Allow Apps in Security & Privacy -> Privacy -> Accessibility in Mojave (Bomgar)

dennisnardi
Contributor

Has anyone figured out an automated way to add apps to the System Preferences -> Security & Privacy -> Privacy -> Accessibility section in Mojave to allow them to control the computer?

We use Bomgar in my environment for remote support, and are running into a less than ideal interaction with Mojave. Users are prompted to allow the Bomgar app to control the computer, but users can only do that if they have administrative privileges, which not many people have in my environment.

I contacted Bomgar about this, and they said it's expected due to security changes Apple made and there's no way around this with their software. I contacted Jamf as well and they told me they were unaware of a way to add an app to this section automatically. I've tried and it does not appear I can grant users the ability to modify this section of System Preferences if they don't have admin privileges, like I can other sections.

I'm hoping someone else may have ideas on this.

2 ACCEPTED SOLUTIONS

sshort
Valued Contributor

check out Jamf's tool to create a Privacy Preferences Policy Control profile and upload to your JSS. You'll want to add Bomgar to the accessibiltiy section, then add an AppleEvent that allows Bomgar to control System Preferences.

You can check out my TeamViewer profile as an example, that's essentially what you'll want, just substitute with Bomgar.

View solution in original post

DBrowning
Valued Contributor II

Yes @dennisnardi that is expected. 10.7.1 does not yet have a GUI for the PPPC Payload. Once the GUI is put into code, you will see the payload options on the screen.

View solution in original post

41 REPLIES 41

benducklow
Contributor III

@tvargas - perhaps your question may asked in a different thread, but in short, yeah, I believe you need to create a Configuration Profile with a Approved Kernel Extensions payload to whitelist the app..

romanne3
New Contributor

@tvargas

You can use this to find the kext. Link for Kext excel sheet
Then make a config profile with the Team ID. Try with that