IT Buyers Guide · Concept · 11 min read

RMM for Mac, and Why the Agent Only Works as Well as the MDM Behind It

On Windows the agent can do almost anything once installed. On a Mac, Apple’s privacy controls decide what it can see and touch, and the switch for most of that sits in MDM. This is what a profile can grant, what it cannot, and what macOS 27 changes.

Written by Marko Ristic, Editor Updated Sep 17, 2026
4permissions an RMM agent needs on a Mac beyond monitoring
0ways for MDM to grant screen recording without a person at the Mac
27the macOS release that removes Accessibility grants through the old profile
90days, the longest custom deferral for a Mac software update
Short answer

RMM for Mac works, but the agent only does what Apple’s privacy controls allow, and most of those grants come from MDM. A privacy profile can give the agent Full Disk Access silently.

It cannot do the same for screen recording, which a person at the Mac has to approve. OS updates on Apple silicon need the bootstrap token MDM holds, and macOS 27 removes the old Accessibility grant through a profile. The working setup is an RMM agent plus an MDM.

  • Full Disk Access can be pre-approved by MDM; without MDM an admin grants it by hand
  • Screen recording cannot be pre-approved; a person at the Mac has to allow it
  • Apple silicon updates need a bootstrap token from MDM, or the user’s credentials
  • macOS 27 removes Accessibility grants through the old privacy profile
  • Any Mac on macOS 11 or later enrolled through Device Enrollment is supervised
On this page

The permissionsWhat an RMM agent needs from macOS

RMM software reaches every endpoint through an agent, and on Windows that agent installs as a service running as SYSTEM and can do almost anything from the moment it starts. That is the model MSPs learned their tools on, and it is the source of most surprises when the same RMM tools meet Mac devices.

On a Mac the agent also runs as root, and it still cannot read a user's mail, watch the screen or move the mouse, because macOS puts those behind a separate privacy layer, Transparency, Consent and Control, that root alone does not pass.

Apple introduced these controls in macOS 10.14, and every Mac RMM vendor's setup guide is shaped by them. They are also why Mac environments behave differently from Windows ones under the same RMM software.

The permissions that matter for remote monitoring and management are four, and each maps to a job:

Full Disk Access. Apple's name for it in a profile is System Policy All Files, and it covers data like Mail, Messages, Safari, Home, Time Machine backups and certain administrative settings for all users.

An agent needs it to back up a Mac, to run scripts that read those locations, and to report on them. N-able's own guide to its backup agent tells the user to open the privacy settings, unlock the padlock and enter the computer's administrative credentials to grant it.

Accessibility. Lets an app control the Mac through the Accessibility APIs. Remote control uses it to click and type on the user's behalf.

Input devices and Post Event. Related permissions for sending mouse and keyboard events, which remote control tools also use.

Screen recording. Lets an app capture the contents of the display. Without it, remote support software sees nothing, which is why remote support is where an unprepared Mac rollout fails first.

Performance monitoring on its own, meaning CPU, memory, disk space, services and uptime, needs none of these. That is why a new Mac agent gives full visibility into device health on day one, and then fails the first time a technician tries to take control or run a backup.

The monitoring half of remote monitoring and management works on any Mac; the management half depends on permissions.

What MDM can doWhat MDM can grant, and what it cannot

MDM grants these permissions with a Privacy Preferences Policy Control profile, usually called a PPPC profile. It names the app by bundle identifier or path, pins it to its code signature, obtained with the codesign -dr - command, and sets a policy for each service.

Apple's developer reference lists an MDM enrollment the user approved as the requirement. Apple's deployment guide says supervision, and on a Mac the two mostly coincide: any Mac on macOS 11 or later that enrolls through account-driven, profile-based or Automated Device Enrollment is supervised.

What the profile can do differs by service, and the table in Apple's own device management documentation spells it out.

PermissionWhat an MDM profile can do
Full Disk Access (System Policy All Files)Allow silently
AccessibilityAllow silently until macOS 27
Screen recordingDeny, or let a standard user approve
Camera and microphoneDeny only

The screen recording line is the one that shapes every Mac remote support setup. Apple's profile documentation describes the screen recording setting as a way to deny apps access, and the only other value it accepts for that service lets a standard, non-admin user approve the app in System Settings.

So the most an MSP can arrange in advance is that the user will not need an admin password. Someone still has to be at the Mac once and click Allow. Plan for that during onboarding, not during the first outage.

macOS 27macOS 27 changes the Accessibility rule

Apple's notes on what changes for IT with macOS 27, published after WWDC26 and marked as covering pre-release software, change the second row of that table.

The old grant goes away. On a Mac with macOS 26.2, granting Accessibility to an app through the PPPC profile was deprecated, and in macOS 27 it is removed. Apple's reference for the profile marks its per-app entries as deprecated from macOS 27.

The replacement asks the user once. On supervised Macs with macOS 27, a new Privacy key in the app settings configuration, part of declarative device management, lets the organization set default permissions per app.

