What you are seeing
In System Settings → Network → Filters & Proxies, the list shows AgenShield more than once — typically two Content Filter rows (one may say Disabled) plus one Transparent Proxy row.What this means
Only one AgenShield network extension is installed and running. Updating AgenShield replaces the extension in place — it never installs a second copy. Two AgenShield rows are normal: one Content Filter plus one Transparent Proxy. Each row in this list is a stored configuration entry, and AgenShield uses both kinds. What is not normal is seeing the Content Filter type twice. That extra row is a redundant configuration entry. It appears when AgenShield was installed before your company’s configuration profile reached the Mac: the app created its own entry at install, and the profile later added the one your organization manages. macOS keeps both — it even renames the second one (for example AgenShield Network Filter 1). Less commonly, an update raced the system’s configuration store and left an orphaned entry. A duplicate carries no extra traffic, but it is confusing and can interfere with AgenShield’s automatic network recovery, so it is worth removing. On a company-managed Mac the entry provided by your organization’s profile is the one that should stay: your IT admin controls it, and AgenShield treats it as the owner of network filtering.How to confirm
- Open System Settings → Network, scroll to Filters & Proxies.
- Count the rows named like AgenShield Network Filter with type Content Filter. One is correct; two or more means a duplicate.
- AgenShield also detects this automatically and shows a “Duplicate network filter entry” card on the dashboard’s Overview page. The card names each entry it found and marks the one provided by your company’s profile.
How to fix it
On a company-managed Mac, usually nothing. Where the cleanup is supported — your company’s profile provides the filter entry and it is switched on — AgenShield attempts to remove the entry it created itself, silently and with no click or password, within about a minute of noticing the duplicate. The dashboard card reads “The extra entry is removed automatically — no action needed” and disappears once the entry is gone. Network filtering keeps working throughout: the entry your company’s profile provides stays in place and active. The attempt is not a guarantee. Some states cannot be cleaned up from the Mac at all — for example when the company profile’s entry is switched off, or when the profile installed its entry more than once. The dashboard card’s status line is the authority on what actually happened: if the card is still there, read it before doing anything, then follow the manual steps below or bring in your IT admin as the card directs. If the card keeps showing, read its status line — it tells you what it is waiting for:- “waiting for the upgrade to finish” / “waiting for the installer” — the cleanup runs once the install or update completes.
- “waiting for the network extension to be active” — approve or turn on the AgenShield network extension first (the Overview page has a card for that too).
- “didn’t finish — remove the entry now” — click Remove entry. No password is needed on a normally installed Mac; the card says so next to the button.
- “Company filter profile is switched off” — your organization’s entry exists but is disabled, so AgenShield deliberately kept its own entry to keep this Mac filtered. Ask your IT admin to enable the profile’s filter entry; the extra entry is then removed automatically.
- “more than once” — your organization’s profile installed the entry twice. Only your IT admin or MDM can collapse profile-installed entries.
DEDUP_OK (removed), DEDUP_BLOCKED (kept everything
on purpose — the output names the reason), or DEDUP_NOT_NEEDED.
If it comes back or won’t remove
- An entry that cannot be removed by you is owned by your company’s profile. That is expected — it is the entry that should stay. If it is the one you want gone (for example after leaving the organization), ask your IT admin to retire the profile in the MDM console; removing the profile removes its entry.
-
Version notes. Up to and including
2026.8.5the card kept offering the button and gave no feedback when it achieved nothing.2026.8.6corrected the reporting. Up to and including2026.9.0the repair could only address whichever entry macOS happened to hand it — on some Macs that was the profile-provided one, so the app’s own entry was never removed and the manual step above was the only way out; the repair also asked for a password. From2026.9.1the app’s own entry is identified directly and removed automatically and silently wherever the cleanup is supported; where it is not, the dashboard card says which state the Mac is in instead of retrying. -
If AgenShield reports that no filter is active, read which entry it names —
the two cases need opposite responses, and this is reported whether or not the
extra entry was removed, because an inactive filter is the more urgent fact.
- “ask your IT admin to enable the remaining entry” — the surviving entry is your company profile’s and it is switched off. Only your IT admin can change that: a company entry that is switched off reads as a deliberate choice, so AgenShield leaves it alone rather than overriding it.
- “no action is needed” — AgenShield removed the duplicate and is waiting to re-create its own entry until it can confirm the network extension is active. It restores filtering by itself, usually within a minute or two. Turning a filter on before that confirmation can cut the Mac off the network, so the wait is deliberate. Nothing is required from you or your IT admin; if it has not cleared after a few minutes, collect diagnostics.
- If the duplicate reappears after an update, collect diagnostics (see Collecting diagnostics) and contact support with the screenshot of the Filters & Proxies list.