ShareDesk on every Mac in your company.
Install ShareDesk with your device management (Jamf Pro, Microsoft Intune, Kandji, Mosyle, Munki …), lock its settings with a configuration profile and prepare the permissions macOS asks for. Then your IT team reaches every Mac, also unattended.
Download the installer packageTalk to us
The installer package
One package for all Macs with macOS 12.3 or later, Apple silicon and Intel:
- Signed with Apple's Developer ID Installer certificate of MarketVision AG (Team ID
6AD6SHV34D) and notarized by Apple. - Installs
/Applications/ShareDesk.app; no other components. - The address always delivers the current version; each release publishes it anew.
- Upload it to Jamf Pro, Intune (macOS LOB app), Kandji, Mosyle or your Munki repository like any signed package.
ShareDesk then updates itself. If you prefer to roll out updates yourself, switch automatic updates off with the profile (SUEnableAutomaticChecks, below) and deploy the new package. For Macs with macOS 10.15 to 12.2, use the version for older Macs (a zip, the complete app).
Settings by configuration profile
macOS passes the values of a profile to ShareDesk ahead of the user's own. A setting set by a profile is locked in the app, which shows “Set by your organization”. Use a Custom Settings payload (Jamf: Application & Custom Settings; Intune: Preference file) for the preference domain ch.marketvision.sharedesk.
The allow… switches are on by default; false turns a feature off on that Mac for every technician and session, and the connection request no longer offers it.
| Key | Type | Meaning |
|---|---|---|
allowRemoteControl | Boolean | Mouse and keyboard control (false: technicians only see the screen) |
allowClipboard | Boolean | Shared clipboard |
allowFileTransfer | Boolean | Sending, receiving and browsing files |
allowSound | Boolean | Hearing this Mac's sound |
allowMicrophone | Boolean | Technicians hearing the person at this Mac through its microphone |
allowTerminal | Boolean | Remote terminal |
allowTCPTunnels | Boolean | TCP tunnels to services in this Mac's network |
allowPrivateNetwork | Boolean | Private network (VPN) between this Mac and a technician's |
allowNetworkAccess | Boolean | Reaching devices of this Mac's network through the private network (the user is still asked) |
allowPrinting | Boolean | Printing on the technician's printer |
allowUnattendedAccess | Boolean | Unattended access with a password (false: every connection must be accepted at the Mac) |
accessMode | String | everyone (after accepting) or allowlist (only IDs and addresses on the allow list) |
accessAllowlist | Array of String | ShareDesk IDs or IP addresses; * as a wildcard (192.168.1.*) |
accessBlocklist | Array of String | Refused without asking, same format |
lockOnSessionEnd | String | never, locked (if it was locked when the session began; default), unattended, always |
logIncomingSessions | Boolean | Keep a log of the sessions on this Mac |
printJobsWithoutAsking | Boolean | Print the technician's print jobs without asking |
tunnelScope | String | mac, network (default) or any: how far TCP tunnels reach |
showMenuBarItem | Boolean | Keep running in the menu bar when the window is closed |
startHiddenAtLogin | Boolean | Start in the background (menu bar only) at login |
SUEnableAutomaticChecks | Boolean | Check for updates automatically |
SUAutomaticallyUpdate | Boolean | Install updates automatically |
Example: no terminal, only the IT department's ShareDesk IDs, and the Mac locks after every session. Change the IDs, then sign the profile with your MDM.
