PPPC Accessibility Profile Not Applied on Golden Gate Beta When Deployed via Jamf

We are experiencing an issue with Privacy Preferences Policy Control (PPPC) profiles deployed through Jamf Pro on the Golden Gate beta.

We use the following Jamf configuration profiles to pre-approve Digital Guardian Accessibility permissions:

DG – Grant Accessibility Access to DgSessionSvc.app

DG – RME

These profiles are intended to grant Accessibility permissions automatically for Digital Guardian under:

System Settings → Privacy & Security → Accessibility

On macOS Tahoe and macOS Sequoia, these PPPC profiles work as expected. After deployment, the required Accessibility permissions are granted automatically and users are not prompted.

However, on the Golden Gate beta, the same configuration profiles are installed successfully, but the required Accessibility permissions are not granted. As a result, users continue to receive the Accessibility permission prompts.

We also observed a difference when inspecting the installed profile under:

System Settings → General → Device Management → Profile

On macOS Tahoe, the installed profile contains the following entry:

Control the Computer — com.verdasys.DgSessionSvc — Allowed

On the Golden Gate beta, this entry is missing, even though the identical Jamf PPPC profile has been installed successfully.

For reference, we have attached:

The Jamf PPPC configuration profiles (.mobileconfig)

Comparison screenshots from macOS Tahoe and the Golden Gate beta

Could you please confirm whether this is:

  • a known issue in the Golden Gate beta,
  • an intentional change in PPPC behavior, or
  • an issue with our PPPC configuration profile?

If this is an operating system issue, we would appreciate it if it could be investigated and addressed in a future Golden Gate beta release.

Environment

Affected OS: Golden Gate 27.0 Beta (26A5388g)

Working OS versions: macOS Tahoe and macOS Sequoia

MDM Solution: Jamf Pro 11.30.1

Affected Application: Fortra Digital Guardian

Required Permission: Accessibility (Control the Computer)

Architecture: Apple silicon

We would also appreciate it if you could review the attached .mobileconfig files and let us know whether any modifications are required to make the PPPC profiles compatible with the Golden Gate beta, or if any additional information would be helpful for your investigation.

Answered by DTS Engineer in 899322022

Quoting the PrivacyPreferencesPolicyControl.Services docs:

Specifies the policies for the app via the Accessibility subsystem. This profile deprecated its ability to grant access as of macOS 26.2, and removes that ability in macOS 27.0.

The replacement is the Privacy app settings property, which you set via declarative device management.

WWDC 2026 Session 206 What’s new in managing Apple devices, starting 10:56, has some great info about appleOS 27 changes in this space.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Quoting the PrivacyPreferencesPolicyControl.Services docs:

Specifies the policies for the app via the Accessibility subsystem. This profile deprecated its ability to grant access as of macOS 26.2, and removes that ability in macOS 27.0.

The replacement is the Privacy app settings property, which you set via declarative device management.

WWDC 2026 Session 206 What’s new in managing Apple devices, starting 10:56, has some great info about appleOS 27 changes in this space.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Thanks for the update but this creates a lot of friction for our users, and have them support the previous options. They can't just go around removing previously supported options without any warnings or heads-up.

PPPC Accessibility Profile Not Applied on Golden Gate Beta When Deployed via Jamf
 
 
Q