What is studentd on macOS?
Last updated: 2026-08-05
studentd is Apple’s built-in student-side agent for Classroom. Its presence does not by itself mean that a school manages the Mac or that someone is viewing its screen. Apple provides no supported switch for disabling the process.
What it is
studentd is the student-side control agent used by Apple Classroom. Apple’s local manual describes it as the component that manages the student’s Classroom experience. The verified executable is /usr/libexec/studentd, supplied and signed by Apple. com.apple.studentd is used as its code-signing identifier and launchd label; calling it an ordinary application bundle ID is not quite precise because this standalone executable does not have a traditional app Info.plist.
After a Mac joins a class, studentd participates in carrying out actions initiated by the teacher. Depending on the class and its policies, those actions can include opening an app or webpage, locking the device, sharing material, viewing the screen, or using AirPlay for the screen. These are Classroom capabilities, not evidence that every running instance is currently performing all of them.
launchd manages studentd on demand. The process can therefore appear even when no class has been configured. Seeing it in Activity Monitor or a network monitor does not, by itself, show that the Mac is enrolled in school management, connected to an active class, or having its screen viewed.
Why it talks to the network
Nearby Classroom sessions use Bluetooth to determine whether devices are close to one another. Communication between the student and teacher devices then takes place over local Wi-Fi that permits device-to-device connections. Apple assigns TCP port 3285 to Classroom communication and TCP port 3284 to document sharing.
Classroom is no longer limited to nearby devices on the same local network. Remote classes, as well as classes mixing nearby and remote students, can use the internet with Managed Apple Accounts. Those arrangements depend on Apple services for classroom rosters, device verification, Apple Accounts, and iCloud in addition to the Classroom interaction itself.
Commands from the teacher, student or device status, document transfers, screen viewing, and AirPlay can all trigger communication. However, Apple does not publish a connection-by-connection map showing which hosts, protocols, or payloads are recorded specifically under studentd. In particular, it is unverified whether a given large transfer will be attributed to studentd, IDS, AirPlay, or another supporting process. A connection shown under a different process is therefore not proof that Classroom played no part, and traffic attributed to studentd should not automatically be treated as the entire session.
How much traffic is normal
There is no reliable process-level traffic baseline for studentd. Apple has not published a normal byte range, so a specific MB figure would be guesswork.
When there is no active class, the functional range may be close to no sustained transfer, with only occasional control communication. During a connected class, commands and status changes may produce small bursts. Those observations describe the likely scale of the Classroom functions involved; they do not establish a guaranteed idle level for the process.
Document sharing can grow to the scale of the files being transferred. Screen viewing or AirPlay can reach the scale of an interactive screen stream. Whether those larger payloads are charged directly to studentd in process-level accounting remains unverified. For that reason, it is not accurate to summarize studentd as a process whose traffic is always tiny, nor is there enough evidence to label any single fixed total as normal for every class.
Can you turn it off
The supported conclusion is to keep studentd. Apple does not provide a System Settings switch that disables the process itself. Force-quitting it, attempting to unload it through launchctl, deleting it, or blocking its communication can prevent nearby, remote, or hybrid Classroom sessions from being joined or maintained. It can also interfere with teacher commands, document sharing, screen viewing, and AirPlay. Because launchd manages the agent, ending it may only cause it to start again.
A user-managed class can sometimes be left through Apple menu > System Settings > Classroom > select the class under Classes > Remove Class > Remove. That removes the Mac from the selected class; it does not disable studentd. A class installed or controlled through MDM may also prevent the user from removing it.
Apple’s manual says the program should not be invoked directly, and Apple documents no supported process-level shutdown method. If the concern is an unfamiliar class rather than the existence of the system component, the relevant question is whether that class can be removed under its management policy.
What people get wrong
1. “It only works on the local network.” That description is outdated. Classroom supports nearby classes, internet-based remote classes, and classes that combine nearby and remote students.
2. “Only school-managed or MDM-enrolled Macs use it.” Apple also supports unmanaged nearby classes that do not require MDM or Apple School Manager. The presence of studentd is therefore not evidence of MDM enrollment.
3. “If studentd is running, a teacher is watching my screen.” The local manual explicitly says it may run when no class is configured. Screen viewing is one particular Classroom operation, and access to it is constrained by student settings or MDM policy.
4. “It is malware or software secretly installed by a school.” The verified executable at /usr/libexec/studentd is an Apple-supplied, Apple-signed system component. That conclusion does not extend to an unrelated file that merely uses the same process name. If its path or signature differs, inspect that file separately.
5. “Its traffic is always tiny.” There is no published process-level baseline supporting that claim. Idle control activity may be limited, while document and screen-related features may generate noticeable traffic. It is also unverified which process receives the byte attribution for every large payload.
6. “Killing it, unloading it, or deleting it is a safe system optimization.” Apple provides no supported process-level off switch and says the program should not be called directly. Interference can break Classroom functions, while launchd may restore the process.
7. “It is included on every Mac and every macOS release.” That universal claim has not been established. The research directly verified a current local installation, but that is not enough to promise identical availability across every historical Mac model and system release.
Seeing what it actually used
Because there is no trustworthy fixed baseline, the practical next step is to measure studentd on the Mac in question. Bytetally’s per-process statistics can show what was attributed to studentd while the Mac was idle and while a class was active. Treat that figure as process attribution, not proof that every Classroom-related byte was recorded under the same name.
Related processes
Common questions
What is studentd on my Mac?
studentd is the Apple-provided student-side control agent for Classroom. It helps carry out classroom actions such as opening an app or webpage, sharing documents, locking a device, and supporting screen viewing or AirPlay.
Does studentd mean my teacher is watching my screen?
No. studentd may run even when no class is configured. Screen viewing is a specific Classroom action and is also subject to student settings or MDM policy.
Why is studentd using the network?
Classroom uses local communication for nearby classes and internet services for supported remote or hybrid classes. Commands, status updates, document sharing, screen viewing, and AirPlay can all cause communication.
Can I disable studentd?
Apple does not provide a system switch for disabling studentd. Force-quitting, unloading, deleting, or blocking it can break Classroom sessions, and launchd may start it again.
Is studentd malware?
The Apple-signed program at /usr/libexec/studentd is a macOS system component. A file with the same name at another path, or with a different signature, should be checked separately.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account