Parallex in managed fleets
Parallex is one app, signed with a Developer ID (Team ID UK74VYMUP7) and notarized by Apple, that people use to run separate copies of other apps. An IT team can install it on every Mac, set and lock its settings with a configuration profile, and add each Mac to a license, from Parallex 3.3; since 3.3.1, each release also comes as a signed installer package. This page covers what that takes, and what Parallex's copies look like to endpoint security tools, honestly.
On this page
Deploying the app
- The disk image. Parallex.dmg always holds the newest release. Copy Parallex.app from it to /Applications with your MDM's app deployment, or a script. Check it with
codesign --verify --deep --strictandspctl -a -vv: the Team ID is UK74VYMUP7. - Homebrew.
brew install --cask mandipadk/parallex/parallexinstalls the app and links theparallexcommand. On Homebrew 6 and later it trusts only the Parallex cask from that tap. - Installomator and AutoPkg. There's no label or recipe yet. For a label of your own: type
dmg, the download URL above, andexpectedTeamID="UK74VYMUP7". The newest version number is in the disk image's app (CFBundleShortVersionString). - The installer package. From Parallex 3.3.1, each release comes with a component package beside its app archive and disk image, signed with Parallex's Developer ID Installer certificate and notarized by Apple:
https://parallex.mandip.dev/download/<version>/Parallex-<version>.pkg, listed on Releases with each version's other files. It installs Parallex.app in /Applications (never relocated to another copy's folder), upgrades an older one there, and links theparallexcommand into /usr/local/bin when nothing else is there. Its postinstall runs as root and touches nothing of any user's: no preferences, no login items, no files in anyone's home. Check it withpkgutil --check-signature: the Team ID is UK74VYMUP7.
Parallex updates itself by default, from signed releases only. If you deploy updates yourself, set AppUpdatesAllowed to false below: Parallex then never checks for, downloads or installs a version of its own. To let it update but not first, set UpdateDeferralDays.
Managed preferences
Deliver the keys in a configuration profile whose payload type is com.parallex.app. A key the profile sets wins over what's chosen on the Mac, in the app and in the parallex command alike, and the app shows it as Managed by your organization, locked. Leave a key out to leave it to the person using the Mac. parallex policy lists what's managed on a Mac, and so does Settings › About.
- The schema: every key, as JSON Schema.
- A Jamf Pro custom schema: paste it into Application & Custom Settings › External Applications, with the preference domain
com.parallex.app. Each key starts as Not Configured. - A sample profile: settings for an agency, and Parallex's login item allowed by Team ID. Change its identifiers before you use it.
| Key | Holds | What it does |
|---|---|---|
TelemetrySharing | Yes or no | Anonymous usage report. The daily anonymous usage report (which well-known apps are copied and how those copies do, what fails, features in use, Parallex's own crashes). True turns it on, false turns it off and deletes anything waiting to be sent. |
AutomaticUpdateChecks | Yes or no | Check for updates automatically. Whether Parallex looks for a new version every few hours. With false, people can still check from Settings unless AppUpdatesAllowed is false. |
AppUpdatesAllowed | Yes or no | Parallex updates itself. False when your organization deploys Parallex's updates itself (a package, Homebrew, Installomator): Parallex then never checks for, downloads or installs a new version of its own. |
UpdateDeferralDays | Number, 0 to 90 | Hold new releases for. Days a new release must have been out before Parallex offers it (0 to 90). Only the newest release is offered: while it's held, nothing is. |
CopyableApps | List of bundle IDs | Apps that may be copied. Bundle IDs of the only apps new copies may be made of. An ID ending in .* covers every ID under it (com.microsoft.*). Leave it out, or empty, for any app. Copies made before stay. |
BlockedApps | List of bundle IDs | Apps that may not be copied. Bundle IDs no new copy may be made of, wildcards as in CopyableApps. A block wins over CopyableApps. Copies made before stay. |
CarryAllowed | Yes or no | Carry. Moving copies and workspaces to another Mac in an encrypted file, signed in. False turns it off in the app and the parallex command. |
FleetAllowed | Yes or no | Fleet. Several sealed agent lanes on one task. False turns it off. |
DescribeAllowed | Yes or no | Describe your setup. Suggesting workspaces and copies from a sentence, with Apple's on-device model. False hides it. |
RecipesAllowed | Yes or no | Setup links. Sharing a setup as a link, and building one from a link. False turns both off. |
AgentWorkspacesAllowed | Yes or no | Agent workspaces. Making agent workspaces and running agents in them. False turns them off; existing ones stay but can't run. |
AgentsRequireSealed | Yes or no | Agent runs must be sealed. True seals every agent run in a macOS sandbox written for the run, whatever the agent's own setting, and its seal can't be turned off. |
WorkspaceProxy | Text | Proxy for workspaces. A proxy every workspace goes through, like http://proxy.example.com:8080 or socks5://proxy.example.com:1080, with no user name or password: copies in a workspace, commands run as a workspace, and agent runs. It replaces a workspace's own proxy. It isn't a system proxy: copies outside workspaces, and other apps, go straight out. |
LicenceKey | Text | License key. A Parallex license key (PRLX-…). On first launch, Parallex adds the Mac to that license without asking, if a seat is free, and tries again a day later if not; it never frees another Mac. A Mac with a license of its own keeps it. The key is read only from the managed profile and never logged. Like every managed preference, any account on the Mac can read it. |
Licenses for many Macs
Put a license key in LicenceKey. When Parallex opens, it adds the Mac to that license without asking, as long as the license has a free seat. When every seat is taken it frees nothing: it tries again a day later, and Settings › License says why. It adds a Mac once per key, so a Mac taken off the license stays off; a Mac that already has a license of its own keeps it. The key is read only from the managed profile and never written to a log. Like any managed preference, every account on the Mac and the programs it runs can read it (sealed agent runs can't), so treat it as you would a shared license key.
