

The EPS team currently creates global profiles for new extension policies as we become aware of them. Workspace ONE supports Kernel and System Extension Policy profiles, which pre-approve kexts and sysexts for all users on a device without customer interaction.

Workspace ONE Kernel and System Extension Profiles Due to Apple restrictions, third-party tools such as Munki can’t be used to apply extension approval, but MDM/UEM systems such as Workspace ONE can. With the November 2020 release of Big Sur, kexts are fully deprecated.Īs we continue to see an increasing number of macOS applications requiring sysext and kext approval, the EPS service attempts to anticipate stakeholder impact and offer practical solutions. In 2019, Apple announced that kernel extensions would be deprecated in favor of system extensions ("sysexts"), which still allow apps to extend macOS functionality but without kernel-level access. In the case where the “Allow” button is no longer available, a restart *may* reinstate it (but doesn’t always) in the other cases, the “Allow” button is visible but not clickable until the interfering software/device/screen-sharing is removed. This could be because 1) the user delayed the "Allow" action by more than a half-hour, in which case the “Allow” button disappears 2) the user is running third-party software emulation for input devices 3) the user is using third-party creative tablets or pens or 4) the Mac is being controlled via a screen sharing utility, including Apple Remote Desktop. However, in some cases, the end user can’t enable the extension, and the software will fail to run. This action is required before the application will run. The user, whether an admin or a standard user, can follow the directions to open System Preferences - Security & Privacy - General and click “Allow", enabling the Box Drive kernel extension to load for all users on the system: For example, when Box Drive is launched for the first time on macOS 10.14, the end user will receive the following prompt:

Workspace ONE Unified Endpoint Management (UEM) Information on secure kernel and system extension loading with macOS 10.13.4 and up.
