We are experiencing an issue with Privacy Preferences Policy Control (PPPC) profiles deployed through Jamf Pro on the Golden Gate beta.
We use the following Jamf configuration profiles to pre-approve Digital Guardian Accessibility permissions:
DG – Grant Accessibility Access to DgSessionSvc.app
DG – RME
These profiles are intended to grant Accessibility permissions automatically for Digital Guardian under:
System Settings → Privacy & Security → Accessibility
On macOS Tahoe and macOS Sequoia, these PPPC profiles work as expected. After deployment, the required Accessibility permissions are granted automatically and users are not prompted.
However, on the Golden Gate beta, the same configuration profiles are installed successfully, but the required Accessibility permissions are not granted. As a result, users continue to receive the Accessibility permission prompts.
We also observed a difference when inspecting the installed profile under:
System Settings → General → Device Management → Profile
On macOS Tahoe, the installed profile contains the following entry:
Control the Computer — com.verdasys.DgSessionSvc — Allowed
On the Golden Gate beta, this entry is missing, even though the identical Jamf PPPC profile has been installed successfully.
For reference, we have attached:
The Jamf PPPC configuration profiles (.mobileconfig)
Comparison screenshots from macOS Tahoe and the Golden Gate beta
Could you please confirm whether this is:
- a known issue in the Golden Gate beta,
- an intentional change in PPPC behavior, or
- an issue with our PPPC configuration profile?
If this is an operating system issue, we would appreciate it if it could be investigated and addressed in a future Golden Gate beta release.
Environment
Affected OS: Golden Gate 27.0 Beta (26A5388g)
Working OS versions: macOS Tahoe and macOS Sequoia
MDM Solution: Jamf Pro 11.30.1
Affected Application: Fortra Digital Guardian
Required Permission: Accessibility (Control the Computer)
Architecture: Apple silicon
We would also appreciate it if you could review the attached .mobileconfig files and let us know whether any modifications are required to make the PPPC profiles compatible with the Golden Gate beta, or if any additional information would be helpful for your investigation.
Quoting the PrivacyPreferencesPolicyControl.Services docs:
Specifies the policies for the app via the Accessibility subsystem. This profile deprecated its ability to grant access as of macOS 26.2, and removes that ability in macOS 27.0.
The replacement is the Privacy app settings property, which you set via declarative device management.
WWDC 2026 Session 206 What’s new in managing Apple devices, starting 10:56, has some great info about appleOS 27 changes in this space.
Share and Enjoy
—
Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"