At the app's first launch the Mac shows one consolidated prompt listing the permissions, with the organization's name, the app name and a justification the organization writes, and Allow selected as the default. If the user chooses Allow, the defaults apply and no further prompts appear. If the user chooses Not Now, the usual separate prompts come back.

What is on the new list. Accessibility, Bluetooth, camera, dictation, local network, location and microphone. Full Disk Access and screen recording are not on it.

For an RMM Mac rollout that means the silent Accessibility grant that remote control relied on becomes a prompt the user sees and answers. The prompt is designed to be answered correctly, and it is still a prompt.

Ask your RMM and MDM vendors how they handle macOS 27 before the first Macs update, because an agent whose remote control worked on macOS 26 can lose it on macOS 27 without anything changing in the RMM.

UpdatesUpdates and patching on a Mac

Patching is the other place where the RMM agent reaches the edge of what it can do alone.

Apple silicon needs authorization. Apple's deployment guide says that on a Mac with Apple silicon, the Mac uses a bootstrap token, if one is available, to authorize an update, or it prompts the user for their credentials.

The bootstrap token is escrowed with the MDM. An RMM agent that runs softwareupdate on an unattended Mac without one can download the update and then wait for a password nobody is there to type.

Enforcement is an MDM feature. From macOS 14, device management can defer software updates for 1 to 90 days and enforce a specific update at a set local time regardless of deferral, through a declarative software update configuration. That is the Mac equivalent of the deadline an RMM would set for Windows.

Third-party apps are the RMM's job. Browsers, Zoom, Office and the rest of the application catalog are where an RMM agent earns its place on a Mac, through its own catalog or Homebrew, with alerts when a patch fails and reports that show which devices are behind. Patch management covers how the rings and deferrals fit together.

RMM and MDMRMM or MDM for Mac, and why the answer is both

The comparison articles ask whether MSPs need MDM or RMM for their Mac devices. The division of labor on macOS is clear enough that the question answers itself, and the answer is the same whether the Macs are a few laptops in a Windows office or a design agency running nothing else.

MDM does what Apple only allows MDM to do. Enrollment, supervision, configuration profiles, the privacy grants above, FileVault and the security settings behind it, the bootstrap token, enforced software updates for the operating system, and lock and erase for lost devices.

The RMM agent does what MDM was never built for. Continuous monitoring and alerting, automation through scripts run on demand as root, remote support sessions, third-party patch management, endpoint inventory in the same console as the Windows fleet, and tickets through the PSA.

For MSPs that single console across every client and every operating system is the reason to run RMM for Mac at all.

The market has already moved this way. NinjaOne sells an MDM product alongside its RMM, and Atera's Mac page offers MDM-grade controls such as FileVault and configuration profiles for teams that need them. Tactical RMM's Mac agent is a paid sponsorship feature, covered in the open source RMM guide.

Whichever route, check that the MDM and the RMM agent come from the same vendor or at least that the RMM vendor publishes a PPPC profile for its agent, with the exact bundle identifiers and code requirements. The MSP software ranking and the MDM ranking compare the main platforms.

RolloutRolling out an RMM agent to Macs

The order matters more on macOS than on Windows, because permissions granted before the agent arrives apply the moment it installs. This is the sequence that avoids most of the issues MSPs report with RMM for Mac.

1. Enroll the Macs in MDM first. New Macs through Automated Device Enrollment, bought through Apple Business Manager, so they arrive supervised and enrolled. Existing Macs through Device Enrollment, approved by a local administrator.

2. Push the privacy profile before the agent. A PPPC profile for each of the agent's components, with the bundle identifier and code requirement the RMM vendor publishes. Full Disk Access and, before macOS 27, Accessibility can be granted here. Screen recording can only be set so a standard user may approve it.

3. Confirm the bootstrap token is escrowed. Without it, enforced updates on Apple silicon wait for a user password.

4. Install the agent through MDM. As a signed package, so the install does not depend on a technician at the Mac.

5. Collect the one approval that cannot be automated. Ask each user to approve screen recording for the remote support tool, ideally during onboarding with a technician on the phone.

6. Test with a real session. Take remote control, run a script that reads a protected location, and run an update on an Apple silicon Mac nobody is logged in to. The failures show up here instead of during the first incident.

PitfallsWhere people go wrong

Installing the agent before the profile. The agent starts without permissions, the user meets prompts they do not recognize, and putting it right usually takes a support session.

Assuming screen recording can be pushed. It cannot. The best a profile does is let a standard user approve it.

Treating a Mac agent as a Windows agent. Root on macOS does not pass TCC, and the security model is the reason, not a bug in the RMM tools. A script that works on the technician's own Mac, which has been granted everything by hand, fails silently on a client's.

No bootstrap token. Updates that never finish on Apple silicon Macs are the usual symptom.

Ignoring macOS 27. Accessibility grants through the old profile stop working, and remote control can break on update day.

Letting users decline and forgetting. A user who chose Not Now or Deny has an agent that reports healthy and cannot be controlled. Check permission state in the RMM's inventory, not just agent status, and set alerts on it where the RMM allows.

