/env zsh

LoggedinUser=$(/usr/bin/stat -f%Su /dev/console)

userGUID=$(dscl . -read "/Users/${LoggedinUser}" GeneratedUID | awk '{ print $2 }')

authStatus=$(defaults read /var/db/locationd/clients.plist $userGUID:icom.absolute.ctesservice.ase: | grep Authorized | awk -F ' = ' '{ print $2}')

if [[ ${authStatus} == "1;" ]]; then
Result="Enabled by user"
elif [[ ${authStatus} == "0;" ]]; then
Result="Disabled by user"
else
Result="Not set"
fi

echo "<result>$Result</result>"

 


pete_c
Forum|alt.badge.img+16
  • Honored Contributor
  • September 23, 2026
#!/bin/bash

uuid=$(
ioreg -rd1 -c IOPlatformExpertDevice |
awk -F'"' '/IOPlatformUUID/{print $4}'
)

if [[ -z "$uuid" ]]; then
echo "<result>Unavailable</result>"
exit 0
fi

plist="/var/db/locationd/Library/Preferences/ByHost/com.apple.locationd.${uuid}.plist"

if [[ ! -f "$plist" ]]; then
echo "<result>Unavailable</result>"
exit 0
fi

status=$(plutil -p /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd.${uuid}.plist | awk '/LocationServicesEnabled/ { print $NF }')

case "$status" in
1|true|TRUE|yes)
result="Enabled"
;;
0|false|FALSE|no)
result="Disabled"
;;
*)
result="Unavailable"
;;
esac

echo "<result>${result}</result>"

Works on macOS 27.


mike_prather
Forum|alt.badge.img+3
  • New Contributor
  • September 23, 2026

The defaults read approach for checking global Location Svcs enablement still works too: 
 

/usr/bin/defaults read /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd LocationServicesEnabled

 


Forum|alt.badge.img+4
  • Author
  • Contributor
  • September 29, 2026
#! /usr/bin/env zsh

LoggedinUser=$(/usr/bin/stat -f%Su /dev/console)

userGUID=$(dscl . -read "/Users/${LoggedinUser}" GeneratedUID | awk '{ print $2 }')

authStatus=$(defaults read /var/db/locationd/clients.plist $userGUID:icom.absolute.ctesservice.ase: | grep Authorized | awk -F ' = ' '{ print $2}')

if [[ ${authStatus} == "1;" ]]; then
Result="Enabled by user"
elif [[ ${authStatus} == "0;" ]]; then
Result="Disabled by user"
else
Result="Not set"
fi

echo "<result>$Result</result>"

 

This one worked as expected.  Thank you.