Datto RMM macOS agent 11994: steps after updating
Applies to: Datto RMM agents on macOS, agent version 11994 and later
Agent version 11994 fixes the macOS connectivity issue posted on the Kaseya Status Page. This version is signed with an updated Kaseya certificate. macOS treats it as a new app, so macOS permissions must be approved again on each Mac.
What you need to do depends on where the Mac is right now. Find your situation in the table, then follow that section. Every section ends by sending you to the same two steps: The background activity notification and Granting macOS permissions.
|
Your situation |
What you need to do |
Go to |
|---|---|---|
|
You're installing the agent on a Mac for the first time |
Install the agent, then grant permissions |
|
|
The Mac already has the agent and shows online in Datto RMM |
Nothing to install. The agent updates on its own. Approve the notification and permissions when they appear. |
|
|
The Mac already has the agent but shows offline in Datto RMM |
Install the new agent over the existing one |
|
|
You reinstalled on an offline Mac, but Web Remote still doesn't show up after 8 minutes |
Run a short reset in Terminal |
Before you start: someone with administrative privileges must be at the Mac to click through the macOS prompts, because Web Remote is not available until those prompts are approved. Changing them in System Settings also needs an administrator account, so have the admin username and password ready.
Use this if the Mac has never had the Datto RMM agent installed.
-
In Datto RMM, download the macOS agent installer for the site this Mac belongs to.
-
Run the installer on the Mac and follow the prompts until it finishes.
-
A macOS notification titled App Background Activity will appear. Follow The background activity notification.
-
Follow Granting macOS permissions to approve each prompt.
-
Check the device in Datto RMM. It should show as online.
Use this if the Mac already has the agent and shows as online in Datto RMM. You don't need to download or reinstall anything.
- Leave the Mac on and connected. The agent updates itself to version 11994.
- After the update, a notification titled App Background Activity appears on the Mac. Follow The background activity notification.
- The first time someone starts a Web Remote session to this Mac, macOS asks for permissions. Follow Granting macOS permissions.
Use this if the Mac already has the agent but shows as offline in Datto RMM. This often happens after the Mac was restarted while the issue was active. You do not need to uninstall the old agent first.
- In Datto RMM, download the macOS agent installer for the site this Mac belongs to.
- Run the installer on the Mac and follow the prompts until it finishes.
- The device comes back online in Datto RMM, and a notification titled App Background Activity appears on the Mac. Follow The background activity notification.
- Wait 5 to 8 minutes. During this time the agent updates Web Remote and its other components in the background. Leave the Mac on and connected.
- Start a Web Remote session to the Mac. macOS asks for permissions at this point. Follow Granting macOS permissions.
If the Web Remote option still is not available for the device after 8 minutes, go to Reinstall didn't work.
Use this only if you already followed Offline device and the Web Remote option still does not appear for the Mac. You will run three commands in Terminal on the Mac.
IMPORTANT Type these commands exactly as shown. The second command permanently deletes a folder. Copying and pasting them from this article is the safest option.
- On the Mac, open Terminal. You'll find it in Applications > Utilities, or press Command + Space, type
Terminal, and press Return. - Go to the agent's folder:
cd /usr/local/share/CentraStage - Delete the AEMAgent folder inside it:
sudo rm -rf AEMAgent/Terminal asks for a password. Type the Mac's administrator password and press Return. Nothing shows on screen while you type, which is normal.
-
Stop the agent service:
sudo launchctl stop com.centrastage.cag -
Wait about 10 seconds.
-
Open Finder, go to Applications, and double-click AEM Agent to start it again.
-
Check the device in Datto RMM. The Web Remote option should now be available.
-
Start a Web Remote session and follow Granting macOS permissions.
After the agent installs or updates, macOS shows this notification in the top-right corner of the screen:
You don't need to click anything. The notification tells you the agent is allowed to run in the background, and it needs to stay that way for the device to stay online.
If someone turned it off, here's how to turn it back on:
- Open System Settings and go to General > Login Items & Extensions.
- Under Allow in the Background, find Kaseya International and make sure its switch is on.
The agent needs four macOS permissions for Web Remote to work: Local Network, Screen & System Audio Recording, Accessibility, and Full Disk Access. MacOS asks for the first three with pop-ups. You turn on Full Disk Access yourself in System Settings.
The prompts show the app name as AEM Agent. That's the Datto RMM agent.
Local Network and Screen Recording
These two prompts usually appear at the same time.
-
On the Local Network prompt, click Allow.
-
On the Screen Recording prompt, click Open System Settings. Don't click Deny.
-
System Settings opens to Screen & System Audio Recording. Find AEM Agent in the list and turn its switch on. Enter the administrator password if macOS asks for it.
-
macOS then says AEM Agent may not be able to record the screen until it is quit. Click Quit & Reopen.
Accessibility
This lets Web Remote control the mouse and keyboard.
-
When the Accessibility Access prompt appears, click Open System Settings. Do not click Deny.
-
System Settings opens to Accessibility. Find AEM Agent and turn its switch on. Enter the administrator password if macOS asks for it.
Full Disk Access
macOS doesn't show a pop-up for this one, so you have to turn it on yourself.
-
Open System Settings and go to Privacy & Security > Full Disk Access.
-
Find AEM Agent and turn its switch on. Enter the administrator password if macOS asks for it.
Check that everything is on
Open System Settings, go to Privacy & Security, and confirm that AEM Agent is switched on in each of these pages:
- Local Network
- Screen & System Audio Recording
- Accessibility
- Full Disk Access
If one is missing or off, turn it on there. You do not need to wait for the prompt to come back.
Need help?
If a Mac still will not come online or Web Remote will not connect after these steps, contact our support team at https://helpdesk.kaseya.com/hc/en-gb#/contact. Include the device name and which section of this article you followed.
For updates on the original issue, subscribe to the Kaseya Status Page.






