MacOS – Add apps to “Files and Folders” permissions

catalinamacospermission

In macOS Catalina, is it possible to add apps directly to Security & Privacy -> Files and Folders? The plus icon is greyed out, even when the preference pane is unlocked.

Image showing Files and Folders window with plus sign greyed out

I know that the option becomes available when an app tries to access one of the protected folders, but I would like to add an app pre-emptively.

Best Answer

This is possible for MDM managed Macs by pushing signed profiles to preemptively white-list signed applications.

The process is quite detailed, but it uses a well documented profile setup (175 pages to cover the basics). We currently push about 20 items this way, so if you need to manage a lot of apps and a lot of Macs, this is possible and once you have your tools in place, easy to add new profiles. This isn’t feasible for a few machines if you’re not running a MDM.

Look at the section on page 64

> Privacy Preferences Policy Control Payload

The Privacy Preferences payload is designated by specifying com.apple.TCC.configuration-profile-policy value as the PayloadType value. It controls the settings that are displayed in the ”Privacy” tab of the ”Security & Privacy” pane in System Preferences. This profile must be delivered via a user approved MDM server in a device profile.

Here is a very not short (but as short as can be reasonably made) guide for an engineer or team thinking about adding this to your MDM.

Here is an awesome tool for automating creation of your profiles: