Disk access in macOS Catalina and Big Sur

Disk access in macOS Catalina and Big Sur

Applies to: Portfolio Server v4.x running in macOS 10.15 and later


Starting in macOS 10.15 (Catalina) and continuing in macOS 11.x (Big Sur), Apple has added security measures that require a user to grant permission to software that attempts to access certain folders or disks.

This can have a difficult consequence when a Portfolio client user attempts to add a watch folder when the Portfolio server system runs one of these recent macOS versions.

The locations that will result in such a prompt are:

  • Network volume: A volume from a server or other system on the network, mounted on the desktop of the Portfolio server system.

  • Removable volume: An external disk, attached to a Thunderbolt, USB, or other port on the Portfolio server system, and mounted on the desktop.

  • Downloads folder: The Downloads folder for the user logged in to the Portfolio server system.

  • Documents folder: The Documents folder for the user logged in to the Portfolio server system.

  • Desktop folder: The Desktop of the user logged in to the Portfolio server system.

These locations are all relative to the macOS system that has the Portfolio server software installed.

When a client user attempts to choose one of these locations (or a folder in one of these locations), the client app won’t expand the parent location (such as the Documents folder or the network volume).

new-watch-folder.png

The client will also show an error message.

generic-error.png

At the same time, the Portfolio server system will present a dialog requesting access to the location.

access_request.png

Until a human grants the server system access to the location, the Client user won’t be able to select a watch folder from their chosen location.

There are several ways to put an end to or at least reduce this situation:

  • Use Vault catalogs.

    While this may require a different hardware configuration, the Vault catalog offers better data security and content versioning.

  • Configure your server on a different OS.

    Portfolio doesn’t have this issue when running in macOS 10.14 or Windows Server.

  • Plan ahead for creating watch folders.

    You grant Portfolio access to any of the protected locations in advance of users attempting to create watch folders. This should end the need for access requests.

    Remember: You only need to do this if your Portfolio server system runs macOS 10.15 or later.

    1. Mount a network shared volume and a removable drive on the Portfolio server system.

    2. Open the web client in a browser on the Portfolio server system.

    3. Choose a watch folder catalog.

    4. Click + below the folders list in the Organizers pane on the left, then choose New Watch Folder.

    5. In the Watch Folder dialog, click the protected folder or drive type that you want to grant access to.

      new-watch-folder.png

    6. When you choose one of the folders (Desktop, Documents, Downloads) or drive types (Network, Removable), switch to the Finder and look for a prompt asking you to grant the software access to that location. Click OK.

      access_request.png

    7. Repeat steps d through f for each type of folder or drive you want users to be able to access.

    • Related Articles

    • Catalog access

      In order for a user to access assets in a catalog, they must have two things: a Portfolio account (either native or through a directory service), and an assigned role in the catalog. The Portfolio Administrator manages Portfolio accounts and ...
    • Internet Access : Firewall + Reverse Proxy Considerations

      PortfolioDAM employees do not provide Firewall and / or Reverse Proxy configuration assistance. Contact your Corporate LAN / WAN Network Infrastructure Team for assistance with granting external ( Internet ) access to your Portfolio instance. Table ...
    • Portfolio 4.0.1 Installers – Macintosh (MacOS)

      Portfolio 4.0.1 Server <Download> This download is not intended for Mac Mini computers. If you are using a Mac Mini or similar Mac device, please visit our System Requirements page for updates. If you have more questions about these requirements, ...
    • System requirements

      The latest system requirements and other information is available at Portfolio System Requirements. These requirements are the minimum necessary to reasonably use Portfolio on a regular basis. A minimal Portfolio installation consists of a server ...
    • Working with original assets

      Note: This feature is only available through the Portfolio Desktop client. You can use Portfolio Desktop to access and work with original asset files. In order to work with originals, you need to have direct access to them from your workstation. This ...