To download and install the Admin By Request macOS endpoint client:
If you haven't already, login to the Admin By Request portal.
In the portal, click the Download menu link to download the Mac endpoint client and store the file in a suitable location:
A number of things occur once Admin By Request is installed:
The Admin By Request icon will be red initially (indicating elevated rights), but it will then change color (to black or white) as admin rights are removed.
This occurs without needing a restart. An important consequence is that any operations requiring elevated privileges from now on need admin credentials, including responding to the Login Items & Extensions prompt coming up next (only a consideration for single endpoint installs - does not apply to MDM installations).
Also does not apply if local admin rights are not revoked or if the user installing is listed in the excluded accounts (see portal setting Endpoint Privilege Management > Settings > Mac Settings > Lockdown > ADMIN RIGHTS).
Several prompts appear, requesting authorization from the logged-in user.
The first of these is the endpoint security extension prompt. When this appears, click Open System Settings:
From Admin By Request version 5.2, if the endpoint is enrolled in Secure Remote Access (portal setting Settings > Product Enrollment > SECURE REMOTE ACCESS - see Product Enrollment Example 2 for a scope example), an Accessibility Access prompt will appear:
When this appears, click Open System Settings, go to Privacy & Security > Accessibility and enable Admin By Request SRA:
This is a first-use, one-time-only prompt raised by the macOS operating system that allows Admin By Request SRA to run on the endpoint.
NOTE
If installing Admin By Request via MDM and the endpoint is enrolled in Secure Remote Access at the time of installation, this prompt will not appear.
If the endpoint is not enrolled in Secure Remote Access, this prompt will not appear. However, if the endpoint is enrolled at some point in the future, the prompt will appear the first time a user logs in after enrollment.
Installation is now complete. Keep System Settings open and go to the next step, which is to ensure that Full Disk Access (FDA) is enabled for Admin By Request.