macOS TCC Privacy Permissions: Audit, Reset and PPPC
How macOS TCC protects Full Disk Access, Screen Recording, Accessibility and more, and how to audit, reset and manage grants with PPPC profiles.
Transparency, Consent and Control (TCC) is the macOS subsystem behind every "App would like to access…" prompt. It stands between applications and the most sensitive resources on a Mac: your files, your screen, your keystrokes, your camera and microphone, and the ability to control other apps. From a hardening point of view, TCC is a least-privilege system for apps. The goal is to grant as little as possible, review what has been granted, and manage the rest centrally. This guide covers how TCC works, how to audit and reset it, and what MDM can and cannot pre-approve on macOS 15 Sequoia and macOS 26 Tahoe.
How TCC works
tccd and the databases
The daemon tccd makes access decisions. There is a system instance and a per-user instance, each backed by a SQLite database:
| Database | Path | Holds |
|---|---|---|
| System | /Library/Application Support/com.apple.TCC/TCC.db | Machine-wide services such as Full Disk Access |
| User | ~/Library/Application Support/com.apple.TCC/TCC.db | Per-user grants such as Camera, Microphone, Automation |
| MDM | /Library/Application Support/com.apple.TCC/MDMOverrides.plist | Decisions delivered by PPPC profiles |
These files are protected by System Integrity Protection. Even root cannot modify them, and a process can only read them if it has Full Disk Access itself. That protection is one reason SIP must stay on. Without it, malware could grant itself permissions by writing to the database.
TCC identifies a client by bundle identifier or path plus its code signature. If an app's signature changes, for example a re-signed or tampered binary, earlier grants no longer match.
Main categories
| System Settings name | Service (tccutil / PPPC key) | Why it matters |
|---|---|---|
| Full Disk Access | SystemPolicyAllFiles | Read Mail, Messages, Safari data, other users' protected files, TCC databases |
| Accessibility | Accessibility | Control the UI, click buttons, read screen content via accessibility APIs |
| Screen & System Audio Recording | ScreenCapture | See everything on screen |
| Input Monitoring | ListenEvent | Observe keystrokes, a keylogger capability |
| Automation | AppleEvents | Send Apple events to control another app (per target app) |
| Camera | Camera | Camera access |
| Microphone | Microphone | Microphone access |
| Files and Folders | SystemPolicyDesktopFolder, SystemPolicyDocumentsFolder, SystemPolicyDownloadsFolder | Access to specific user folders |
Full Disk Access, Accessibility, Screen Recording and Input Monitoring are the high-value targets. Each amounts to near-total visibility into, or control over, the user's session.
Reviewing grants
The main review surface is System Settings > Privacy & Security. Go through Full Disk Access, Accessibility, Screen & System Audio Recording, Input Monitoring and Automation at least once per review cycle. Remove any entry the user cannot justify. Leftovers from uninstalled apps, old remote-support tools and one-off utilities are common.
For audit scripts on a single machine, a terminal with Full Disk Access can read the databases:
# System database: requires the terminal to have Full Disk Access
sudo sqlite3 "/Library/Application Support/com.apple.TCC/TCC.db" \
"SELECT service, client, auth_value FROM access ORDER BY service;"
# Current user's database
sqlite3 "$HOME/Library/Application Support/com.apple.TCC/TCC.db" \
"SELECT service, client, auth_value FROM access ORDER BY service;"
In practice, auth_value 2 means allowed and 0 means denied. The schema is undocumented and has changed between macOS releases, so treat these queries as read-only inspection. Never write to the database. At fleet scale, use your MDM, EDR or a tool such as osquery to collect this data rather than ad-hoc scripts.
TCC decisions also appear in the unified log:
log stream --predicate 'subsystem == "com.apple.TCC"'
See the logging and Endpoint Security guide for forwarding and retention.
Resetting permissions with tccutil
tccutil is Apple's supported tool for resetting decisions. It cannot grant anything.
# Reset Screen Recording for one app
tccutil reset ScreenCapture com.example.app
# Reset all Full Disk Access decisions
sudo tccutil reset SystemPolicyAllFiles
# Reset every service for one app
tccutil reset All com.example.app
After a reset, the app prompts again the next time it needs the resource. This is useful when retiring a tool, in incident response, or when a user granted too much by mistake.
Managing TCC with PPPC profiles
MDM manages TCC with the Privacy Preferences Policy Control (PPPC) payload, com.apple.TCC.configuration-profile-policy. It is honored only when installed through user-approved or automated MDM enrollment. A manually installed profile does not work. See the MDM guide.
