What is Iru Library Manager on Mac?
Last updated: 2026-08-05
Iru Library Manager belongs to the third-party Iru Endpoint management agent, formerly Kandji; it is not part of macOS. Apple provides no separate switch for it, and blocking it can break organization-assigned management tasks without removing MDM.
What it is
Iru Library Manager is a background helper included with Iru Endpoint, the enterprise device-management product formerly known as Kandji. It is not an Apple process and does not ship as part of macOS. Its presence generally means that an organization has installed the Iru management agent on the Mac.
The word “Library” does not refer to a personal music, photo, or document library. In this product, Library Items are resources and tasks assigned by an administrator. Iru Library Manager handles agent-driven items such as Auto Apps, Custom Apps, scripts, printers, and managed macOS updates. It can download or install software, run organization-assigned scripts with elevated privileges, and report the result of those actions to the management service.
The product was renamed from Kandji to Iru in April 2026. The application package now uses the name Iru Library Manager, but its executable and CFBundleIdentifier still use kandji-library-manager. Activity Monitor and other diagnostic tools may therefore show the older technical name even though the installed component belongs to Iru Endpoint.
Iru Library Manager does not carry out every management policy on the Mac. Configuration profiles and items such as Apps and Books are delivered mainly through Apple’s MDM channel. That distinction matters when diagnosing the process or considering whether it can be disabled: Iru Library Manager is one part of the management system, not the entire enrollment.
Why it talks to the network
Iru Library Manager normally connects to the network when the agent performs a periodic check-in, when an administrator changes a Blueprint or Library Item, when a user requests an installation through Self Service, or when an assigned application or operating-system update reaches its scheduled execution time.
Control and status communication goes to the organization-specific Iru or Kandji tenant API. Iru Library Manager uses that connection to learn about assigned work and to report whether an installation, script, update, or other Library Item succeeded. Custom Apps and Auto Apps may also be downloaded from Iru- or Kandji-managed S3 storage or a managed-library service.
Not every legitimate destination will necessarily belong to Iru or Kandji. An administrator can assign a script or installer that contacts its own software vendor, an internal company service, or another third-party endpoint. The destinations visible during execution therefore depend on the organization’s configuration. A connection to a non-Kandji destination is not, by itself, proof that Iru Library Manager is malicious. An unfamiliar destination should still be checked with the organization’s IT administrator, who can compare it with the assigned script or installation package.
How much traffic is normal
When there is no pending work, Iru Library Manager usually produces low-frequency, low-volume HTTPS traffic for control messages, check-ins, and status reporting. That quiet pattern can change abruptly when an assigned item becomes due.
Installing or updating an application, downloading a Custom App package, or fetching a managed macOS update can produce a burst comparable to the size of the relevant installer or update. The amount can therefore vary substantially between two managed Macs or between two time periods on the same Mac.
No reliable public traffic range is available for Iru Library Manager. Its actual usage depends entirely on which items the organization assigns and how large those items are. A specific allowance in megabytes or gigabytes would be unverified, so the useful comparison is the process’s measured traffic against the management work scheduled during the same period.
Can you turn it off
For an organization-managed Mac, the appropriate default is to keep Iru Library Manager running. Apple does not provide a System Settings switch that independently disables this helper, so there is no settings path to follow for this process.
Force-quitting Iru Library Manager or blocking its connections can stop agent-driven Library Items from running or reporting their status. Application updates, Custom Apps, assigned scripts, printers, and managed operating-system work may fail or remain overdue. The device may then be reported as noncompliant to the organization.
Blocking Iru Library Manager also does not reliably remove device management. Configuration profiles and some applications can still be managed through Apple’s MDM channel, existing configuration may remain active, and the management service may reinstall the agent. Apple’s device-management controls can remove the overall enrollment profile only when the organization’s configuration permits removal; they are not an independent off switch for Iru Library Manager. Anyone who believes the Mac should no longer be managed should resolve the enrollment with the organization’s IT administrator rather than disabling one helper process.
What people get wrong
- “Iru Library Manager is built into macOS.” It is not. Iru Library Manager belongs to the third-party Iru Endpoint device-management product, previously named Kandji. The older executable name can make the branding less obvious, but it does not make the process an Apple component.
- “Iru Library Manager is scanning my music, photos, or documents.” “Library” has a product-specific meaning here. It refers to administrator-assigned apps, scripts, printers, updates, and other management items, not the user’s media or document libraries.
- “Iru Library Manager only performs passive inventory or telemetry.” That description leaves out its operational role. Iru Library Manager can install and update software and can run scripts assigned by the organization with elevated privileges. Its traffic may therefore represent an actual download or management action, not merely a report about the Mac.
- “Force-quitting Iru Library Manager or blocking it in a firewall safely turns off Kandji.” It can disrupt agent-driven tasks, but it does not reliably remove MDM enrollment, existing profiles, or work delivered through Apple’s management channel. The result can be a partially managed, noncompliant device rather than an unmanaged one.
- “Any third-party domain contacted by Iru Library Manager or its child processes proves malware.” Assigned scripts and installers may legitimately contact software vendors, company infrastructure, or other third-party services. The destination alone is not enough to classify the activity. If the endpoint is unfamiliar, the organization’s IT administrator should verify it against the assigned item.
Seeing what it actually used
The next step is to measure Iru Library Manager itself over the time window in question instead of relying on a generic estimate. Use Bytetally’s per-process statistics, then compare the observed activity with scheduled installations, scripts, and managed updates. If an unexplained destination or burst remains, take that evidence to the organization’s IT administrator.
Related processes
Common questions
Is Iru Library Manager an Apple process?
No. Iru Library Manager is part of the third-party Iru Endpoint management agent, previously called Kandji.
Why is Iru Library Manager using my network?
It checks in with the organization’s management service, reports task status, and may download assigned apps, installers, scripts, printers, or managed macOS updates.
Can I disable Iru Library Manager?
Apple provides no independent switch for Iru Library Manager. Terminating or blocking it can prevent agent-driven management work while leaving the Mac’s MDM enrollment and existing configuration in place.
Is kandji-library-manager the same as Iru Library Manager?
Yes. The current package name is Iru Library Manager, while the executable and bundle identifier can still use kandji-library-manager.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account