Installing the Mac agent
To manage your devices in Absolute, you first need to download and install the Secure Endpoint Agent on each device. After the agent is installed, it contacts the Absolute Monitoring Center to receive a unique identifier. A device record is then created in the database and the device information detected by the agent is made available in the Secure Endpoint Console.
You can install the Secure Endpoint Agent in the following ways:
- Direct installation: commonly used to install the agent on individual computers not connected through a network. This method requires hands-on contact with each target device.
- Batch installation: used to install the agent on multiple devices, either locally or remotely.
The agent installation package also includes the Agent Management Tool. You can use this application to manage individual agents and to verify the state of the agent in an image before deploying the image to devices in your network.
To ensure that your Mac devices are compatible with the Secure Endpoint Agent, the following requirements must be met:
-
Supported operating systems:
- macOS 11
- macOS 12
- macOS 13
- macOS 14
NOTE Intel Core, Apple M1, and Apple M2 based devices are supported.
- Internet connection
To prepare to install the Secure Endpoint Agent on Mac devices:
- Use a virus-scanning program to ensure that your hard drive is free from viruses.
-
Disable all resident virus-scanning programs.
NOTE Remember to enable all virus-scanning programs again after installing the agent successfully.
- Ensure the device is connected to the Internet.
- Ensure that you have Administrator privileges on the device.
You can deploy the Secure Endpoint Agent on your Mac devices using either of the following installers:
- Full agent installer
- Core agent installer
Choosing an installer depends on a number of factors, including your network configuration and whether you are installing the agent locally or remotely.
To learn more about the two installers and how to download them, see Downloading the Secure Endpoint Agent.
To extract the installer:
-
Complete the steps to download the Mac installer of your choice.
Account-specific installers are downloaded in the following zip files:
- Full agent: AbsoluteMacFullAgent-<agent version>-<account_id>.zip
- Core agent: AbsoluteMacCoreAgent-<agent version>-<account_id>.zip
-
From the location where you saved the downloaded zip file, extract its contents to a local folder, a network drive, or to removable media such as a USB device.
Each download package contains the following files:
IMPORTANT Before you run the installer, ensure that the AbsoluteAgent.dat and AbsoluteAgent.sig files are in the same folder as the .pkg file. Agent installation cannot be completed if these files are not present.
You can use the command line or the InstallShield wizard to run the full agent installer locally on a Mac device.
To install the agent using the command line:
-
Open a Terminal window and browse to the location where you extracted the downloaded zip file.
IMPORTANT If you have copied the .pkg file to another location, ensure that the AbsoluteAgent.dat and AbsoluteAgent.sig files are in the same folder as the .pkg file. Agent installation cannot be completed if these files are not present.
-
Run one of the following commands depending on the installer you want to use:
- When prompted, type the Administrator password for the Mac device and press Enter.
-
When the following message shows, the files are installed:
installer: The install was successful.
To install the agent using the Installer interface:
-
Browse to the location where you extracted the downloaded zip file.
IMPORTANT If you have copied the .pkg file to another location, ensure that the AbsoluteAgent.dat and AbsoluteAgent.sig files are in the same folder as the .pkg file. Agent installation cannot be completed if these files are not present.
- Double-click the applicable .pkg file to open the Installer interface and then click Continue.
-
To change the location where the agent is installed:
- Click Change Install Location.
- On the Select a Destination page, select the disk where you want to install the agent.
- Click Continue.
- Click Install to perform a standard installation of the agent and to open the password dialog.
- In the Password field, enter the Administrator password for the Mac device and click Install Software. When you see a confirmation message, the agent is installed successfully.
- Click Close.
After installation, the agent connects to the Absolute Monitoring Center and receives a unique Identifier. You can verify that the agent was installed successfully on your devices in the following ways:
Verify that an agent is activated and that it can successfully connect to Absolute Monitoring Center.
To verify agent installation:
- Ensure that the device is connected to the Internet.
