MacOS Agent Change Log
Key
- + New Feature
- * Bug Fix
- - General Change
Version 3.5.1
- * Passwords that begin with "-" or "[" can now be set. macOS read them as a command option and did nothing, which looked like "only simple passwords work". Passwords are now passed to macOS in a way that avoids this for password resets, account creation and the managed admin account
- - There is no restriction on which characters a password may contain. The only thing refused is a line break
- * Resetting the password of an account without a secure token (below macOS 26) now checks the new password actually works before reporting success
- * Command output containing accented or other non-ASCII characters is no longer discarded. Previously a single accented character could make a user appear to have no secure token, or make the Users tab come back empty
Version 3.5.0
- + Managed admin account: the agent creates a hidden administrator (_btadmin) holding a secure token on each Mac. Apple requires a secure token holder to authorise changes to other token holders, and from macOS 26 this is the only way local user management works at all
- + The managed admin's password is generated on the Mac itself, never sent from the server, and is rotated every 90 days or on demand
- + Secure token setup by a technician supplying an existing token holder's credentials, or by prompting the logged-in user for their own password. Neither credential is stored or logged
- + Managed admin status (secure token, token holders, rotation due) is reported on every check-in
- + The agent reports whether it has Full Disk Access. Full Disk Access is required to delete an account with a secure token; all other user management works without it
- + New Execute Shell Command task: runs the command line through /bin/sh, so quoting, pipes, && and redirection work. stdout, stderr and the exit code are reported separately, with a configurable timeout (1-3600 seconds, default 60) and an option to run as the logged-in user. Matches the Linux and Windows agents
- * Password resets, deletions and account creation now work on current macOS versions, including token-holding accounts, by authenticating as the managed admin
- * New accounts get a secure token when created, so they can unlock FileVault and approve software updates. If an account ends up without one, the job result says so
- * Deleting a user now works on macOS 26.1 and later. A deletion that macOS would refuse is stopped before it starts, so the user's home folder is no longer removed while the account is left behind
- * "Require a new password at next login" now works reliably across macOS versions
- * Task results were sometimes not matched to their task on the server, so results from collection jobs were lost. Fixed
- * A password check can no longer report a password as valid when the check itself failed to run
- - Passwords are never written to the agent log or returned in task results
- - Minimum supported version is now macOS 11.0 Big Sur
- - Signed with the Dalegroup Developer ID certificate
- - Uninstalling the agent leaves the managed admin account in place, so a Mac is never left without a secure token holder
Version 3.3.1
- * Fixed error with new standard users not getting the specified password.
- - Cannot change password for locally created users due to Apple's secure token. This now gives a more helpful error message.
- + Deleting a locally added user works but it may not completely remove the user directory until after a reboot.
- + Added ability to request a password reset. This requires a reboot to trigger it. Only tested manually, but works with locally created users.
Version 3.3
- + Added ability to list local users and groups.
- + Added ability to modify users: password, enabled status, admin status.
- + Added ability to delete users (not available on dashboard yet).
Version 3.2
- + For M series laptops, GPU and CPU temp can now be reported
Version 3.1
- + Build for Apple Silicon (M series chips) as well as Intel.
- + Added services commands: get_services, restart_service, stop_service, start_service.
- + Added Network tab support
- + Added Storage tab support
- - Increase minimum target to macOS 10.15.
- - Improved software update check to report system updates only.
- - Updated the free memory check which was not correct on modern Macs due to change in page size.
----------------------
For Mac OS 10.14.3 and lower you also need to install the Swift 5 Runtime Support for Command Line Tools (We recommend you install this first but you can also install afterwards)
Version 2.0.1
- + Split out OS info (OS Name & OS Build) to allow for better reporting
- + Create local admin account task supported
- * Fixes to agent reliability
Version 2.0.0
- + First release of native MacOS agent
Added Monday 10th August 2020 Last modified Thursday 24th September 2026