How to Install and Set Up Intego ONE on Mac—and Prove It Works
Intego can be present in Applications while the protection that matters is still off. The current setup needs two separate macOS permissions, a verified account, fresh definitions, real-time Antivirus, Firewall filtering and a first full scan. This walkthrough ends only when those controls survive a restart and the account, app and scan history agree.

Quick answer: Use the installer inside your authenticated Intego account, sign in to ONE with the purchase email and account password, grant Full Disk Access and the Intego ONE Network Extension, allow useful notifications, update the app and definitions, turn on Real-Time Protection and Firewall filtering, then complete a Full Scan. Restart once and recheck every control; an installer success message alone doesn't prove protection.
Intego ONE setup in ten verifiable steps
- Check the Mac and subscription. Confirm macOS 12.4 or later, Intel or Apple silicon, at least 8 GB RAM, 2 GB free space, an active ONE plan and an administrator account.
- Download the installer from My Account. Sign in at Intego.com/one, use Download below Your Plan and Your devices, and avoid ads, mirrors or email attachments.
- Run the downloaded Intego installer. Open the current installer from Downloads, review the publisher and prompts, then authenticate with the Mac administrator password.
- Activate the account and sign in. Verify the purchase email, create the portal password if required, and sign in to ONE with the registered email and password rather than an X9 serial number.
- Grant Full Disk Access. Open the permission prompt or Privacy & Security settings, enable Full Disk Access for the expected Intego ONE app and authenticate the change.
- Enable the Network Extension. Open General, Login Items & Extensions, Network Extensions, enable Intego ONE and allow its network-content filter.
- Allow useful notifications. Enable Intego ONE notifications so protection failures and detections are visible, while keeping previews private on the lock screen.
- Update the app and definitions. Enable automatic application updates, run Check for Updates and manually refresh virus definitions before the first full scan.
- Verify Antivirus and Firewall. Confirm Real-Time Protection and Firewall filtering are on, the network extension remains enabled and normal internet access still works.
- Run the first full scan and restart test. Complete a full scan, save the history details, restart the Mac and prove the protected state returns without a permission loop.
The sequence matters. Account download reduces installer risk, permissions define what the product can see and filter, and the full scan covers files that real-time monitoring didn't retroactively inspect. The restart test catches the common “permission looked enabled until the helper reloaded” failure.
Allow about 45 minutes for setup plus however long the first full scan needs. File count, archives, external disks and storage speed make a universal scan-time estimate dishonest, so the HowTo duration covers the configuration work rather than promising completion of every disk scan.
Check compatibility, access and the old antivirus before downloading
Intego's current ONE setup page requires macOS 12.4 or later, including macOS 15 Sequoia and macOS 26 Tahoe, on Intel or Apple silicon. It lists at least 8 GB RAM, 2 GB available storage, Full Disk Access, Network System Extension permission and account credentials.
| Before install | Evidence to capture | Stop if |
|---|---|---|
| Mac version and hardware | About This Mac: OS, chip, memory | Below macOS 12.4 or 8 GB RAM |
| Free space | General → Storage | Less than the documented 2 GB minimum |
| Subscription | Tier, Mac count, renewal date | No active ONE entitlement |
| Account access | Purchase email and verified portal login | Email is unknown or inaccessible |
| Administrator rights | Local admin can authenticate installer/permissions | Managed policy blocks changes |
| Existing antivirus | Provider, license, uninstall/rollback instructions | Another real-time engine is still active |
Preserve the old product's license and settings before removal, then uninstall through its supported process and restart. Don't disable Apple's XProtect, Gatekeeper or System Integrity Protection. ONE replaces another third-party real-time antivirus, not macOS's built-in security model.
Download ONE from the authenticated account, not a search ad
The current download article sends customers to Intego.com/one, then Sign In. On Overview, the Download control appears below Your Plan and Your devices. A second Installer link exists in Devices & Users under “Set up Intego on your Mac.”
That account route proves the installer is tied to the expected entitlement and avoids look-alike ads, mirrors and unsolicited email attachments. The support page we checked doesn't publish a checksum, so we don't invent one. Keep the purchase receipt, but don't treat an attached installer from email as equivalent to the account download.
Save the file in Downloads and record the time it arrived. Intego's current articles describe the installer inconsistently—one says disk image while a troubleshooting page says `.pkg`—so use the actual file delivered by the authenticated account and follow its signed macOS installer flow rather than renaming it to match a guide.
