General discussion
August 21, 2026 at 01:34 PM
Munaqash Interiors

Managing macOS Sequoia and Sonoma Privacy Permissions at Enterprise Scale

by Munaqash Interiors . Updated 19 hours, 19 minutes ago

Hi everyone,

As macOS environments continue to expand in enterprise IT infrastructure, managing Privacy & Security settings (TCC / System Extensions) across remote fleets is becoming a growing challenge.

While MDM profiles (PPPC) handle most app permissions smoothly, recent macOS updates have introduced tighter user-prompt restrictions around screen recording, local network access, and background items that often trigger unexpected prompts for end-users—even when profiles are properly deployed.

I’d love to hear how other IT admins and sysadmins are handling this balance:

  1. Are you enforcing zero-touch configurations via declarative device management (DDM)?

  2. How are you dealing with non-standard developer tools or internal software that require elevated security permissions?

  3. What MDM solutions (Jamf, Kandji, Intune, etc.) are giving you the smoothest compliance workflows for macOS lately?

Looking forward to hearing your strategies and best practices!

All Comments