# SAP/macOS-enterprise-privileges

This application gives Mac users in enterprise environments control over the administration of their machines by elevating their access level to administrator privileges on macOS. Users can set a timeframe in the application's settings to perform specific tasks, such as installing or uninstalling applications.

Repository: https://github.com/SAP/macOS-enterprise-privileges
Canonical: https://ross.abutalabs.com/products/macos-enterprise-privileges
Language: Objective-C
License: Apache-2.0
License Family: permissive
Topics: open-source, macos, privileges
Last push: 2026-08-11T09:47:21+00:00

## Health v2 (maintenance only)
Score: 89/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 72, longevity 100
- inputs: {"age_days": 2989, "days_push": 22, "days_rel": 110, "gap_med": 58.0, "n_releases_24m": 11}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2043, forks 179 (observed 2026-08-28T04:06:08.729874+00:00)

## What it is
Privileges is a free macOS application from SAP that lets enterprise users temporarily elevate their accounts to administrator rights for a set timeframe. It supports MDM configuration, a command-line tool, smart card authentication, and works fully offline.

## Use cases
- temporarily grant admin rights on a managed mac
- install software without permanent administrator access
- revoke admin rights at login for security
- manage mac admin policy via mdm configuration profiles
- elevate privileges from the command line with touch id
- run standard user accounts as a security best practice

## When to choose
- you manage a fleet of macs in an enterprise and want least-privilege access
- users occasionally need admin rights for installs but should not keep them permanently
- you need offline, MDM-manageable privilege elevation with CLI and webhook support

## When to avoid
- you need network-centralized privilege auditing or approval workflows
- you are not on macOS
- you need per-command sudo policy control rather than account-level elevation

## Facets
- artifact type: application
- maturity: active
- function: security, cli, gui
- domain: security, operating-systems, erp, self-hosted
- platform: -
- tags: admin-privileges, mdm, privilege-elevation, enterprise-it, temporary-admin-rights, macos

## Member repositories
- SAP/macOS-enterprise-privileges (main) score 89

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:08.729874+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:58:06.167942+00:00, confidence not recorded.
  - readme: https://github.com/SAP/macOS-enterprise-privileges (fetched 2026-08-28T04:06:08.729874+00:00, sha 000c54c0251d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
