The following explains the process for downloading and installing a Mac agent on a disconnected asset. The same token and agent binaries can be used by multiple machines which (depending on your organization's environment) may allow for this to be pushed out to multiple machines rather than having to manually install an agent on each individual machine. There are 2 Mac agents to select from depending on your environment:
To download a Mac x64 agent
-
On the Downloads page, click the Download button associated with the Mac x64 tile.
A zipped ConnectForSafeguardMacAgent folder will be downloaded according to your browser settings.
-
Unzip the ConnectForSafeguardMacAgent.zip folder.
-
To the extracted ConnectForSafeguardMacAgent folder, add the agent enrollment token file (Downloading an Agent Enrollment token).
CAUTION: Keep a copy of the enrollment token until the agent has been successfully enrolled. The token file will be automatically removed after each enrollment attempt (including failed attempts).
-
Right-click the appsettings.json file and select to run a command line prompt. The service account used for enrollment must be a member of sudoers.
-
From a terminal, the enroll command on the ConnectForSafeguardAssetsAgent executable.
Once the agent has been successfully enrolled, the Safeguard Disconnected Asset Agent will be installed under the service account along with a ConnectForSafeguardAssets certificate that is valid for 60 days. The agent will automatically attempt to renew the certificate after 30 days have passed since the last certificate was issued. However, if an agent is unable to re-enroll and the certificate expires, the re-enroll command can be used to re-enroll the agent (for more information, see Re-enrolling an installed agent).
-
In Safeguard for Privileged Passwords, you can now add or discover the asset (using the macOS (Starling Connect) platform). For more information, see the One Identity Safeguard for Privileged Passwords Administration Guide.
Make sure the Agent ID is the same as shown in Safeguard for Privileged Passwords (Assets > (select asset) > Properties > Connection > (Edit) > StarlingAgentID). If the Agent ID is different, you need to update the StarlingAgentID in Safeguard for Privileged Passwords to match the Agent ID.
NOTE: When running a task in Safeguard for Privileged Passwords against a Mac agent, the task is created in a submitted state and will be updated once the agent processes the task. The amount of time this will take to update will vary depending upon the state of the machine the agent is running on.
To download a Mac arm64 agent
-
On the Downloads page, click the Download button associated with the Mac arm64 tile.
A zipped ConnectForSafeguardMacArm64Agent folder will be downloaded according to your browser settings.
-
Unzip the ConnectForSafeguardMacArm64Agent.zip folder.
-
To the extracted ConnectForSafeguardMacArm64Agent folder, add the agent enrollment token file (Downloading an Agent Enrollment token).
-
Right-click the appsettings.json file and select to run a command line prompt. The service account used for enrollment must be a member of sudoers.
-
From a terminal, the enroll command on the ConnectForSafeguardAssetsAgent executable.
Once the agent has been successfully enrolled, the Safeguard Disconnected Asset Agent will be installed under the service account along with a ConnectForSafeguardAssets certificate that is valid for 60 days. The agent will automatically attempt to renew the certificate after 30 days have passed since the last certificate was issued. However, if an agent is unable to re-enroll and the certificate expires, the re-enroll command can be used to re-enroll the agent (for more information, see Re-enrolling an installed agent).
-
In Safeguard for Privileged Passwords, you can now add or discover the asset (using the macOS (Starling Connect) platform). For more information, see the One Identity Safeguard for Privileged Passwords Administration Guide.
Make sure the Agent ID is the same as shown in Safeguard for Privileged Passwords (Assets > (select asset) > Properties > Connection > (Edit) > StarlingAgentID). If the Agent ID is different, you need to update the StarlingAgentID in Safeguard for Privileged Passwords to match the Agent ID.
NOTE: When running a task in Safeguard for Privileged Passwords against a Mac agent, the task is created in a submitted state and will be updated once the agent processes the task. The amount of time this will take to update will vary depending upon the state of the machine the agent is running on.