For scripted installs without a profile, parallex license activate --key-file /path/to/key reads the key from a file, so it isn't in the command's arguments, and never prints it. Each license covers the Macs its seats allow; for more, write to hello@mandip.dev.
Privacy permissions (PPPC)
Parallex itself asks for no privacy permissions by default: no Full Disk Access, Accessibility, Screen Recording, camera or microphone. Opening at login uses a login item, which a managed login item rule can allow by Team ID; the sample profile does.
- Sign-in link routing is off until someone turns it on. Then Parallex builds a small helper on that Mac, Parallex Links, and macOS asks once to let it pass links to the apps (Automation). It's signed on each Mac, so a PPPC profile can't approve it in advance.
- Copies are apps of their own to macOS. A copy of Zoom asks for the camera as itself, the first time it needs it, and the person using the Mac answers. A PPPC payload needs an app's code requirement, and each Mac signs its copies with its own certificate, so copies can't be approved ahead of time across a fleet.
Endpoint security, EDR and Santa
Everything Parallex makes on a Mac is signed on that Mac. A plain instance is a small wrapper app, signed ad hoc, whose launcher starts the original app with a data folder of its own; the original keeps its developer's signature. A copy is what security tools notice most, because of how it works:
- Each copy is a copy of the app re-signed on that Mac, with a self-signed certificate Parallex makes once per Mac ("Parallex Local Signing"). It has no Team ID, and no two Macs share the certificate.
- Copies run without the hardened runtime, and the launcher loads Parallex's own library into them with
DYLD_INSERT_LIBRARIES, so the app keeps to its own data. Those are the signals EDR rules for library injection and app tampering look for: some tools flag them, and some block them. - A copy is rebuilt when its app updates, so its code hash changes with every update.
What you can do: allow Parallex itself, its command and its libraries by Team ID UK74VYMUP7 (they ship signed with its Developer ID, and the library a copy loads is that same signed file, kept in Parallex's folder). For copies and wrappers, a rule by certificate or code hash covers one Mac only, and a hash only until the next rebuild, so in Santa Lockdown they won't run without rules made on each Mac. Where your EDR's exclusions can match the signer of an injected library, Team ID UK74VYMUP7 is the one to use; check how yours scopes them, as Parallex hasn't been tested against each EDR. Agent workspaces and the parallex command don't need copies at all.
To turn copies off for some apps, or allow only a few, use BlockedApps and CopyableApps. Copies made before a block stay; remove them with parallex remove.
Questions
Can people change a managed setting?
Not in Parallex or its command: a managed setting is shown as managed and can't be changed there. Anyone with an administrator account can remove a profile, though, and a profile installed by hand is easier to remove than one from an MDM, so locks are as strong as your device management.
Does Parallex need Full Disk Access or Accessibility?
No. It asks for no privacy permissions by default. Copies ask for what their app needs, as themselves.
Is there a signed installer package?
Yes, from Parallex 3.3.1: Parallex-<version>.pkg, signed with Parallex's Developer ID Installer certificate and notarized, beside each release's disk image on Releases. Earlier versions have only the disk image and the app archive.
Where do security problems go?
Write to hello@mandip.dev with "Security" in the subject. The security policy says what's covered and what happens next.
Get Parallex
Try it free for 14 days, then a one-time purchase, for macOS 14 and later.
Or in Terminal
curl -fsSL https://parallex.mandip.dev/install | shOr with Homebrew
brew install --cask mandipadk/parallex/parallex