For IT departments

ShareDesk on every Mac in your company.

Install ShareDesk with your device management (Jamf Pro, Microsoft Intune, Kandji, Mosyle, Munki …), lock its settings with a configuration profile and prepare the permissions macOS asks for. Then your IT team reaches every Mac, also unattended.

Download the installer packageTalk to us

The installer package

One package for all Macs with macOS 12.3 or later, Apple silicon and Intel:

Download ShareDesk.pkg

ShareDesk then updates itself. If you prefer to roll out updates yourself, switch automatic updates off with the profile (SUEnableAutomaticChecks, below) and deploy the new package. For Macs with macOS 10.15 to 12.2, use the version for older Macs (a zip, the complete app).

Settings by configuration profile

macOS passes the values of a profile to ShareDesk ahead of the user's own. A setting set by a profile is locked in the app, which shows “Set by your organization”. Use a Custom Settings payload (Jamf: Application & Custom Settings; Intune: Preference file) for the preference domain ch.marketvision.sharedesk.

The allow… switches are on by default; false turns a feature off on that Mac for every technician and session, and the connection request no longer offers it.

KeyTypeMeaning
allowRemoteControlBooleanMouse and keyboard control (false: technicians only see the screen)
allowClipboardBooleanShared clipboard
allowFileTransferBooleanSending, receiving and browsing files
allowSoundBooleanHearing this Mac's sound
allowMicrophoneBooleanTechnicians hearing the person at this Mac through its microphone
allowTerminalBooleanRemote terminal
allowTCPTunnelsBooleanTCP tunnels to services in this Mac's network
allowPrivateNetworkBooleanPrivate network (VPN) between this Mac and a technician's
allowNetworkAccessBooleanReaching devices of this Mac's network through the private network (the user is still asked)
allowPrintingBooleanPrinting on the technician's printer
allowUnattendedAccessBooleanUnattended access with a password (false: every connection must be accepted at the Mac)
accessModeStringeveryone (after accepting) or allowlist (only IDs and addresses on the allow list)
accessAllowlistArray of StringShareDesk IDs or IP addresses; * as a wildcard (192.168.1.*)
accessBlocklistArray of StringRefused without asking, same format
lockOnSessionEndStringnever, locked (if it was locked when the session began; default), unattended, always
logIncomingSessionsBooleanKeep a log of the sessions on this Mac
printJobsWithoutAskingBooleanPrint the technician's print jobs without asking
tunnelScopeStringmac, network (default) or any: how far TCP tunnels reach
showMenuBarItemBooleanKeep running in the menu bar when the window is closed
startHiddenAtLoginBooleanStart in the background (menu bar only) at login
SUEnableAutomaticChecksBooleanCheck for updates automatically
SUAutomaticallyUpdateBooleanInstall updates automatically

Example: no terminal, only the IT department's ShareDesk IDs, and the Mac locks after every session. Change the IDs, then sign the profile with your MDM.

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>PayloadContent</key>
    <array>
        <dict>
            <key>PayloadType</key>          <string>ch.marketvision.sharedesk</string>
            <key>PayloadIdentifier</key>    <string>ch.marketvision.sharedesk.settings</string>
            <key>PayloadUUID</key>          <string>CAB651A5-5AC8-43F3-8C64-6E17A6D16067</string>
            <key>PayloadVersion</key>       <integer>1</integer>
            <key>PayloadDisplayName</key>   <string>ShareDesk</string>
            <key>allowTerminal</key>        <false/>
            <key>accessMode</key>           <string>allowlist</string>
            <key>accessAllowlist</key>
            <array><string>123456789</string><string>987654321</string></array>
            <key>lockOnSessionEnd</key>     <string>always</string>
        </dict>
    </array>
    <key>PayloadType</key>        <string>Configuration</string>
    <key>PayloadIdentifier</key>  <string>ch.marketvision.sharedesk.profile</string>
    <key>PayloadUUID</key>        <string>B4795054-CD27-4F39-A9CC-7A7FBFC84C69</string>
    <key>PayloadVersion</key>     <integer>1</integer>
    <key>PayloadDisplayName</key> <string>ShareDesk settings</string>
    <key>PayloadScope</key>       <string>System</string>
</dict>
</plist>

Permissions: what MDM can and can't do

ShareDesk needs Screen Recording to show the screen and Accessibility for the technician's mouse and keyboard. Apple decides what a Privacy Preferences Policy Control (PPPC) payload may do:

MDM can

  • allow Accessibility outright;
  • allow Full Disk Access, so files work without questions from macOS;
  • let users without administrator rights allow Screen Recording themselves (Allow Standard User to Set System Service, macOS 11 and later).

MDM can't

  • allow Screen Recording by itself: Apple reserves that for the person at the Mac, who turns it on once;
  • allow the microphone: macOS asks the user the first time it is used.

So plan one step per Mac: the user opens ShareDesk and turns on Screen Recording when it asks (or the first time a technician connects; the request is refused until then, with a note saying why).

Identifierch.marketvision.sharedesk (bundle ID)
Code requirementanchor apple generic and identifier "ch.marketvision.sharedesk" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "6AD6SHV34D")

Start at login

With showMenuBarItem and startHiddenAtLogin, ShareDesk keeps running in the menu bar. When the user turns on “Start ShareDesk at login”, ShareDesk adds itself as a login item. A Managed Login Items payload (macOS 13 and later) with the rule Team Identifier 6AD6SHV34D keeps users from switching it off in System Settings.

Unattended access for your IT team

Whatever you choose, the person at the Mac always sees a banner during a session and can end it.

Private network (VPN, beta)

The private network between a Mac and a technician's needs a small helper. ShareDesk installs it the first time it is used, with an administrator's password; for managed Macs it can also be installed ahead of time by an MDM script – ask us for it. With allowPrivateNetwork false it is never used.

Windows: Group Policy

The Windows app reads the same switches from the registry, under HKLM\SOFTWARE\Policies\MarketVision\ShareDesk (else the same path under HKCU). Set them with Group Policy Preferences, Intune or reg add; a value set there is locked in the app.

ValueTypeMeaning
allowRemoteControl, allowClipboard, allowFileTransfer, allowSound, allowTerminal, allowTCPTunnels, allowPrintingDWORD0 switches the feature off
allowUnattendedAccessDWORD0 switches unattended access off
tunnelScopeStringcomputer, network or any
lockOnEndStringnever, locked, unattended or always
logIncomingSessions, automaticUpdatesDWORD1 or 0
reg add "HKLM\SOFTWARE\Policies\MarketVision\ShareDesk" /v allowTerminal /t REG_DWORD /d 0 /f

For IT service providers: your branding

Supporting other companies' Macs? Give them ShareDesk from your own link: the app shows your logo and contact, and you get a customer page with a short link and downloads of your own. See branding for IT companies. Your team works from one shared address book, with organisations, departments and hourly rates per customer.

Connect it to your other tools

API keys read the session log, the address books and the brandings, and webhooks tell your ticket system or inventory when something happens: the API and webhooks for developers.

Questions about a rollout?

Write to us – we help with profiles, scripts and licences for your team.

info@marketvision.ch