Skip to content
  • There are no suggestions because the search field is empty.

🍏macOS: Granting necessary permissions to Safetica Client after installation

Learn how to grant the necessary permissions to Safetica Client after installing it on a macOS device.

❗This article applies only to devices with macOS.

In this article, you will learn more about:

 

 



Introduction: Two ways of granting permissions

After the successful installation of Safetica Client on a macOS device, certain permissions must be granted to the Safetica Client. You can do that either by installing our signed Apple Configuration Profile or manually.

❗Required for macOS: Grant permissions using Apple Configuration Profile. Without it, Safetica Client functionality on macOS cannot be guaranteed and may be limited.

Manual permission setup is unreliable and should only be used for testing or troubleshooting.

macOS 27 and newer: The Apple Configuration Profile no longer covers one permission. Apple removed the ability to grant Accessibility through a configuration profile, so on macOS 27 and newer, the user must grant this permission on the device, even when the profile is deployed correctly. It is needed only for blocking emails in the Mail app; all other permissions are still covered by the profile. See details below.

 

 


How to grant permissions to Safetica Client via a signed Apple Configuration Profile

Apple Configuration Profile contains all the system permissions required for Safetica Client to work correctly on macOS devices.

✍️You can download the Apple Configuration Profile signed by Safetica here.

For Microsoft Intune, use this unsigned Apple Configuration Profile.

❗Distribution via MDM only: Apple Configuration Profiles can only be distributed and installed on devices via MDM (Mobile Device Management).

 

To install an Apple Configuration Profile:

  1. Download the Apple Configuration Profile signed by Safetica here.
  2. Distribute the downloaded profile to macOS devices using your preferred MDM solution. You can find a list of MDM solutions here.
  3. (Optional) If Safetica Client is already installed on your devices, choose one of these options after distributing the profile:

           Option A: Restart the devices.

           Option B: Restart Safetica services on the devices using the Terminal. Run the following commands:

           sudo /Library/Application\ Support/Safetica/Tools/setup UnloadAllServices

           sudo /Library/Application\ Support/Safetica/Tools/setup LoadAllServices

           Tip: You may see Boot-out failed: 5: Input/Output error messages after running the UnloadAllService command. This is normal and can be ignored.

     4.  Install Safetica Client on the macOS device. Learn more about Safetica Client installation here.

     5.  Enable the Sensitive content found extension in the Mail app:
      1. In the Mail app , choose Mail > Settings, then click Extensions.
      2. In the list of Mail extensions, find the Sensitive content found extension.
      3. Enable it by selecting its checkbox.

         6.  On macOS 27 and newer: Grant the Accessibility permission to STUserApp on the device. The profile still grants Automation, but Accessibility must be granted by the user on the device. Apple no longer allows it to be granted through a configuration profile. See how to grant Accessibility to STUserApp in the manual section below.

      • Without the Accessibility permission, the email is evaluated and the user is warned, but they can send the email by confirming the system dialog. For full protection, the Accessibility permission must be granted.

      • macOS 26 and older: The configuration profile grants both permissions, so with the profile deployed, no dialog appears at all. There is nothing to do manually.

     

     

    MDM solutions

    ✍️If you need a free MDM solution, consider:

    • jumpcloud (free for up to 10 devices and users)

    Other MDM solutions you can use:

    ❗Enrollment into MDM solution and distribution of Apple Configuration Profiles may sometimes take a while. To speed things up, restart the affected devices in these situations:

    • After enrolling devices into the MDM solution.
    • After distributing new Apple Configuration Profiles to devices.

     

     


    How to grant permissions to Safetica Client manually (not recommended)

    ❗Required for macOS: Grant permissions using Apple Configuration Profile. Without it, Safetica Client functionality on macOS cannot be guaranteed and may be limited.

    Manual permission setup is unreliable and should only be used for testing or troubleshooting.

