New features
Elevation cooldown
Stop users from chaining back-to-back admin sessions. Once an elevated session ends, the Mac can't elevate again until a cooldown period you set has passed.
- Applies everywhere a session can end: the Elevate24 app, the CLI, and automatic session expiry
- Enforced per computer and resistant to clock changes, so it can't be bypassed by adjusting the system time
- Users see a live countdown in the Elevate24 window, so they always know when they can elevate again
| Key | Domain | Type | Default | Notes |
|---|---|---|---|---|
CooldownMinutes
| com.jigsaw24.elevate24
| Integer (minutes) | 0
| 0 disables the cooldown.
|
Helpdesk cooldown override (works offline)
If a user genuinely needs admin rights during a cooldown, your helpdesk can issue a one-time code that clears it, even when the Mac is offline.
- Codes are single-use and rate-limited
- Backed by the Mac's Secure Enclave, so no reusable secret is stored on the device
Requirements: a Mac with a Secure Enclave (Apple silicon or T2), accurate system clock, and a login to the Elevate24 portal for override codes.
| Key | Domain | Type | Default | Notes |
|---|---|---|---|---|
CooldownOverrideEnabled
| com.jigsaw24.elevate24
| Boolean | false
| Enables enrollment and the override option. |
CooldownOverrideMessage
| com.jigsaw24.elevate24
| String | Built-in text | Your helpdesk contact text, shown in the override popover. |
Advanced reasons
Get better context for every elevation. You can now define reasons that require the user to add a short note, for example "Other – please explain" or "Installing software – which app?".
- The selected reason is logged to
Reasonand the user's note toReasonText, so both appear in your logs and SIEM
| Key | Domain | Type | Notes |
|---|---|---|---|
advancedReasons
| com.jigsaw24.elevate24
| Array of dictionaries | Each entry: reason (String), requireFreeText (Boolean), freeTextPlaceholder (String).
|
Block setuid-root execution for standard users
Close off a common route to root access. When enabled, standard users can no longer run setuid binaries that execute as root, unless you've explicitly allowed them. Apple platform binaries are always exempt.
| Key | Domain | Type | Default | Notes |
|---|---|---|---|---|
blockEffectiveRootUserFromStd
| Security Extension | Boolean | false
| Enables blocking. |
blockEffectiveRootUserAllowList
| Security Extension | Array of dictionaries | []
| Each entry: signingId and/or teamId. If both are set, both must match.
|
Before you enable this: allow-listing relies on code signing, so unsigned or ad-hoc signed tools can't be exempted. We recommend testing on a pilot group first to identify any third-party tools your users rely on.
CLI enhancements
-d– end the current elevated session immediately. If the Elevate24 app is open, it updates straight away.-note <text>– provide the note for a reason that requires one. If omitted, you'll be prompted.
Improvements
- The
killterminalsessionsfunction has been rebuilt for broader, more dependable coverage. - Process execution events now log the user who launched the process (real UID) plus a new
effectiveUsernamefield, making it easier to see who actually ran what, and as whom. - Fixes some UI glitches that are present in macOS Golden Gate.
- new
formatLogMessageSplunkkey ensures correct formatting of logs when using Splunk as the endpoint.