All macOS Elastic Endpoint versions affected by macOS 13 (Ventura) Full Disk Access bug
- Dominant language
- Swift
- Stars
- 47
- Forks
- 9
- PR merge metrics
- No merged PRs in 30d
Description
All versions of Elastic Endpoint are affected by a [bug](https://developer.apple.com/documentation/macos-release-notes/macos-13_1-release-notes) in macOS 13 (Ventura) which disables previously granted Full Disk Access. This bug does not affect Elastic Endpoints managed by an MDM solution.
Steps to reproduce:
* Install Elastic Endpoint on macOS 12 (Monterey) without MDM
* Follow [these](https://www.elastic.co/guide/en/security/current/deploy-elastic-endpoint.html) steps to grant all permissions needed
* See that after approval Endpoint's status in the Security App's Endpoint page is HEALTHY
* Upgrade to macOS 13 (Ventura)
* See that Endpoint's status in the Security App is is now UNHEALTHY because Full Disk Access is no longer approved
Workaround
* In Settings -> Security & Privacy -> Privacy -> Full Disk Access, remove Full Disk Access approval from `ElasticEndpoint` and `co.elastic.systemextension`
* Re-enable Full Disk Access in the same location. A reboot may be required between these two steps.
This bug is in macOS not Elastic Endpoint. It will be fixed by an update to macOS.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.