macOS Full Disk Access: prepare for new controls
Apple has announced additional future controls around Full Disk Access in macOS. For organizations, the signal is clear: broad permissions granted to backup, security, support, or AI agent software should be inventoried and justified before the consent journey changes.
1. What Apple announced — and what it has not announced yet
Apple says Full Disk Access largely bypasses normal protections to enable use cases such as backup applications. The permission can expose files, mail, messages, and browsing history. For communication apps, Apple also highlights the privacy risk to the people with whom users communicate.
Apple plans additional controls so that granting this access requires very explicit user action. The announcement provides no macOS version, timeline, or implementation details, however. It would therefore be premature to announce a new MDM payload or promise that an existing profile will continue — or cease — to work.
2. Why AI agents change the risk assessment
Apple explicitly links this hardening to increasingly capable and autonomous AI agents. Software that can explore local data, reason, and then act turns a broad permission into a dynamic exposure surface. Risk no longer depends only on the vendor: it also depends on connectors, instructions, automations, and the destinations to which the tool can send data.
The right control is not to label every AI app as dangerous. Teams should verify the actual need for access, limit exposed populations, document data flows, and distinguish an essential function — such as backup or threat detection — from a convenience feature.
3. What does this announcement change for a Belgian or French organization?
The announcement is global, but it directly supports European expectations for access control, minimization, and traceability. A Belgian SME and a French enterprise alike should be able to explain why an app accesses the entire disk, which data it processes, who approves the exception, and how that exception is removed.
IT and security teams should reconcile MDM inventory with the reality on their Macs. Compliance teams should identify processing that may include communications or personal data. For business users, a future deployment may require explicit action: support and communications must prevent improvised workarounds.
4. Underside analysis: separate technical need from permanent entitlement
Our reading is that Apple is preparing a clearer boundary between what an app can do and consent to an exceptional permission. Organizations should not wait for final documentation before cleaning up their fleets, but they should not extrapolate MDM behavior that Apple has not described.
In a Jamf or other Apple MDM environment, the inventory of Privacy Preferences Policy Control profiles should be reconciled with installed apps, their signatures, owners, and purpose. This complements privacy consent governance and app and binary controls: permission to execute does not automatically justify access to all data.
5. Readiness plan for the Mac fleet
- Inventory apps with Full Disk Access and the MDM profiles that govern privacy preferences.
- Map every authorization to an owner, rationale, population, review period, and removal procedure.
- Isolate AI agents and communication tools for review of connectors, network destinations, logs, and retention policies.
- Test removal of unnecessary exceptions with a pilot group without disrupting backup, EDR, support, or compliance.
- Track future Apple notes and MDM vendor documentation before changing profiles or the user journey.
- Prepare clear user guidance if Apple requires a new explicit action in future macOS releases.
Goal: justify every Full Disk Access grant and remove nonessential permissions before the new controls arrive.
Audit permissions across your Mac fleetOfficial source: Apple Developer — Updates to Full Disk Access in macOS.