Buying MDM and RMM that do not know about each other. The profile has to match the agent's signature exactly. A vendor that does not publish one is leaving that work to you.

WHAT THE MDM CAN ARRANGE BEFORE THE RMM AGENT ARRIVESMDMprivacy profilebootstrap tokenFULL DISK ACCESSSilent grantbackups and scriptsinto user dataACCESSIBILITYSilent until macOS 27remote control,then one promptSCREEN RECORDINGUser must approveremote viewing,never silentUPDATES, APPLE SILICONToken authorizeswithout it, waitsfor a passwordApple Platform Deployment and Device Management reference, September 11, 2026. macOS 27 notes are pre-release.
The four things an RMM agent needs on a Mac, and how much of each an MDM can arrange before the agent installs. Only the screen recording row always needs a person.

ComparisonWhat an RMM agent can do on a Mac, with and without MDM

CriterionRMM agent aloneRMM agent with MDM
Health monitoring and alertsYesYes
Scripts as rootYes, but not into protected dataYes, with Full Disk Access granted
Full Disk AccessAdmin clicks on every MacGranted silently by profile
Remote control inputAdmin clicks on every MacProfile until macOS 27, then one consent prompt
Screen viewingUser approves on every MacUser approves, no admin password needed
OS updates on Apple siliconWaits for the user's passwordBootstrap token
Enforced update deadlineNoYes, from macOS 14
FileVault and lock or eraseNoYes
Third-party app patchingYesYes

Read the last column as the minimum for MSPs managing client Mac devices. The agent alone is enough to watch a Mac and not enough to manage one, which is the short version of every RMM for Mac decision.

FAQFrequently asked questions

Can an RMM manage a Mac without MDM?

It can monitor one, run scripts and patch third-party apps. It cannot give itself Full Disk Access, Accessibility or screen recording, which someone with an admin password has to grant by hand on every Mac, and it cannot authorize OS updates on Apple silicon without the user's credentials.

What permissions does an RMM agent need on macOS?

Usually Full Disk Access for backups and scripts that read protected data, Accessibility and input permissions for remote control, and screen recording for remote viewing. Monitoring alone needs none of them.

Can MDM grant screen recording to a remote support tool?

No. A privacy profile can deny it, or allow a standard user to approve it in System Settings without an admin password. Someone at the Mac still has to approve it once.

What is a PPPC profile?

A Privacy Preferences Policy Control profile, delivered by MDM, that sets privacy permissions for named apps, identified by bundle identifier or path and pinned to their code signature. It is how Full Disk Access and, before macOS 27, Accessibility are granted without prompting the user.

What changes for Mac RMM in macOS 27?

Granting Accessibility through the PPPC profile, deprecated in macOS 26.2, is removed. On supervised Macs, a new Privacy key lets the organization set default permissions, and the user sees one consent prompt at the app's first launch with Allow selected by default. Apple marks its notes on macOS 27 as covering pre-release software.

Why do macOS updates fail through the RMM?

On Apple silicon, the Mac needs a bootstrap token to authorize an update, and the token is escrowed with MDM. Without it, the Mac asks the user for their credentials, and an unattended Mac waits.

Is my Mac supervised?

If it runs macOS 11 or later and is enrolled in an MDM through Automated Device Enrollment or Device Enrollment, yes. Apple supervises those Macs automatically.

What is the difference between MDM and RMM for Mac?

MDM uses Apple's management framework for enrollment, profiles, privacy grants, FileVault and update enforcement. RMM adds an agent for monitoring, alerting, scripts, remote support and third-party patching. On a Mac, the RMM agent depends on the MDM for its permissions.

Do I need Apple Business Manager?

For new Macs to arrive supervised and enrolled automatically, yes, through Automated Device Enrollment. Existing Macs can enroll through Device Enrollment, approved by a local administrator.

Does Tactical RMM support Macs?

Its Mac agent is a sponsorship feature rather than part of the free build, and it faces the same macOS permission rules as every other agent.

Which RMM software works best for Mac?

The one whose vendor publishes a PPPC profile for its agent, supports the macOS 27 Privacy key, and pairs with an MDM you already run or sells one. Feature lists for monitoring and automation look alike across RMM tools; the Mac-specific difference is how much of the permission work the vendor has done for you.

Should an MSP use a Mac-only platform or a cross-platform RMM?

A client with mostly Macs is often better served by a platform built around Apple's MDM with a live agent added. A mixed fleet usually stays on a cross-platform RMM with an MDM added for the Macs. Either way, the MDM is not optional.

What does Mac remote monitoring and management need that Windows does not?

Mac remote monitoring and management depends on Apple's MDM framework for anything privileged. The agent needs MDM delivered approval for full disk access, screen recording and system extensions, and operating system updates are enforced through MDM commands. An RMM that ships only a Mac agent, with no MDM, cannot do these silently.

Read next · Managed IT What RMM Is, and What the Agent Can Actually Do The agent, the console and the risk, on any operating system. Open this next9 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.