Home

> Case studies

> macOS endpoints

Copyright © 2026 Kelly Murphy. All rights reserved. This document is strictly confidential and personal to its recipients. It should not be copied, distributed, or reproduced in part or whole, or passed on to any third parties.

Work in progress: Thank you for your patience (Just need samples? Open my Google Drive folder)

Dammit, Apple.

Installing the Huntress Agent on macOS endpoints

A long-range, multi-prong effort to lessen the complexities of working with third-party products that have a non-intuitive UI features, as well as enabling IT teams that didn’t have macOS technical chops. During this time, I was the institutional memory that kept this effort from constantly restarting as this work went through 3 different PMs, 3 Designers, and intermittent PMM support.

Background

TL;DR: The native Apple UI and IT teams lack of familiarity with Apple made protecting macOS endpoints harder

There is a myth that macOS endpoints don’t get hacked (they do, more than you’d think). Rising in popularity, macOS endpoints are more common in the workplace due to its user-friendly UIs and seamless integration with mobile devices. The Huntress Agent gets installed on the endpoint to communicate back with the platform, for monitoring by the SOC team. Installing the Agent on Windows endpoints is quick, nearly silent to the end user, and it’s easy to deploy to huge networks. Not so with macOS, for a number of reasons, several of them out of Huntress’ control.

​

Complicating this, many IT folks and MSPs are not as familiar with how to even manage macOS endpoints. Plus third-party RMM/MDM tooling to manage endpoints and control security policies rarely come in the same package, and pursuing a partnership with Apple never materialized.

​

All of this made deploying the Huntress Agent to macOS endpoints a complicated endeavor.

​

In June of 2024, we started tracking the hard data. We found that we had 37,160 Agents deployed to macOS endpoints but only 8,165 endpoints were fully configured for EDR protection, a mere fraction of them.

Context

When I joined Huntress, the work had already begun on the Agent for macOS, but they hadn’t made much progress. It seemed like every time we overcame something, another issue would crop up.

The challenge was twofold:

​

  1. Third-party tooling challenges: The PM & Eng teams needed to do discovery on what the real issues were, so the PM and I created a first survey to find out how MSPs were supporting their current macOS endpoints and how much of their business was Macs. We got back a dizzying array of RMM and MDM tools, used in several ways, so knowledgebase articles (KBs) and install scripts for each tool were pushed out as fast as we could. This led to a sprawl of 27+ KB articles before I stepped in.
  2. Extra deployment steps for macOS UI: Even the data we got back didn’t have the same protection parity as Windows data, so the Enginnering team figured out that after installing our Agent, MSP folks also need to install an extension and a network content filter—as well as granting Full Disk Access (FDA) to our Agent. However, macOS UI strongly tries to discourage users from installing unknown third-party tools, so we also had to overcome intuitive Apple design choices.

Business Goals

Endpoint protection for all

  • Expand our endpoint market
  • Streamline onboarding endpoints
  • Parity with the Windows data
  • Reduce Support tickets
  • Encourage large-scale deployments

My Role

I influenced this work in so many ways through the years:

​

Discovery

  • Initial discovery survey
  • Updated deployment scripts in GitHub

​

System design

  • Rearchitected all of the KB sprawl for the Support team
  • Partnered with Design & PM to create a UI to manage macOS install status
  • Revised the Agent Download UI, twice
  • Partnered with Design & Eng to create an installation wizard

​

Cross-functional enablement

  • Reviewed installation video created PMM and marketing for technical accuracy and terminology
  • Suggested PM+Support+SE macOS office hours for MSPs

Results

Lots of incremental changes for a big win

It’s hard to simplify so many touchpoints along the way, but there is a write up available for a snapshot of time where we saw a big jump in MSPs installing and fully configuring their macOS endpoints that correlates directly to my efforts.

​

In June 2024, there were 37,160 Agents deployed to macOS but only 8,165 of those Agents were fully configured for EDR protection. By August 30, 2024, we saw a total of 41,847 Agents deployed to macOS endpoints. Of those, 13,705 endpoints are fully configured for Huntress EDR, which is an almost 10% increase in just two months.

​

The KB sprawl started as 27+ articles that were not linked together and I got them down to 13, with one main article and then revising the specific articles for each third-party RMM/MDM vendor install process. I had to walk each of those UIs and scripts to make sure they were accurate.

​

Outcome

​

As of February 2026, there are 95k Huntress Agents installed on macOS endpoints and 81k are fully configured, more than double the Agents by count and a 160% increase in fully configured Agents.