    For Safetica Client to work correctly on macOS devices, you need to:

    1. Allow Full Disk Access - required for file audit.

    2. Allow notifications - required for user notifications.

    3. Allow access to web browser data in Safari, Chrome, Opera, and Microsoft Edge - required for web audit (Safari, Chrome, Opera, and Microsoft Edge).

    4. Enable the Sensitive content found extension in Mail app - required for audit and protection of outgoing emails through the Mail app.

    5. Allow STUserApp - required for correctly auditing and blocking emails sent via Mail app.

    6. Install trusted certificate – required if you want to enable protection for emails sent via Microsoft Outlook.

    ❗After performing the steps above, you need to perform one of these options:

    Option A: Restart the devices.

    Option B: Restart Safetica services on the devices using the Terminal. Run the following commands:

    sudo /Library/Application\ Support/Safetica/Tools/setup UnloadAllServices

    sudo /Library/Application\ Support/Safetica/Tools/setup LoadAllServices

    Tip: You may see Boot-out failed: 5: Input/Output error messages after running the UnloadAllService command. This is normal and can be ignored.

     

    1.  Allow Full Disk Access

    Full Disk Access is crucial for the correct functioning of Safetica and needs to be allowed manually after Safetica Client is installed.

      a. Go to System preferences > Privacy & Security > Full Disk Access.

      b. You will see our services – STClassiTagger, STContentService, STCService, and STFileMonitor – easily recognizable by the Safetica logo.

      c. Switch their toggle to Allow. This will give these services Full Disk Access.

    ❗We strongly recommend not granting the permission to services you do not know or services that you are not specifically willing to grant the permission to.

     

    2.  Allow notifications

    After the successful installation of Safetica Client, a pop-up related to user notifications and alerts appears. Click Allow.

    Further options related to user notifications are available in System preferences > Notifications > STUserApp.

     

    3.  Allow access to web browser data in Safari, Chrome, Opera, and Microsoft Edge

    When you open the Safari, Chrome, Opera, and Microsoft Edge web browsers for the first time after installing Safetica Client, a pop-up appears. You must click Allow.

    ❗This pop-up will be displayed repeatedly in regular intervals when the user works with Safari, Chrome, Opera, or Microsoft Edge. They must always click Allow for web audit to work correctly.

    If web browser permissions are not granted, they will be requested automatically after every browser restart.

    This issue will not occur if you grant permissions to Safetica Client via the Apple Configuration Profile instead of manually.

     

    If you are having issues, you can check that permissions are granted correctly to Safari, Chrome, Opera, and Microsoft Edge in System preferences >Privacy & Security > Automation > STAppMonitor.

     

    4.  Enable the Sensitive content found extension in the Mail app

    ❗The Sensitive content found extension is only supported on macOS 12 and newer.

    1. In the Mail app , choose Mail > Settings, then click Extensions.

    2. In the list of Mail extensions available on your device, find the Sensitive content found extension.

    3. Enable it by selecting its checkbox.

    ❗To make email auditing and blocking policies work correctly, you must allow the STUserApp.

    Otherwise, users will be able to override blocked emails by clicking a Send anyway button in a dialog.

     

    5. Allow STUserApp

    To correctly audit and block emails sent via the Mail app, STUserApp needs two permissions:

      • Automation: Allow STUserApp in System Settings > Privacy & Security > Automation (> Privacy on older systems).
      • Accessibility: Allow STUserApp in System Settings > Privacy & Security > Accessibility (> Privacy on older systems).

    ❗Without these permissions, email blocking still works (the email is evaluated and the user is warned), but the user can override the block and send the email by confirming the system dialog. For full protection, both permissions must be granted.

    The Accessibility dialog has no Allow button. It offers only Open System Settings and Deny, so the permission cannot be granted from the dialog itself.

    To grant it:

      • Click Open System Settings in the dialog, or go to System Settings > Privacy & Security > Accessibility.
      • Find STUserApp in the list. If it is not there, see How STUserApp behaves based on Safetica Client version below.
      • Turn on the toggle next to it.
      • Confirm with Touch ID or your user password. An administrator password is not required.

