{"id":76939,"date":"2023-05-18T15:03:04","date_gmt":"2023-05-18T19:03:04","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=76939"},"modified":"2023-06-08T18:55:56","modified_gmt":"2023-06-08T22:55:56","slug":"manage-jumpcloud-login-items","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/manage-jumpcloud-login-items","title":{"rendered":"Create a Mac Managed Login Items Policy"},"content":{"rendered":"\n
Apple has made a change in macOS 13 Ventura that affects JumpCloud and IT Admins. In macOS 13 Ventura, end users have the ability to switch off persistent software, such as the JumpCloud agent. JumpCloud has implemented new processes to address this concern, which vary depending on the configuration of your organization. <\/p>\n\n\n\n
<\/p><\/div>
You must apply this policy after you upgrade or install macOS 13 Ventura. Applying the policy before the device has Ventura installed causes the policy to not be recognized.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Depending on how your organization manages its macOS devices, the actions you must take to ensure smooth operation vary:<\/p>\n\n\n\n
To prevent your macOS users from turning off persistent software such as the JumpCloud Agent, you must configure the Managed Login Items Policy. This policy allows Admins to allowlist login items<\/a> for macOS devices based on RuleTypes defined by Apple:<\/p>\n\n\n\n Login items managed by this policy installed on macOS 13 systems or later will always be activated and the end user of the device cannot deactivate these items, even if they are administrators of their device. All items are evaluated against all RuleTypes and when matched it will be locked in the UI and automatically approved. <\/p>\n\n\n\n\n
com.jumpcloud.darwin-agent<\/code>. If a Bundle Identifier Prefix rule type is selected, a rule value of com.jumpcloud would allow any package with a Bundle Identifier that starts with
com.jumpcloud<\/code>, such as
com.jumpcloud.assist-app<\/code> or
com.jumpcloud.pwm.desktop.live<\/code>.<\/li>\n\n\n\n
com.jumpcloud<\/code> to operate, including
com.jumpcloud.jcagent-tray<\/code> or
com.jumpcloud.user-agent<\/code>.<\/li>\n\n\n\n
Create a Managed Login Items Policy<\/strong><\/h2>\n\n\n\n