Skip to main content
Installing AgenShield is not the last step on macOS. Several parts of setup need a person at the keyboard — approving a security extension, granting Full Disk Access, trusting the certificate that lets AgenShield inspect encrypted traffic. Until those are done, the device is enrolled and reporting in, but it is not enforcing everything your policy asks of it. The AgenShield app on each Mac has always shown its own remaining steps under Finish protecting this device. The Frontegg Portal now shows the same steps for every device, so you do not have to ask people one at a time.

Where to look

Devices → the Status column. A device with unfinished setup reads Degraded instead of Online. Hover it and the tooltip names the step that is outstanding, and how many others there are.
A device only reports setup status while it is actually checking in. An Offline device keeps the Offline label — the last thing it told us may no longer be true, so the Portal does not present it as current.
Devices → the Setup filter. Pick a step to narrow the list to just the devices that need it. This is the fastest way to answer “how many Macs are waiting on the certificate?” before an upgrade or an audit. A device’s detail view → Unfinished setup. The full list for that one machine, worst first, with a sentence explaining what is off until it is fixed.

What the steps mean

Some steps stop protection outright. Others switch off one capability and leave the rest working. The Portal shows the more serious kind in red and the rest in amber.

Fixing them

Every one of these is fixed on the device, not in the Portal, and the AgenShield app on that Mac gives the exact steps for its own macOS version — including a button that opens the right System Settings pane. Point the person at Finish protecting this device in the app rather than relaying steps yourself; the wording differs between macOS versions and the app already knows which one it is on. Two shortcuts worth knowing:
  • Managed fleets can skip the approval prompts. A configuration profile pushed through your MDM pre-approves the extensions, so nobody has to click anything. See MDM deployment.
  • The duplicate filter entry is removed automatically on upgrade, and the app offers a one-click Remove duplicate now button. See Duplicate filter entries.

If a step will not clear

The Portal reflects what the device reports, on a short delay — give it a minute after someone completes a step. If it persists:
  • The step is done on the Mac but the Portal still shows it — confirm the device is Online, not Offline; a device that has stopped checking in cannot update its status.
  • The step keeps coming back — the setting is being switched off again, either by a person or by another management tool.
  • Nothing changes and the app offers no way forward — collect diagnostics from that Mac and contact support. See Collecting diagnostics.