What is kandji-daemon on Mac?

Last updated: 2026-08-05

kandji-daemon is the privileged background service inside Iru Agent, formerly Kandji Agent. It manages settings, software, inventory, scripts, and optional security features on organization-enrolled Macs.

What it is

kandji-daemon is the privileged background daemon inside Iru Agent, the application formerly known as Kandji Agent. It comes from Iru, the company and product previously called Kandji. It is not an Apple process and is not built into macOS.

Organizations install Iru Agent on enrolled Macs to extend Apple’s mobile device management system. kandji-daemon helps enforce settings assigned by administrators, manage applications, run administrator-provided scripts, and collect hardware and software inventory. It can also support optional endpoint-security capabilities when the organization has enabled them.

The name can look inconsistent with the current product branding. Executable names, launchd labels, bundle identifiers, and logging subsystems may still use kandji-daemon or io.kandji even though the application is now called Iru Agent. Identifiers associated with it include io.kandji.KandjiAgent and io.kandji.kandji-daemon. On a verified installation, the executable was located inside the Iru Agent application under /Library/Iru/.

Why it talks to the network

kandji-daemon contacts the organization’s tenant-specific Iru/Kandji device-management service over HTTPS. Recurring agent check-ins normally happen every 15 minutes. A synchronization started by an administrator or user can also cause it to connect outside that recurring schedule.

During these exchanges, the daemon retrieves current policy and Library Item state. It reports the results of enforcement work, sends application inventory, and checks whether the agent or managed applications need updates. When an administrator assigns software, the broader Iru system may download it from Iru/Kandji distribution or object-storage endpoints.

Additional traffic depends on which features the organization has enabled. Endpoint detection and response, vulnerability management, telemetry, and diagnostic features can all produce further exchanges. The precise data involved therefore depends on the organization’s licensed modules and configured policies.

Not every management-related connection on the Mac should be assigned to kandji-daemon. Apple’s MDM and APNs communication uses separate components, including mdmclient, and other Iru helper processes handle distinct parts of synchronization and software installation. Some application downloads, including larger ones, may be transferred by those helpers instead of kandji-daemon itself.

How much traffic is normal

There is no verified per-process traffic baseline for kandji-daemon, and no reliable vendor-published bandwidth figure was found. A specific daily total or expected number of megabytes would therefore be misleading.

The observable range can vary considerably. An idle, compliant Mac may show brief metadata exchanges during periodic check-ins. Assigning or updating software can lead to installer-sized transfers, although a separate Iru helper may carry some or all of a large download. Diagnostics and enabled security modules can add traffic whose volume depends on their activity and configuration.

For that reason, a large transfer is not automatically abnormal, while a quiet period does not mean the agent has stopped working. The useful questions are when the traffic occurred, whether software or policies were changing at the time, and whether another Iru process handled part of the transfer.

Can you turn it off

On an organization-managed Mac, the appropriate default is to keep kandji-daemon running. Apple does not provide a reliable System Settings switch specifically for this daemon. Login Items & Extensions may display the managed component, but the installed management profile is designed to prevent enrolled users from disabling its background services there.

Stopping or blocking the daemon can interrupt policy enforcement, inventory reporting, managed application installation and updates, administrator-provided scripts, and any enabled endpoint-security functions that depend on it. The Mac may consequently appear unhealthy or noncompliant in the organization’s management system.

That does not mean corporate access will always disappear immediately. Loss of access depends on whether the organization has configured compliance checks or conditional-access rules, so the outcome is organization-specific rather than universal.

Force-quitting the process is not a lasting removal method. Its launchd job uses KeepAlive, and the management service may attempt to reinstall an agent that is missing from an enrolled Mac. Proper removal should be handled by the organization’s administrator as part of device unenrollment. In some deployments, General > Device Management may allow removal of an enrollment profile, but that option is controlled by the organization, may be unavailable, and is not a dedicated kandji-daemon switch.

What people get wrong

Seeing what it actually used

When a total cannot be inferred from a published baseline, the next step is to measure the process on the affected Mac over the time period you care about. Bytetally’s per-process statistics can show how much traffic kandji-daemon actually used, while separate Iru helpers should be checked independently. Compare the timing with policy changes, application assignments, updates, or diagnostic activity before deciding whether a transfer is unusual.

Related processes

Common questions

Is kandji-daemon malware?

No. It is an enterprise management component installed with Iru Agent, formerly Kandji Agent. Its presence is expected on a Mac knowingly enrolled by an organization; an unexpected installation should be checked with the device owner or IT administrator.

Why does kandji-daemon keep coming back after I quit it?

Its launchd job uses KeepAlive, so force-quitting it does not permanently stop it. An enrolled device may also receive a command to reinstall a missing agent.

Can I disable kandji-daemon in System Settings?

Apple provides no reliable daemon-specific switch. The management profile can prevent enrolled users from disabling the agent's background services, and proper removal normally requires administrator-controlled unenrollment.

How much data should kandji-daemon use?

There is no verified per-process baseline. Usage can range from brief periodic metadata exchanges to software-related transfers, while diagnostics and enabled security modules can add variable traffic.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account