Run the installer and read every macOS prompt
Open Finder → Downloads and launch the current Intego installer. macOS should show the package/disk-image flow that came from the account; review the publisher and destination, continue through the installer and enter the local Mac administrator password when asked. The purchase email/password and Mac admin password are different credentials.
If macOS says the developer can't be verified, stop and redownload through the account rather than bypassing Gatekeeper by habit. If a managed Mac blocks the package or extensions, don't disable policy controls. Record the exact message and hand it to the administrator who owns the MDM profile.
A finished installer means files were placed on the Mac. It doesn't prove account entitlement, protected-file access, network filtering, current definitions or real-time monitoring. Leave the setup window open until those layers are complete.
Create or verify the Intego account, then sign in with the purchase email
Intego's August 5 account guide says both ONE and X9 customers may need to activate the newer portal before first login. After a new purchase, confirm the displayed email and create a password of at least eight characters with uppercase, lowercase and a digit.
If setup wasn't finished on the Thank You page, look for “Verify Email Address” from `[email protected]`. The receipt email proves a transaction; the verification email establishes portal access. Intego's general setup page still contains a placeholder where an email subject should be, so use the newer account article rather than guessing.
Sign in to ONE with that registered email and password. If the account isn't found, verify the exact purchase email and whether the activation link was completed. A useful support packet contains the email, exact error, verification state and ONE/X9 generation; it never contains the password.
ONE uses account activation; X9 uses serial numbers
A current ONE login asks for the Intego account email and password. Legacy VirusBarrier/NetBarrier X9 applications use serial-number activation and NetUpdate. If the screen asks for a name and serial number, stop treating it as a ONE setup and identify which generation was downloaded.
Our ONE vs X9 comparison maps the product families and the missing legacy utilities. An eligible X9 customer upgrading to ONE may need to refresh the account entitlement, but shouldn't paste an X9 serial into ONE. Save the serial privately only for legitimate legacy recovery.
The product choice should be settled before permissions are granted. If a Mac is below ONE's requirements or still depends on ContentBarrier or Personal Backup, installation may need to remain X9-specific instead of forcing the new app.
Grant Full Disk Access to the exact Intego ONE app
Full Disk Access and the network extension are separate macOS approvals. Intego's current ONE permission page says the antivirus needs FDA to scan protected Mail, Messages, Safari and other user data. Without it, some locations remain outside the intended coverage.
Use the post-install prompt's Open System Settings button or open System Settings → Privacy & Security → Full Disk Access. Confirm that the item is the expected Intego ONE application, switch it on and authenticate with the Mac username/password. If macOS asks to quit and reopen, do that before judging status.
FDA is broad by design, so caution is appropriate. A community permission discussion makes the right general point: access appropriate for antivirus or backup shouldn't become a generic fix for every app. Verify the publisher and need; never grant Terminal FDA or disable SIP simply because a copied troubleshooting answer says so.
Enable the Network Extension and allow content filtering
Open System Settings → General → Login Items & Extensions → Network Extensions. Use By App or By Category, open the information control for Intego ONE, enable its Network Extension, authenticate and allow network-content filtering. This is what permits the ONE Firewall to evaluate application connections.
Intego's current network-permission guide notes that a separate window may ask which running apps or systems can use the network. Read the rule target before choosing Allow. A content filter isn't the same as a VPN and shouldn't be described as encrypting traffic.
After enabling the extension, open a known website and check that ordinary DNS/web access still works. If the internet fails, preserve the permission state and recent firewall decisions before changing anything. Randomly allowing every process can hide the rule that caused the failure.
Allow alerts without exposing detection details on the lock screen
Enable Intego ONE notifications during setup so permission failures, detections and scan completion are visible. In macOS, open System Settings → Notifications → Intego ONE and turn on Allow notifications. Apple's current Notifications settings guide explains per-app styles and preview controls.
A persistent style is reasonable for security alerts that shouldn't disappear unnoticed. Set previews to When Unlocked if filenames or detection details could expose private information on the lock screen. Don't call every alert “critical” in Apple's technical sense unless the app actually requests that notification class.
Trigger evidence later with a harmless completed scan, not real malware. Confirm that the notification opens the correct ONE view and that a Focus mode hasn't silently hidden it.
