LockDown Browser Full Disk Access on Mac - When and Why

Full Disk Access (FDA) is the most permissive macOS TCC permission - it lets the holding app read every file in protected locations including Mail, Messages, Safari history, Time Machine backups, and the entire user home directory. LDB requests FDA only on rare institutional configurations. The privacy implications are substantial; understand what you're granting before clicking Allow.

What Full Disk Access actually grants

Apple's FDA permission removes the macOS sandboxing that blocks apps from reading these locations:

This is a much broader grant than Camera or Microphone. An app with FDA can read your entire digital life on the Mac.

When LDB asks for FDA

LDB requests FDA only in specific institutional configurations - typically professional certification programs or law schools using LDB for high-stakes assessments where the Dashboard config explicitly enables "Verify absence of forbidden files". The check itself looks for specific files that violate the academic-integrity policy (cached answer keys, pre-written essays, etc.).

Most undergraduate and standard graduate course exams do not require FDA. If LDB asks for it, your specific course is in a small minority.

What LDB does (and does not) do with FDA

From observed behaviour during the LDBypass test fleet reproductions:

Granting FDA - procedure

  1. System Settings → Privacy & Security → Full Disk Access.
  2. Click the (+) plus button.
  3. Navigate to /Applications and select LockDown Browser.app.
  4. Authenticate with admin password.
  5. Toggle on. Quit and relaunch LDB.

If you're uncomfortable granting FDA

Reasonable options:

  1. Email your instructor. Ask whether the FDA requirement can be relaxed (some Dashboard configs default to FDA but the instructor doesn't actually need it).
  2. Take the exam on a borrowed Mac. Use a Mac that does not contain your personal data. Granting FDA on a "clean" Mac limits the exposure.
  3. Take the exam in person. Most institutions allow alternative testing arrangements when documented privacy concerns exist.
  4. Document the concern in writing to your instructor and academic advisor. Universities usually have a path through the dean of students for FDA-grade objections.

Revoking FDA after the exam

Critical: revoke FDA immediately after the exam ends. LDB does not need it between exams.

  1. System Settings → Privacy & Security → Full Disk Access.
  2. Toggle LockDown Browser off, or click (-) to remove entirely.
  3. The next exam that requires it will prompt fresh.

Frequently asked questions

Is FDA the same as Accessibility?

No. Accessibility = monitor keystrokes, send synthetic events, read UI of other apps. FDA = read protected file system locations. They're separate permissions; some institutions require both.

Will Respondus see my email if I grant FDA?

In principle, yes - the permission allows reading ~/Library/Mail. In observed behaviour, LDB scans for specific filenames, not content. The risk is the gap between observed behaviour and what the permission technically allows.

Why does my course require FDA when classmates' courses don't?

Each course has its own Respondus Dashboard configuration. Your instructor or department enabled the "verify forbidden files" feature; the default is off.