# After the ElasticEndpoint enables full disk access, it is closed after a period of time

**URL:** <https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243>\
**Category:** Endpoint Security\
**Created:** [February 27, 2024, 2:41pm UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243 "2024-02-27T14:41:50Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [February 27, 2024, 2:41pm UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/1 "2024-02-27T14:41:50Z")

</div>

Elastic agent version: 8.9.1  
Mac versions: 14.0, 14.1  
Problem Description:  
After installing the Elatic Agent, full disk access was enabled, and the logs were all normal. However, after running for 1-2 days, the full disk access was turned off, causing the Elatic Agent log to be abnormal. Then enable full disk access again. A few days later, the same situation occurred again. Does anyone know what the problem is? What's the solution?

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [February 28, 2024, 2:39pm UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/2 "2024-02-28T14:39:06Z")

</div>

Hi @xqaiviwjxzw!

Have you granted permission to Elastic Agent or Endpointe security? I saw in some sources that you need to assign the permission to Elastic Endpoint. Below are the resources researched:

> <https://github.com/elastic/security-docs/issues/334>
>
> This page https://www.elastic.co/guide/en/security/master/sensor-full-disk-acces…s.html gives directions for enabling full disk access on macOS.
> 
> The document is slightly wrong for Elastic and is missing an image. The page ends with this text
> 
> \`\`\`
> 5. Click the + button to view Finder. Navigate to the /Library/Endgame directory, select the elastic-agent or esensor file, and then click Open.
> 6. In the Privacy tab, confirm that the elastic-agent or esensor file appears in the list of applications that have full access permission, as seen in the following image:
> 
> Elastic Endpoint Security now has the access required to fully protect your system.
> \`\`\`
> 
> The two issues are that
> 1. While \`esensor\` lives in \`/Library/Endgame\`, \`elastic-endpoint\` is found in \`/Library/Elastic/Endpoint/elastic-endpoint\`
> 2. There is no image following the text \`as seen in the following image\`

> **[Install Elastic Endpoint manually on macOS Ventura and higher | Elastic...](https://www.elastic.co/guide/en/security/current/deploy-elastic-endpoint-ven.html#enable-fda-endpoint-ven)**

Another possibility would be to update the Elastic Agent. Currently, it is in version 8.12.2.

---

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [February 29, 2024, 7:55am UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/3 "2024-02-29T07:55:22Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/6/5/65d754b2e5b6c3f344523ba659c2f9d4424515f6.jpeg)

@wsouza Thank you for your reply. When the installation was completed, elasticendpoint was turned on and the logs were normal. However, after running for 1 day, I found that elasticendpoint was closed and the logs were abnormal.

---

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [February 29, 2024, 8:02am UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/4 "2024-02-29T08:02:11Z")

</div>

@wsouza Can upgrading the current 8.9.1 version to 8.12.2 solve the problem?

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [February 29, 2024, 1:17pm UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/5 "2024-02-29T13:17:17Z")

</div>

It may be an alternative to try updating the elastic agent to see if the problem is resolved. Is your system also up to date?

---

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [February 29, 2024, 2:25pm UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/6 "2024-02-29T14:25:22Z")

</div>

@wsouza Problems were found in macos systems 14.0 and 14.1, which are not the latest macos systems. Is there any other way besides upgrading the version?

---

<div class="post-metadata">

**Author:** ![wsouza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wsouza/32/92547_2.png) [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Post date:** [February 29, 2024, 2:29pm UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/7 "2024-02-29T14:29:19Z")

</div>

As I mentioned, I just made a suggestion to perform the update. Therefore, I cannot guarantee that it would be a definitive solution since I do not have the same environment to carry out the tests.

---

<div class="post-metadata">

**Author:** ![ricardo2197](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@ricardo2197](https://discuss.elastic.co/u/ricardo2197)\
**Post date:** [March 4, 2024, 9:30am UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/8 "2024-03-04T09:30:16Z")

</div>

Hi @xqaiviwjxzw!

I know this is an issue you were reporting in the last couple of months. Agent and Endpoint cannot either grant or revoke FDA by themselves. There are 2 situations that would result in the behavior that you are seeing:

- 3rd party program would interfere with Agent or Endpoint invalidating the their signature
- 3rd party software leverages `tccutil` command to modify the TCC state.

I've personally running 8.10 on macOS 14.0 for over 2 months and Full Disk Access wasn't ever altered.

---

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [March 7, 2024, 3:40am UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/9 "2024-03-07T03:40:51Z")

</div>

@ricardo2197 thank you for your reply. I'm currently using version 8.9.1. I recently tried version 8.10. There is currently no such problem found in version 8.10. I feel that version 8.9.1 may have some kind of conflict with the system or other software?

---

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [March 7, 2024, 3:46am UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/10 "2024-03-07T03:46:21Z")

</div>

@ricardo2197 Which version of 8.10 are you using? Which version among 8.10.0-8.10.4? I will try to install this version and take a look, thanks

---

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [April 3, 2024, 2:01am UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/11 "2024-04-03T02:01:25Z")

</div>

@wsouza @ricardo2197  
After installing elastic agent 8.10.1, 8.12.2, 8.13.0, 8.13.1 in macos14.1, a situation occurs. After the installation is complete, full access permissions enable ElasticEndpoint permissions. ElasticEndpoint permissions are turned off once when the computer is shut down and restarted. Has anyone encountered this situation? Or is it related to macos system?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/6/d60bf78ba87b78e29184189a9d66f06284329df2.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2024, 2:01am UTC](https://discuss.elastic.co/t/after-the-elasticendpoint-enables-full-disk-access-it-is-closed-after-a-period-of-time/354243/12 "2024-05-01T02:01:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
