PPPC Settings for ActivTrak

gloper1977
Contributor

I have been tasked with creating a Policy to push out ActivTrak to MacBooks.  It installed just fine the problem I'm running into is it asks the user to grant Accessibility access.  Obviously with ActivTrak being a tracking software to see what our employees are doing we want to push it out silently and we don't want to depend on the user to grant access.

This is the first PPPC Configuration Profile I've attempted.  It says completed on the machine but it isn't setting the access that ActivTrak needs. Below are the settings I created for the PPPC payload.  I got the CodeRequiment with the codesign -display command.  

I also added an Extension payload of com.bgrove.scthost not sure if this is necessary.  Any help would be appreciated.

Identifier: com.bgrove.scthost

Identifier Type: Bundle ID

Code Requirement: identifier "com.bgrove.scthost" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = B3MJ3FU6NZ

APP OR SERVICE     ACCESS

Accessibility              Allow

 

2 REPLIES 2

JennyTrower
New Contributor

Hi, did you ever find a solution to push ActivTrak silently?  Ive been tasked with the same and can't stop notification coming up about app needing permission.

gloper1977
Contributor

Nope because of Apple's strict security on their devices it isn't possible we just gave up on it