> For the complete documentation index, see [llms.txt](https://docs.stepsecurity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.stepsecurity.io/developer-machines/installation/script/mdm-deployment/macos/iru-formerly-kandji.md).

# Iru (formerly Kandji)

This guide walks through deploying Dev Machine Guard across your macOS fleet using **Iru** (formerly Kandji). The deployment uses Iru's **Custom Script** library item to run the loader on a daily schedule, after a short pilot run at higher frequency.

Two separate schedules are involved:

* **Iru execution frequency** controls how often Iru launches the loader on the device. You set this per library item in Iru, in Step 3 below.
* **Scan Schedule** controls how often a launch performs a full scan. You set this once for the whole organization in the StepSecurity dashboard, under Settings. Between scans, agent launches check in and exit without scanning.

Changing how often devices are scanned is a StepSecurity dashboard change, not an Iru change. See [Adjusting scan frequency](#adjusting-scan-frequency) below.

{% hint style="info" %}
The loader script shown in the StepSecurity dashboard is rendered with your tenant's credentials already embedded and should work as-is. If you need to customize the script (alternative install directory, proxy, etc.), reach out to StepSecurity.
{% endhint %}

### Prerequisites

* An Iru tenant with administrative access to **Library** and **Blueprints**.
* A Blueprint scoped to the devices you want to enroll in the pilot, and a second Blueprint covering your full fleet for rollout.
* The Dev Machine Guard loader script for your tenant, downloaded from the StepSecurity dashboard (Step 1 below).

### Step 1. Copy the loader script

* Sign in to the [StepSecurity dashboard](https://app.stepsecurity.io/).
* In the sidebar, go to **Developer Machines → Installation Script**.
* On the **macOS** tab, click the **Copy** button at the top right of the script editor. (You can alternatively click **Download** to save the script as a file.)

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FFrEJfKMuAg20M8LTG9fd%2Floader-script.png?alt=media&amp;token=a5ccfc69-1c15-48b6-9bc3-6569d63122fb" alt=""><figcaption></figcaption></figure>

### Step 2. Create a Custom Script in Iru

* In Iru, open **Library** from the left sidebar.
* Click **Add Library Item**.
* In the **General** category, select **Custom Script** and click **Add and configure**.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FSfIyaMxvUWnNqa4KWQvj%2Fadd-custom-script.png?alt=media&amp;token=a8f62063-e30a-4423-9de4-c86afe7680b7" alt=""><figcaption></figcaption></figure>

### Step 3. Configure the script

* Give the script a descriptive name, for example `StepSecurity Dev Machine Guard`.
* Under **Blueprints**, select the Blueprint that targets your pilot devices.
* Under execution frequency, select **Every 15 Minutes**. You will change this to **Run daily** after pilot validation in Step 6.
* This setting controls how often Iru launches the loader, not how often the device is scanned. Full scan cadence comes from **Scan Schedule** in the StepSecurity dashboard, covered in [Adjusting scan frequency](#adjusting-scan-frequency).
* Leave **Self Service** disabled.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FRyEyEiqcAtDWc2kZaWrf%2Firu-run-15-mins.png?alt=media&amp;token=d2a22fe5-0ca1-4001-bf34-d02fbd730571" alt=""><figcaption></figcaption></figure>

### Step 4. Paste the loader script

* Scroll to the **Audit Script** section.
* Paste the loader script you copied in Step 1 into the editor.
* Leave the **Remediation Script** field empty.
* Click **Save** at the bottom right.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FTZNNKjXFBseETSeInoUw%2Firu-audit-script.png?alt=media&amp;token=5a603249-80c4-44ec-bc84-e36fe8176f47" alt=""><figcaption></figcaption></figure>

### Step 5. Validate on the pilot group

The 15-minute frequency set in Step 3 means each pilot device will run the loader automatically within 15 minutes of receiving the Blueprint. **No action is needed on the client devices.**

After 15 to 30 minutes, confirm on each pilot device:

* The library item status in Iru shows the script ran successfully.
* The device appears in the StepSecurity dashboard under **Developer Machines → Devices** with recent telemetry.

### Adjusting scan frequency

Once the fleet is rolled out, how often devices run a full scan is controlled from the StepSecurity dashboard, not from Iru.

In the dashboard, go to **Developer Machines → Installation → Settings → Scan Schedule** and set **Full scan every (minutes)**. The default is a full scan every 4 hours. A human-readable equivalent appears beside the field, so `240` displays as *4 hours*. Select **Save schedule** to apply.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2Fq5BObw6ukGOLqxHB3jZK%2FScreenshot%202026-08-20%20at%2010.24.09.png?alt=media&amp;token=7b050696-5d95-41e3-9b70-242c544219ee" alt=""><figcaption></figcaption></figure>

The setting is organization-wide and applies to every device in your tenant. Agents pick up the change on their next check-in, so you do not need to redeploy the loader, regenerate the script, or edit the Custom Script library item in Iru.

To confirm what a specific device is using, open **Developer Machines → Devices**, select the device, and check **Scan Frequency** in the Device Information block.&#x20;

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2F5oC63anSwVZydKSyR3n3%2FScreenshot%202026-08-20%20at%2010.42.49.png?alt=media&amp;token=e17010f3-a424-4db1-ae54-72a2138b5dfa" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Agents older than **1.15.0** ignore the scan schedule and scan on every launch. Upgrade to 1.15.0 or later for schedule changes to take effect on a device.
{% endhint %}

**Temporary boost**

To scan more aggressively for a limited period, for example during an incident, select **Add temporary boost** on the Scan Schedule panel, set **Every (minutes)** and an end time, then select **Save schedule**. The fleet reverts to the regular schedule automatically when the boost ends. To end a boost early, select **Remove boost** and then **Save schedule**.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FcYtPKCOnIZB6EJxfLc6q%2FScreenshot%202026-08-20%20at%2010.45.27.png?alt=media&amp;token=412b0959-09c4-4350-bced-c86b2fc99d83" alt=""><figcaption></figcaption></figure>

### Uninstalling

To stop Dev Machine Guard from running on enrolled devices, either:

* Remove the Custom Script library item from the Blueprint, or
* Remove the device from the Blueprint.

Iru will stop scheduling further loader runs immediately. Any locally installed Dev Machine Guard binary will remain on the device until cleaned up out-of-band; see [Devices](/developer-machines/devices.md) for guidance.

### Troubleshooting

| Symptom                                               | Where to look                                                                                                                                               |
| ----------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Iru reports the library item as failed                | Iru → Library → the Custom Script item → run history and per-device logs                                                                                    |
| Iru shows the script as successful but no device data | Confirm the script pasted in Step 4 is the full loader, including the embedded configuration                                                                |
| Devices missing from the StepSecurity dashboard       | Confirm the pilot Blueprint covers the expected devices in Iru                                                                                              |
| Devices scanning less often than expected             | Check **Scan Frequency** on the device in **Developer Machines → Devices**, then **Settings → Scan Schedule**. Agents older than 1.15.0 ignore the schedule |

For additional support, [contact StepSecurity](https://www.stepsecurity.io/contact).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.stepsecurity.io/developer-machines/installation/script/mdm-deployment/macos/iru-formerly-kandji.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
