What you are seeing
Either of these, on a Mac that is otherwise enrolled and reporting in:- Finish protecting this device keeps showing Trust the AgenShield certificate, and completing it does not clear the card.
- The AgenShield menu bar item offers no Trust Certificate action at all.
- The Frontegg Portal shows the device as Degraded, with a tooltip naming the certificate step.
What this means
The certificate itself was created on this Mac. What did not happen is the second half — recording it as trusted in the system keychain, which needs an administrator password. Until that completes:- Encrypted (HTTPS) traffic is not inspected. Network observation runs degraded.
- Everything else is unaffected. The security and network extensions keep enforcing, your organization’s policy keeps syncing, and command and file activity keeps being recorded.
The most common cause: nobody was at the keyboard
If AgenShield was installed by your IT team without anyone signed in — a zero-touch deployment, or an install that ran overnight — the Mac was almost certainly at the login screen or locked. The certificate step needs the Mac unlocked, because it needs a user session and an administrator password. It cannot complete on a locked Mac and it will not retry on a timer; it waits for someone to unlock. If that describes your Mac, unlock it and sign in. That lets the step proceed — but it does not finish on its own: macOS still has to ask for an administrator password, and someone has to approve that prompt.- If a password prompt appears, approve it.
- If no prompt appears, open the AgenShield menu bar item and choose Trust Certificate to trigger it.
How to confirm
Run this in Terminal:- “certificate verification successful” — trust is in place. If the card is still showing, it is stale; quit and reopen AgenShield.
- Anything else — trust is genuinely missing. Continue below.
How to fix it
First, use the app. Open the AgenShield menu bar item and choose Trust Certificate, then enter your administrator password when macOS asks. This is the supported path and it is the one that keeps the app’s own state in step. If the option is missing or the prompt never appears, do not install the certificate by hand. Trusting a certificate authority changes how every encrypted connection on the Mac is validated, so it is not a step to apply from a copied command — collect diagnostics and contact support, who have a supported repair for this state. See When to escalate below.Administrator rights are needed only to approve the interactive prompt.
AgenShield tries the non-interactive route first and, where that succeeds, no
password is asked for at all — so a standard-user account is not automatically
blocked here.When the prompt is required and your account is a standard user, someone with
administrator rights has to approve it. Fleets can remove the per-device step
entirely by distributing the certificate through MDM — see
MDM deployment.
If it comes back
- You dismissed the password prompt once. AgenShield deliberately does not re-ask automatically — repeatedly prompting for a password nobody wanted to give is worse than waiting. Use Trust Certificate from the menu bar when you are ready.
- It reappears after every update. That is a different problem with a different cause — see Certificate prompt after update.
- It reappears on many Macs at once. Ask your IT team whether your organization can distribute a company-wide certificate through MDM, which removes the per-device step entirely. See MDM deployment.
Seeing it across the fleet
In the Frontegg Portal, Devices → the Setup filter narrows the list to every device still waiting on the certificate, so you can tell one stuck Mac from a rollout-wide gap. See Fleet setup status.When to escalate
Collect diagnostics and contact support if:~/.agenshield/mitm-ca.pemdoes not exist even after the Mac has been unlocked and signed in for a few minutes;verify-certstill fails right after theadd-trusted-certcommand reports success;- the step clears and then returns without an update having been installed.