    Granting Accessibility takes effect immediately. Granting Automation may not be reflected right away - if the device still reports the permission as missing, restart Safetica Client or log out and back in.

    ❗Until the permission is granted, the dialog appears again every time STUserApp starts, e.g., after Safetica Client restarts, after each login, and several times in a row while Safetica Client is being updated. Clicking Deny does not stop it; it only closes the current dialog. Once the permission is granted, the dialog stops appearing.

     

    How STUserApp behaves based on the Safetica Client version:

    Safetica Client 11.41.4 and newer: When a permission is missing, STUserApp asks for it with a system dialog shortly after the user logs in.

    Safetica Client versions older than 11.41.4: STUserApp may not appear in the Automation or Accessibility list until it has tried to block an email. If you do not see it, send a test email that violates a blocking policy - STUserApp should then appear in those sections.

    After allowing STUserApp, when the user sends an email that violates a blocking policy for the first time, 2 dialog will appear:

      • A dialog that lets the email be sent even though it should be blocked. The user must click Cancel.
      • A dialog asking to allow STUserApp. The user must click Allow.

     

     

    6. Install trusted certificate

    After updating Safetica Client to a version that supports protection for emails sent via Outlook (Safetica Client 11.21.5 or newer), you must install a trusted certificate:

    1. Open Terminal and run the following command to install the trusted certificate:   sudo /Library/Application\ Support/Safetica/Tools/setup InstallTrustedCertificate
    2. (Optional) Verify the certificate installation:
      • Open Keychain Access (press CMD+SPACE, type "Keychain Access" and press Enter).
      • Check that the Safetica certificate is marked as trusted (If the status doesn't update immediately, close and reopen Keychain Access).

     

     


    Where to find what permissions are missing

    You can see some missing permissions in Safetica console in Devices > Protection details column. The Protection details column currently reports Missing full disk access permission, Missing notification permission, and Not enrolled in MDM. Other permissions (web browser access, the Mail app extension, and Mail app blocking) are not shown there yet.

    An empty Protection details column therefore does not mean that all permissions are granted. To confirm that a device is fully set up, check the permissions on the device itself using the steps in this article.

     

     


    FAQ

    Q: I have an issue with macOS - I can send emails via Outlook, even though I have a policy that blocks such emails. What should I do?
    A: Please check if all the necessary permissions are granted to Safetica based on this article. Also, if you are using Outlook for Mac, you need to activate Outlook protection. Learn more here.
     
    Q: What is MDM?
    A: MDM (Mobile Device Management) is a technology that allows organizations to remotely manage, secure, and configure mobile devices such as smartphones, tablets, and laptops. It helps enforce security policies, control applications, protect corporate data, and ensure compliance across an organization's device fleet.
     
    Q: How can we resolve the "Not enrolled in MDM" error on a macOS device?

    A: This status indicates that the device is not enrolled in a Mobile Device Management (MDM) solution. To resolve it, enroll the device in an MDM of your choice. Here are some MDM solutions you can use.

    Q: After updating to macOS 27, users can send blocked emails by clicking "Send anyway". Why?

    A: On macOS 27 and newer, Apple no longer allows the Accessibility permission to be granted through a configuration profile; only the user can grant it on the device. Without it, the email is still evaluated and the user is warned, but the Send anyway button remains clickable. Ask the user to allow STUserApp in System Settings > Privacy & Security > Accessibility. STUserApp asks for this permission automatically every time it starts until it is granted.

    Q: A dialog asking for the Accessibility permission keeps appearing after every restart. How do we stop it?

    A: Grant the permission; that is the only way to stop it. The dialog reappears every time STUserApp starts while the permission is missing, and clicking Deny does not suppress it. See Allow STUserApp above.

     

     

    Read next

    How to install Safetica Client to your devices