- Download the Agent Management Tool from the Utilities page in the Settings area.
- Start the Agent Management Tool.
-
Review the following fields on the Status page:
- Agent Version
- Agent Mode: confirm that the value is Active.
-
ESN: shows the unique Electronic Serial Number assigned to the device's agent. In the console, a device's ESN shows in the Identifier field. For activated agents, the last four characters of the ESN are greater than 0000.
If the last four characters are 0000, the device failed to contact the Absolute Monitoring Center. Force a test call. The Call Status shows on screen.
-
Last IP Call Time: shows the date and time of the most recent successful agent call.
If the Last IP Call Time field shows No last call, the device failed to contact the Absolute Monitoring Center. Force a test call.
- Next IP Call Time: the date and time of the next scheduled agent call.
You can verify that an agent is activated by reviewing the Activation report in the Secure Endpoint Console.
To verify the agent installation using the console:
- Log in to the Secure Endpoint Console as an Administrator.
- On the navigation bar, click Reports.
- Under Categories, click Device, and then click Activation to open the Activation report.
It may take several minutes to process the device's information and make it available in the console. The data in the Activation report is sorted in descending order by Activation date, so the newly activated device should show at or near the top of the result grid. If it doesn't show, the device has failed to contact the Absolute Monitoring Center. If so, you can force a test call.
You can install the agent on multiple devices using disk imaging, which is used to copy standard applications onto unconfigured devices. Incorporating the full agent installer onto disk images helps to ensure that the agent is fully functional on all Mac devices that you want to manage in Absolute.
To ensure that the agent is fully functional on all devices:
Step 1: Incorporate the full agent installer into a disk image on a single (source) computer.
Step 2: Use a disk imaging program to create a complete image of the source computer’s hard disk, including the agent installer.
Step 3: Copy this disk image to any number of identical computers (referred to as target devices).
When you create an image in this manner, the agent is unactivated and shows a generic Identifier (with an ESN that ends in 0000). After the image is deployed to each target device and the device is restarted, the agent contacts the Absolute Monitoring Center for activation and assignment of a unique Identifier.
To create a standard disk image on a source computer for your Mac devices:
-
Prepare the source computer as follows:
- On a newly formatted computer, install all software that you want to include in the disk image for your organization.
- Ensure that the computer does not already have an Secure Endpoint Agent installed.
- Use a virus-scanning program to ensure that the source computer is free from viruses.
NOTE There is no requirement for network or Internet connectivity while you create the disk image. The source computer may be connected or disconnected.
- Download the full agent installer for Mac.
-
Open a Terminal window and browse to the location where you extracted the downloaded zip file.
IMPORTANT If you have copied the .pkg file to another location, ensure that the AbsoluteAgent.dat and AbsoluteAgent.sig files are in the same folder as the .pkg file. Agent installation cannot be completed if these files are not present.
-
Run the following command:
Copycp AbsoluteFullAgent.pkg /tmp ; touch /tmp/createImageFlag ; sudo installer -pkg /tmp/FullAgent.pkg -target / ; rm /tmp/FullAgent.pkg /tmp/createImageFlag
IMPORTANT Do not restart the source computer. Do not trigger an agent call.
After a restart, the agent contacts the Absolute Monitoring Center to receive a unique Identifier. It is imperative that the agent is not able to secure a unique Identifier before you create the disk image. - Use the Agent Management Tool to verify that the Identifier ends in 0000, which indicates that the agent is not activated.
-
Use the disk imaging software of your choice to create a hard disk image of the source computer.
NOTE The process of creating a disk image varies depending on your software. For more information on creating a disk image, refer to the user guide for your disk imaging software.
-
Test the new disk image as follows:
- Deploy the disk image to a target device.
- Connect the target device to the Internet if it is disconnected.
- Restart the target device to initiate an agent call.
- Use the Agent Management Tool to verify that the target device’s agent has received a unique identifier (that is, the ESN field on the Status page does not end with 0000).