Update the application and virus definitions before the first scan
In ONE Settings → General, keep automatic application updates enabled and run Check for Updates manually during setup. In Antivirus settings, use the manual virus-definition update. Record the app version and definition date so a later support report can distinguish stale data from a permission or engine failure.
The current interface guide also exposes email scanning, scan-on-volume-mount, Windows-malware detection, power-saving mode, archive scanning and completion sounds. Leave the security defaults alone for the first baseline; tune archives or power-saving only after one clean, measured full scan.
Update failures can come from account entitlement, network filtering, DNS/proxy controls or another security product. Don't disable every layer at once. Capture the error and test the account, app update and definition update separately.
Turn on Real-Time Protection and prove the counter moves
Open Antivirus and confirm Real-Time Protection is enabled. Intego's ONE Antivirus guide says the module monitors files, folders or programs as they're written or opened and exposes a scanned-file counter. A green dashboard without that control enabled isn't enough.
Create or copy a harmless text file in a readable folder and watch for the counter/history to change; don't download live malware. A clean file won't generate an alert, so the goal is evidence that monitoring is operating. Keep Apple's built-in protections enabled throughout.
Real-time monitoring protects new activity after activation, not every pre-existing file on disk. That is why the first full scan remains necessary even when the status says Actively Protected.
Start the Firewall with a safe, observable baseline
Confirm Firewall filtering is on after the network extension is enabled. The interface guide recommends allowing Apple-published and Intego-published applications because blocking core system or product update traffic can break normal operation. App Store and validly signed applications can be handled by the user's risk tolerance, while unsigned processes deserve individual attention.
Don't approve every first-connection prompt reflexively. Read the executable/app name, publisher, destination context and whether the action matches what you just did. “Ask” is useful when the process is unfamiliar; Block is appropriate when the request is unexpected and preserved for investigation.
Test browser, mail and software update access after the baseline is set. The paid Firewall offers connection control, but AV-Comparatives found no malicious/fraudulent-site protection in ONE 1.2, so firewall filtering shouldn't be presented as a phishing verdict. Our current Intego review keeps that lab limitation visible.
Run a Full Scan and preserve the history record
After the app and definitions are current, choose Full Scan. Intego says it covers the startup disk and locally mounted disks; duration depends on file count and attached volumes. Disconnect unneeded archives/backups only if you deliberately want a startup-disk baseline, and note that scope in the record.
Let the Mac remain awake and avoid starting another antivirus scan. In History, save the file count, date/time, duration, scan type/location and any threats. If a detection appears, review the exact path and quarantine action before choosing Repair, Ignore or Trust; Trust moves the item into the Safe List and excludes it from future scanning.
A completed scan with an unexpectedly tiny file count needs investigation. Verify Full Disk Access, selected disks, skipped/incomplete messages and scan history rather than accepting the word “complete.”
Restart once and prove all five layers return
Restart the Mac after permissions, updates and the first scan. Sign in, wait for background services to load and check the account, permissions, Antivirus, Firewall and scan history. Repeated permission prompts or a disabled real-time toggle after restart mean setup isn't complete.
| Layer | Proof after restart | Failure signal |
|---|---|---|
| Account | Correct plan and device visible | Trial/expired/unknown device |
| Permissions | FDA and Network Extension remain on | Prompt loop or missing toggle |
| Antivirus | Real-Time on, definitions current, scan history retained | Disabled engine or empty/stale history |
| Firewall | Filtering on, rules visible, internet works | Extension off or normal traffic blocked |
| Operations | Notification and update checks succeed | Silent alerts or update error |

Capture screenshots that don't expose the account email, serials, device identifiers or filenames. The useful support packet is state, version, time and exact error—not the credentials that protect the account.
Fix account and permission loops without weakening macOS
Account not found: verify the purchase email, complete the `[email protected]` verification message and try the portal in another clean browser session. No download: confirm an active ONE plan and use Overview or Devices & Users. Installer blocked: redownload through the account and preserve the exact Gatekeeper/MDM message.
Full Disk Access still missing: confirm the exact Intego ONE entry, toggle it only after authenticating, quit/reopen and restart. Network prompt repeats: check General → Login Items & Extensions → Network Extensions, then update ONE and macOS. Intego recommends a supported clean reinstall only after those checks.
Don't disable SIP, Gatekeeper, XProtect or the macOS firewall; don't give Terminal Full Disk Access; don't run broad `tccutil` resets copied from a forum. Those actions change unrelated security state and can destroy the evidence needed to understand one permission failure. Escalate with timestamps, screenshots, versions and the exact branch already tested.
