Elevating Activity Monitor

Authorizationdb Right: com.apple.activitymonitor.kill

This action can be used to elevate killing processes that do not belong to the logged in user in Activity Monitor while it is running. The right will be elevated for the duration that Activity Monitor is running. Once the application is quit, the right will be restored to its default.

Advanced message actions such as Approval, Deny, Justification, or Warning should not be used in conjunction with this action.

Example Application: Activity Monitor

  1. Using the Policy Wizard, create a controlling policy, click Next Step.

  2. Select Elevate, click Next Step.

  3. Select Run Silently, click Next Step.

  4. Select Executables, click Next Step.

  5. Select Modify Authorization Database, click Next Step.

  6. Select Existing Filter, search for select the App Bundle filter for Activity Monitor. If it doesn't exist, create it.

  7. Click Update.

  8. Click Next Step.

  9. Name your policy, add a description.

  10. From the Right Name drop-down, select Activity Monitor Kill Authorization Right (com.apple.activitymonitor.kill) for macOS versions older than Sequoia, or Activity Monitor Sudo Authorization Right (com.apple.activitymonitor.sudo) for macOS Sequoia and later. To support all macOS versions, the policy should include both rights (select one now, and add the other in Actions after creating the policy).

    activity monitor

  11. Click Create Policy.

  12. Set the Inactive switch to Active.

  13. Next to Deployment click the i icon and run the Resource and Collection Targeting Update task.

What to Expect on the Endpoint

  • With a policy in place, when Activity Monitor is running and the policy is effective and you try to kill a process that doesn't belong to you and you click Force Quit, the process will be terminated without prompting you for administrator credentials.

  • Without a policy in place, when Activity Monitor is running and you try to kill a process that doesn't belong to you, it will present this dialog:

    no policy