/
/

How to Audit and Manage macOS System Extensions Across Managed Macs

by Lauren Ballejos, IT Editorial Expert
How to Audit and Manage macOS System Extensions Across Managed Macs
How to Audit and Manage macOS System Extensions Across Managed Macs

Key points:

  • macOS system extensions safely integrate apps such as security tools and VPN clients with the OS, but must be audited, as any extension can pose a threat.
  • A proper inventory tracks extension name, type, vendor, Team ID and bundle identifier, version, and device scope, plus context like approval status and review date.
  • Manual audits involve listing managed Macs, identifying installed extensions, and comparing them against approved vendor lists to flag outdated ones, but it doesn’t scale well.
  • MDM and RMM tools automate inventory and let IT approve or block extensions by Team ID or bundle identifier, test before deployment, and schedule recurring reports.
  • Treating audits as a one-time task is a key mistake; as extensions and macOS updates evolve, ongoing monitoring and attack-surface reduction are essential.

macOS system extensions present a potential security threat that must be governed and managed by IT teams and managed service providers (MSPs).

This guide explains how macOS system extensions work and how you can ensure they aren’t an invisible threat to your IT infrastructure.

What are macOS system extensions?

macOS system extensions are software that extend the macOS operating system. Their purpose is to allow apps like security tools, VPN clients, network filters, developer tools, and device drivers to integrate with macOS to add system functionality.

For example, for a network monitor and firewall app to work, it needs to be able to run in the background and access network activity so that it can see what apps are sending traffic and manage it. To do this, a macOS system extension is used to tap into additional networking functionality at the operating system level.

macOS system extensions replace KEXTs (kernel extensions), which served the same purpose, but were considered insecure and could threaten stability. Unlike KEXTs that once ran in kernel-space (the macOS operating system’s core, which should be kept highly privileged and secure) with almost unlimited access and control to the system, macOS system extensions run in user-space just like other apps and services, so they can be protected and controlled.

Why you need to audit macOS system extensions

Assuming KEXTs are entirely phased out on your Mac deployments by now (and they should be), you still need to audit macOS system extensions. Any piece of software can be a threat, whether it’s intentionally malicious, misconfigured, or contains a vulnerability. In some cases, software is perfectly safe until its update mechanism is hijacked, turning a benign app or extension into a malware threat.

Due to this potential impact on endpoint security, networking, device control, and compliance, macOS system extensions must be tracked by IT security teams.

How to inventory macOS system extensions

Auditing, followed by continuous monitoring, is required to keep an accurate and up-to-date software inventory that exposes vulnerabilities and threats.

A macOS system extension inventory should include the following details:

  • Extension name
  • Extension type
  • Related app or vendor name
  • Team ID and bundle identifier
  • Version
  • Device or user scope

You should also document additional context, such as the purpose/justification for the extension, last review date, approval status, and, in the case of any lingering legacy KEXT extensions, retirement/replacement status.

How to audit macOS system extensions

The above information should be obtainable using software inventory tools as part of your mobile device management (MDM) or remote monitoring and management (RMM) solution. This automates the process, reducing labor, and allowing for scheduled reports to be exported for long-term storage in your IT documentation platform.

Otherwise, you can periodically run a manual macOS system extension audit by:

  • Building a list of managed Macs and MacBooks in your organization
  • Identifying macOS system extensions, including security, VPN, filtering, EDR, backup, and device-control apps
  • Collect installed system extension details, including Team IDs and bundle identifiers
  • Comparing installed extensions against approved vendor lists
  • Identifying pending, inactive, outdated, or unknown extensions
  • Document which extensions should be approved, blocked, replaced, or retired

You should also manually check for any remaining KEXTs and find updated software that removes the need for them. For most teams, performing this manual process at scale is impractical and inefficient at best.

How to manage macOS system extensions with MDM

MDM and RMM should give you the ability to vet, approve, and deny macOS system extensions using policies, removing the need for manual intervention.

This should allow you to approve specific bundle/team identifiers, allow only approved extensions, test extensions before wider deployment, and review pending app and extension updates.

Common mistakes IT teams make when managing macOS system extensions

Treating macOS system extension auditing as a once-off task is a common mistake: it may prove that you’re secure at that moment, but it doesn’t prevent new extensions from appearing, nor does it prevent existing extensions from falling behind on critical security updates. It also doesn’t factor compatibility (for example, macOS updates may break extensions), so you need to know what needs to be updated.

You should ensure that all software on your endpoints is covered by your ongoing vulnerability management. You should also reduce your attack surface by reviewing your inventory regularly and removing software that is no longer required.

Automating macOS system extension auditing, and keeping a full cross-platform app inventory

Keeping a current, comprehensive catalog of all hardware and software is critical to maintaining IT visibility and security.

NinjaOne provides a unified IT management toolchain, combining MDM and RMM with automated discovery, inventory, vulnerability scanning, and built-in help desk and documentation. This helps ensure you know what is installed, what risk it poses, and can keep track of responsibilities, details, and exceptions.

FAQs

Run systemextensionsctl list in Terminal to see all installed system extensions, their status, and Team IDs. You can also check System Settings > Privacy & Security > Extensions for a GUI view.

System extensions are a requirement for many apps to function, including cybersecurity tools like antivirus and monitoring tools. However, as malicious or misconfigured extensions could present a security threat, they should be visible to IT teams.

KEXTs are the legacy way of extending macOS, and are loaded directly by the macOS kernel. The security and stability implications of this have led to their phase out in favor of macOS system extensions that operate under an improved security model, as well as offering more developer features.

System extensions were introduced in macOS Catalina (10.15) in 2019 as a KEXT replacement. Starting with macOS Sequoia, Apple began phasing out support for most legacy KEXTs entirely, making system extensions mandatory for many app categories.

Yes. MDM policies can approve (or block) system extensions across managed Macs when configured with the correct identifiers and scope.

You might also like

Ready to simplify the hardest parts of IT?