← All Binaries

dseditgroup

dseditgroup is Apple's supported command-line tool for manipulating a single named group record on the local Directory Services node or a bound network node such as Active Directory or LDAP. It grants admin rights, populates service access groups and audits membership. An attacker with code execution can run the same operations: a single "-o edit -a" invocation converts a controlled standard account into a local administrator, and the macOS service access control groups (com.apple.access_ssh, com.apple.access_screensharing) gating Remote Login and Screen Sharing are ordinary group records dseditgroup can add members to or delete. It is Apple-signed, is the documented way to change group membership, and runs constantly in MDM workflows.

Author: Hare Sudhan (@cyb3rbuff) Created: 2026-09-20

Paths

/usr/sbin/dseditgroup

Example Use Cases

Promote a local account to administrator #

Adding a user record to the local "admin" group grants administrator rights, which on macOS include authenticating to authorization prompts, using sudo and installing software. It survives reboots because it changes the local directory database, not a running process. Modifying the admin group requires root, so the command runs under sudo or an already-root context.

dseditgroup -o edit -a <TARGET_USER> -t user admin

Edit a group using explicit credentials on a local or network directory node #

The -n parameter selects the Directory Services node (the local node "." or a bound LDAP/Active Directory server) and -u/-P supply admin credentials to authenticate against it. With harvested credentials an attacker can add accounts to groups on the local node without a root shell, or on a bound directory server to propagate changes to every Mac bound to that node. The -P password appears in the process argument list.

dseditgroup -o edit -n /LDAPv3/<DIRECTORY_SERVER> -u <DIR_ADMIN> -P <PASSWORD> -a <TARGET_USER> -t user <GROUP>

Grant remote service access through a SACL group #

When Remote Login or Screen Sharing is restricted to specific users, macOS enforces it through the com.apple.access_ssh and com.apple.access_screensharing groups. Adding a controlled account to either group opens a remote channel (SSH or GUI) without dropping a payload. The account still needs valid credentials or an authorized key. Requires root.

dseditgroup -o edit -a <TARGET_USER> -t user com.apple.access_ssh

Remove a service access group so the service accepts all users #

Deleting a com.apple.access_* group record removes the restriction and the service reverts to allowing all users, widening remote access without adding a visible member to an allow list. The -q flag suppresses the delete confirmation, making the operation usable from a non-interactive shell. Requires root.

dseditgroup -o delete -q com.apple.access_screensharing

Enumerate group membership to identify privileged accounts #

The read and checkmember operations consult the authentication search policy and do not require root. "read" lists all members of a group (admin, com.apple.access_ssh, etc.), and "checkmember -m" tests whether a specific user belongs to it. Either can map who holds administrator rights or service access without writing to the directory.

dseditgroup -o read admin

Detections

Resources

Acknowledgements

  • Armin Briegel (@scriptingosx) for documenting macOS group records and the com.apple.access_ssh service access group