Multiple Macs and managed devices need a per-device proof record
The subscription's Mac count limits how many devices can be registered, but it doesn't grant permissions remotely to an unmanaged personal Mac. Install and verify each Mac separately, label devices clearly in the account and remove a stale entry only after identifying it. Don't evict a family member's active Mac just to make a seat appear.
On a managed work/school Mac, MDM may need to approve the package, Full Disk Access profile, system/network extension and content filter. Local administrator credentials don't override every policy. Send the IT owner the vendor article URLs, bundle/publisher evidence from the actual installer and requested permissions instead of asking for security controls to be disabled.
For mixed old/new Macs, read the ONE/X9 migration guide before converting the subscription. For tier, term and seat-count billing, use the current pricing guide. Installation and purchasing are separate decisions.
Intego ONE installation and setup FAQ
What are the current Intego ONE system requirements?
Intego's current setup page requires macOS 12.4 or later, including macOS 15 Sequoia and macOS 26 Tahoe, on an Intel or Apple silicon Mac. It also lists at least 8 GB RAM, 2 GB free storage, Full Disk Access, Network System Extension permission and Intego account credentials.
Where should I download the Intego ONE installer?
Use the authenticated Intego account. Sign in at Intego.com/one, open Overview and use Download below Your Plan and Your devices, or use the installer link under Devices & Users. Avoid search ads, mirrors and unsolicited attachments, because Intego's checked support page doesn't publish a checksum for us to repeat.
Does Intego ONE use a serial number?
No. ONE activates with the email and password for the current Intego account. Legacy X9 applications use serial-number activation, so a screen asking for a serial is evidence that you're installing or opening the X9 generation rather than ONE.
Why does Intego ONE need Full Disk Access?
macOS protects Mail, Messages, Safari data and other user files from broad app access. Intego says ONE needs Full Disk Access to scan those protected locations as intended. Verify the exact installed app and publisher first, then enable the permission only for Intego ONE in Privacy & Security.
Why does Intego ONE need a Network Extension?
The ONE Firewall filters and evaluates application network connections through a macOS network extension/content filter. Enable the Intego ONE extension in General → Login Items & Extensions → Network Extensions, then allow network-content filtering. This permission is separate from Full Disk Access.
How do I know Intego ONE is really protecting the Mac?
Don't stop at a successful installer message. Confirm the correct plan/device in the account, Full Disk Access and Network Extension on, notifications allowed, app and definitions current, Real-Time Protection and Firewall filtering enabled, a completed full scan in History, working internet and the same protected state after restart.
Which scan should I run after installing Intego ONE?
Run a Full Scan after updating the application and virus definitions. Real-Time Protection watches files written or opened after it starts, but it doesn't retroactively prove every existing file was checked. Save the full-scan history with its file count, duration, type/location and threat result.
What should I do if Intego keeps asking for network permission?
Check System Settings → General → Login Items & Extensions → Network Extensions and enable Intego ONE by app or category. Then update ONE and macOS and restart. If the prompt still loops, use Intego's supported uninstall/reinstall route from the authenticated account; don't reset all privacy permissions or disable macOS protections as a first fix.
Can I install Intego ONE on more than one Mac?
Only up to the Mac count attached to the subscription. Confirm the plan and Devices & Users page before installing, identify any stale device carefully, and don't remove a family member's active Mac to free a seat. Every Mac still needs its own local permissions and restart verification.
Should I uninstall another antivirus before installing Intego ONE?
Yes if the other product provides real-time antivirus protection. Two real-time engines can duplicate file monitoring and interfere with quarantine or performance. Preserve the old product's license and uninstall instructions, remove it through its supported process, restart, then install and verify ONE. Apple's built-in XProtect and Gatekeeper should remain enabled.
Bottom line: the restart proof is the finish line
A safe Intego ONE setup isn't difficult, but it has more than one green button. Use the authenticated download, the correct account generation, exact ONE permissions, current software/definitions, real-time Antivirus, Firewall filtering and a full-scan record. Each layer answers a different failure mode.
Finish by restarting and checking the same state again. If the permission loop returns, the engine is off or the account/device doesn't match, keep troubleshooting with evidence. If every layer persists and normal networking works, the Mac is configured—not merely installed.