What MDM can and cannot do
| Service | Can MDM allow? | Can MDM deny? | Notes |
|---|---|---|---|
| Full Disk Access, Accessibility, Automation, Files and Folders | Yes | Yes | Typical use: EDR, backup and management agents |
| Camera, Microphone | No | Yes | The user must always consent |
| Screen Recording | No | Yes | Can let a standard user approve the prompt |
Apple's policy is that the user must consent to camera, microphone and screen capture. The value a profile adds for Screen Recording is AllowStandardUserToSetSystemService. Normally only an admin can approve screen recording, and this setting lets a standard user approve it for the specified app. This fits the least-privilege model in the accounts guide, because users don't need admin rights to use a video-conferencing tool.
Example payload
Grant Full Disk Access to an agent, pinned to its code signature:
<dict>
<key>PayloadType</key>
<string>com.apple.TCC.configuration-profile-policy</string>
<key>PayloadIdentifier</key>
<string>com.example.baseline.pppc</string>
<key>PayloadUUID</key>
<string>REPLACE-WITH-UUID</string>
<key>PayloadVersion</key>
<integer>1</integer>
<key>Services</key>
<dict>
<key>SystemPolicyAllFiles</key>
<array>
<dict>
<key>Identifier</key>
<string>com.example.agent</string>
<key>IdentifierType</key>
<string>bundleID</string>
<key>CodeRequirement</key>
<string>REPLACE-WITH-OUTPUT-OF-codesign-dr</string>
<key>Authorization</key>
<string>Allow</string>
<key>Comment</key>
<string>EDR agent needs FDA</string>
</dict>
</array>
</dict>
</dict>
Get the designated requirement for CodeRequirement from the signed app:
codesign -dr - /Applications/ExampleAgent.app
The code requirement is the security anchor. It ties the grant to the developer's signing identity, so a different binary with the same bundle ID cannot inherit it. Never use a PPPC entry without it. For Automation (AppleEvents), each entry also names the receiving app with AEReceiverIdentifier, AEReceiverIdentifierType and AEReceiverCodeRequirement. Grant automation per target app rather than broadly.
Sequoia screen recording re-prompts
macOS 15 Sequoia changed Screen Recording consent. Apps using certain capture methods trigger a recurring system prompt, roughly monthly, asking the user to allow continued access. The intent is to stop an app that was approved once from watching the screen indefinitely without the user noticing.
For hardening, treat the prompt as a feature. On managed fleets where it disrupts approved tools, Apple added a Restrictions option (forceBypassScreenCaptureAlert, supervised Macs, macOS 15.1 and later) that suppresses these alerts. Use it sparingly and only alongside a PPPC review of which apps hold Screen Recording.
Least privilege for Full Disk Access
Full Disk Access is the most over-granted permission on the Mac. Guidelines:
- Don't grant FDA to Terminal or iTerm2 permanently. Any script or tool run from that terminal inherits it. Grant it temporarily for a task, then remove it.
- Grant FDA to agents, not wrappers. Some tools need FDA on a specific helper binary rather than the app bundle. Follow the vendor's documented identifiers and code requirement.
- Security tools legitimately need it. EDR and backup agents need FDA, usually with a system extension. Deliver both by profile so users never see the prompts. See the logging guide.
- Remove grants when you remove software. Uninstalling an app does not always clear its TCC entries. Use
tccutil resetas part of decommissioning.
Verify it
# Profiles present, including PPPC payloads
sudo profiles show
# Read-only view of system-level grants (terminal needs FDA)
sudo sqlite3 "/Library/Application Support/com.apple.TCC/TCC.db" \
"SELECT service, client, auth_value FROM access WHERE service IN \
('kTCCServiceSystemPolicyAllFiles','kTCCServiceAccessibility','kTCCServiceScreenCapture','kTCCServiceListenEvent');"
# Confirm the code requirement you pinned matches the installed app
codesign -dr - /Applications/ExampleAgent.app
# SIP must be enabled for TCC protections to hold
csrutil status
In the database, service names carry the kTCCService prefix, while tccutil and PPPC use the short form.
Checklist
- SIP enabled. TCC databases never modified directly.
- Full Disk Access, Accessibility, Screen Recording and Input Monitoring reviewed regularly. Unjustified entries removed.
- Terminal apps do not hold permanent Full Disk Access.
- Security and management agents receive grants through PPPC profiles with a
CodeRequirement. - Camera, Microphone and Screen Recording left to user consent.
AllowStandardUserToSetSystemServiceused where standard users need screen recording. - Automation grants scoped to specific receiver apps.
-
tccutil resetpart of the app decommissioning process. - TCC events collected from the unified log.
Common pitfalls
- Expecting MDM to grant camera or microphone. It can only deny them.
- PPPC without user-approved MDM. The payload is ignored if installed manually.
- Stale code requirements. If a vendor changes signing identity, the grant stops matching and prompts return. Regenerate the requirement.
- Granting FDA to fix a prompt. Understand what the app needs first. Many apps only need a specific folder, or nothing at all.
- Confusing TCC with Gatekeeper. TCC controls what an app may access once it runs. Gatekeeper and notarization control whether it runs at all.