Configuring OS permissions for the Prey desktop agent

To prevent unauthorized uninstallations or client interruptions, the Prey agent is designed to run silently in the background. On Windows, for example, it will not create desktop shortcuts, appear in the system tray, or show up in the standard "Apps & features" list.

However, to maximize the agent's resilience against manual uninstallation attempts and OS-level restrictions, proper environment configuration is required. To ensure the client executes critical security actions successfully during an active incident, you must configure the following system permissions and security best practices per Operating System.

  • To ensure Prey tracks your device accurately and to prevent unauthorized users from tampering with the agent, we strongly recommend implementing the following security measures and permissions:

    Mandatory permissions

    • Location Services: Required for Prey to fetch the device's exact location.
      Path (Windows 11): Go to Settings Privacy & security Location. Ensure Location services is turned On, and that apps are allowed to access your location.

    Security best practices

    • Restrict administrator access: An administrator password is required to uninstall Prey or stop its background processes. Ensure standard users do not have admin rights; without them, they cannot use the Task Manager to kill the Prey client.
    • Restrict access to C:\Windows: The Prey agent resides in this directory. If a standard user cannot modify this folder, they cannot delete the C:\Windows\Prey folder or read the Prey logs. This also protects other critical system programs.
    • Block USB/optical drive boot access: Prevent users from booting the device from an external drive to bypass the OS or reinstall Windows.
    • Lock BIOS/UEFI settings: Secure the machine's BIOS/UEFI behind a password to prevent unauthorized changes that could circumvent your security measures.
  • Due to strict privacy frameworks in recent macOS versions (Ventura, Sonoma, Sequoia), Apple requires explicit user consent for background apps to interact with the system.

    Critical Warning: If these permissions are not granted, the OS will silence or disable the Prey agent. Critical security actions—such as fetching location, missing reports, or executing a remote wipe—will fail.

    During installation, you must manually grant these permissions. To configure these, navigate to System Settings Privacy & Security and approve the following:

    Mandatory permissions checklist

    • Full Disk Access: Required to execute critical security actions (like remote wipe).
      Path: System Settings Privacy & Security Full Disk Access
      Action: Grant access to the prey-user and bash binaries (or the main Prey app, depending on your version).
    • Accessibility: Required by newer macOS versions to allow the agent to run background scripts and manage system controls effectively.
      Path: System Settings Privacy & Security Accessibility
      Action: Approve the Prey app/binary.
    • Location Services: Required to track the device's geolocation accurately. (Note: This must be enabled for every user account on the device).
      Path: System Settings Privacy & Security Location Services
      Action: Find Prey in the list and turn on the toggle.
    • Screen Recording: Required to capture screenshots of the desktop when a device is marked as missing.
      Path: System Settings Privacy & Security Screen Recording
      Action: Approve the Prey app/binary.
    • Camera: Required to take pictures using the built-in webcam to identify whoever is using the missing device.
      Path: System Settings Privacy & Security Camera
      Action: Approve the Prey app/binary.

Need assistance?

If you have any questions about the Prey for Computers client or best practices for securing your fleet, please reach out to our Support team via your Prey Panel by clicking on the Help widget.

Was this article helpful?

0 out of 0 found this helpful