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>PayloadContent</key>
<array>
<dict>
<key>PayloadType</key> <string>ch.marketvision.sharedesk</string>
<key>PayloadIdentifier</key> <string>ch.marketvision.sharedesk.settings</string>
<key>PayloadUUID</key> <string>CAB651A5-5AC8-43F3-8C64-6E17A6D16067</string>
<key>PayloadVersion</key> <integer>1</integer>
<key>PayloadDisplayName</key> <string>ShareDesk</string>
<key>allowTerminal</key> <false/>
<key>accessMode</key> <string>allowlist</string>
<key>accessAllowlist</key>
<array><string>123456789</string><string>987654321</string></array>
<key>lockOnSessionEnd</key> <string>always</string>
</dict>
</array>
<key>PayloadType</key> <string>Configuration</string>
<key>PayloadIdentifier</key> <string>ch.marketvision.sharedesk.profile</string>
<key>PayloadUUID</key> <string>B4795054-CD27-4F39-A9CC-7A7FBFC84C69</string>
<key>PayloadVersion</key> <integer>1</integer>
<key>PayloadDisplayName</key> <string>ShareDesk settings</string>
<key>PayloadScope</key> <string>System</string>
</dict>
</plist>
Permissions: what MDM can and can't do
ShareDesk needs Screen Recording to show the screen and Accessibility for the technician's mouse and keyboard. Apple decides what a Privacy Preferences Policy Control (PPPC) payload may do:
MDM can
- allow Accessibility outright;
- allow Full Disk Access, so files work without questions from macOS;
- let users without administrator rights allow Screen Recording themselves (Allow Standard User to Set System Service, macOS 11 and later).
MDM can't
- allow Screen Recording by itself: Apple reserves that for the person at the Mac, who turns it on once;
- allow the microphone: macOS asks the user the first time it is used.
So plan one step per Mac: the user opens ShareDesk and turns on Screen Recording when it asks (or the first time a technician connects; the request is refused until then, with a note saying why).
| Identifier | ch.marketvision.sharedesk (bundle ID) |
|---|---|
| Code requirement | anchor apple generic and identifier "ch.marketvision.sharedesk" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "6AD6SHV34D") |
Start at login
With showMenuBarItem and startHiddenAtLogin, ShareDesk keeps running in the menu bar. When the user turns on “Start ShareDesk at login”, ShareDesk adds itself as a login item. A Managed Login Items payload (macOS 13 and later) with the rule Team Identifier 6AD6SHV34D keeps users from switching it off in System Settings.
Unattended access for your IT team
- A password per Mac: set once in the app (the lock in the main window), at least 10 characters; technicians save it in the shared address book of your team. Optionally with two-factor codes.
- Or trusted technicians: send the user an invitation link; with “Whenever needed”, that technician connects without a password.
- Only your IT team:
accessModeallowlistwith your technicians' ShareDesk IDs. - After a restart: access at the login window (screen and control only; turned on with an administrator password).
- Lock afterwards:
lockOnSessionEnd. - Not wanted?
allowUnattendedAccessfalse: every connection must be accepted at the Mac.
Whatever you choose, the person at the Mac always sees a banner during a session and can end it.
Private network (VPN, beta)
The private network between a Mac and a technician's needs a small helper. ShareDesk installs it the first time it is used, with an administrator's password; for managed Macs it can also be installed ahead of time by an MDM script – ask us for it. With allowPrivateNetwork false it is never used.
Windows: Group Policy
The Windows app reads the same switches from the registry, under HKLM\SOFTWARE\Policies\MarketVision\ShareDesk (else the same path under HKCU). Set them with Group Policy Preferences, Intune or reg add; a value set there is locked in the app.
| Value | Type | Meaning |
|---|---|---|
allowRemoteControl, allowClipboard, allowFileTransfer, allowSound, allowTerminal, allowTCPTunnels, allowPrinting | DWORD | 0 switches the feature off |
allowUnattendedAccess | DWORD | 0 switches unattended access off |
tunnelScope | String | computer, network or any |
lockOnEnd | String | never, locked, unattended or always |
logIncomingSessions, automaticUpdates | DWORD | 1 or 0 |
reg add "HKLM\SOFTWARE\Policies\MarketVision\ShareDesk" /v allowTerminal /t REG_DWORD /d 0 /f
For IT service providers: your branding
Supporting other companies' Macs? Give them ShareDesk from your own link: the app shows your logo and contact, and you get a customer page with a short link and downloads of your own. See branding for IT companies. Your team works from one shared address book, with organisations, departments and hourly rates per customer.
Connect it to your other tools
API keys read the session log, the address books and the brandings, and webhooks tell your ticket system or inventory when something happens: the API and webhooks for developers.
Questions about a rollout?
Write to us – we help with profiles, scripts and licences for your team.