What is kandji-parameter-agent on Mac?
Last updated: 2026-08-05
kandji-parameter-agent is a proprietary management helper installed with Iru Endpoint, formerly Kandji, rather than an Apple system process. It checks assigned Parameters, reports their results, and performs remediation when the relevant policy calls for it.
What it is
kandji-parameter-agent is a proprietary macOS management component installed as part of Iru Endpoint, the product known as Kandji until April 2026. It is not an Apple system process. The current software still retains the kandji-parameter-agent executable name and several io.kandji identifiers even though the product now uses the Iru name.
The helper is called by Iru Agent. Its job is to examine the Parameters that an organization has assigned to the Mac through a Blueprint, run the behavior defined for each one, and return the outcome. That behavior is not identical for every Parameter. Some checks report what they find, while others may perform remediation when their policy provides for it. It would therefore be inaccurate to describe kandji-parameter-agent as a process that continuously changes every managed setting.
On an inspected installation, its executable path was /Library/Iru/Iru Agent.app/Contents/Helpers/Iru Parameter Agent.app/Contents/MacOS/kandji-parameter-agent. Related identifiers include io.kandji.KandjiAgent, the io.kandji.kandji-agent launchd label, and the io.kandji.parameter-agent logging subsystem. The bundle may be presented as Iru Parameter Agent, but whether Activity Monitor uses that friendly bundle name on every macOS version has not been verified.
Why it talks to the network
kandji-parameter-agent participates in exchanges between the managed Mac and the organization’s Iru Endpoint cloud control plane. The exchanged information concerns Parameter configuration, execution state, and result reporting. This is management traffic: the process needs to learn what the organization assigned and report what happened when those assignments were evaluated.
Several events can lead to this activity. Iru Agent performs periodic check-ins, which the vendor says normally occur about every 15 minutes. An administrator can also force a check-in. Other triggers include the daily full Parameter check and changes to the Blueprint assigned to the device. Network activity may therefore appear in brief bursts rather than as one uninterrupted transfer.
The available documentation does not publish a complete list of domains used specifically by this helper. It also does not establish, connection by connection, whether kandji-parameter-agent or its parent daemon opens the socket. Those boundaries should not be inferred from the product name or from a single process view. kandji-parameter-agent is also not the Apple process responsible for the APNs or MDM communication channel; those mechanisms are separate from this Parameters helper.
How much traffic is normal
Normal traffic should generally be short-lived and intermittent. It primarily carries policy and status information, so its pattern should look different from sustained file synchronization, backup, or media transfer. A burst around a regular check-in, an administrator-triggered check-in, a daily Parameter evaluation, or a Blueprint change can be consistent with its role.
There is no reliable published byte range for kandji-parameter-agent. The vendor has not provided a defensible minimum, average, or maximum, so a specific KB or MB figure would be guesswork. Actual usage can vary with assigned Parameters and evaluation events. In addition, the share attributable to this helper rather than the parent Iru Agent has not been independently verified. Process-level measurements should therefore be treated as observations from that particular Mac and time window, not as a universal allowance.
Can you turn it off
The practical answer for an organization-managed Mac is to keep kandji-parameter-agent running. Apple does not provide a verified System Settings switch for disabling this helper. A related managed background item may appear under login items and extensions, but seeing it there does not mean the user has an effective or permanent off switch.
Blocking or terminating the helper can prevent or delay assigned Parameter checks, result reporting, and any remediation required by those Parameters. The organization may then regard the device as noncompliant. launchd or the organization’s device-management configuration may also restart or restore the component, so stopping it is not equivalent to disabling an ordinary, optional login item.
If a Parameter should no longer apply, the appropriate change is for the organization’s administrator to adjust it in Iru Endpoint. If the Mac should no longer be managed at all, it should be formally released from management. Interfering with the helper locally does not cleanly perform either action.
What people get wrong
- “It is an Apple macOS daemon.” It is not.
kandji-parameter-agentis a third-party Iru/Kandji management component deployed by an organization.
- “The strange name proves it is malware or a crypto miner.” The name alone proves neither. When the executable is inside the properly signed Iru Agent bundle and the Mac is genuinely organization-managed, it is a legitimate component. If it appears unexpectedly on a personal device, check the executable path, code signature, and device-management status, then contact IT rather than classifying it from its name alone.
- “It is the complete Kandji or Iru MDM client.” That overstates its role.
kandji-parameter-agentis a helper for the Parameters subsystem. Apple’s MDM and APNs channel uses a separate mechanism.
- “Turning it off only reduces network traffic.” It also disrupts Parameter auditing, reporting, and any remediation that the assigned policies require. That disruption may put the Mac out of compliance with organizational requirements.
- “Every Parameter constantly watches and automatically changes macOS.” Parameter timing and behavior depend on the individual assignment. Some report only, some run daily, and only some perform remediation.
- “The background-item control in System Settings permanently disables it.” That is generally not true on a managed Mac. Service Management configuration can mark the background component as organization-managed, and its presence in the interface does not establish that the user can turn it off.
Seeing what it actually used
To answer the traffic question for a particular Mac, measure a representative period in Bytetally’s per-process statistics and look for kandji-parameter-agent. Compare brief bursts with known check-ins or Parameter events, while remembering that some related traffic may belong to the parent agent. Use the result as a measurement of that device and time window, not as a vendor-published normal range.
Related processes
Common questions
Is kandji-parameter-agent malware?
Not when it is inside the properly signed Iru Agent bundle on a Mac that your organization manages. If it appears unexpectedly on a personal Mac, verify its path, signature, and device-management status with your IT administrator.
Why is kandji-parameter-agent using the internet?
It exchanges assigned Parameter configurations, execution status, and result reports with the organization's Iru Endpoint tenant during management check-ins and Parameter evaluations.
Can I disable kandji-parameter-agent in System Settings?
Apple does not provide a verified System Settings switch for disabling this helper. On a managed Mac, the organization may control it through device-management and Service Management configuration.
How much data should kandji-parameter-agent use?
It should normally produce short, intermittent control-plane traffic, but the vendor has not published a reliable byte range and the division of traffic between this helper and its parent agent has not been verified.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account