We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

ONE, X9, free Scanner, Tahoe, Sequoia and current macOS permission paths verified August 7, 2026

Intego macOS Compatibility and Full Disk Access: ONE vs X9

“Does Intego work on my Mac?” has three different answers now. ONE, the X9 suite and the free App Store Scanner have different operating-system floors, permission models and evidence. Use this guide before a macOS upgrade—and again after restart—so a compatible app is also an actually working one.

ONE/X9/Scanner separatedTahoe table conflict disclosedIntel + Apple silicon checkedPermission switch ≠ proof

Quick answer: Intego ONE supports macOS 12.4 and later—including Sequoia 15 and Tahoe 26—on Intel and Apple-silicon Macs. Current X9 listings start at macOS 10.13, but Tahoe needs current component builds; because Intego publishes two conflicting official minimum tables, use the stricter matrix below and still update to the latest releases. The free Scanner also lists 10.13+, but its App Store sandbox and evidence don't inherit ONE/X9 compatibility claims. After any OS update, verify Full Disk Access, the separate Network Extension where applicable, real-time protection, definitions and scan history.

Compatibility matrix: answer the product question first

Intego's product name isn't a cosmetic detail. The unified ONE app has a newer macOS floor and two explicit permission gates; X9 remains a set of separately versioned components; the free Scanner is a sandboxed App Store utility. A Tahoe statement for one doesn't silently upgrade the evidence for the other two.

Product generationPublished OS/hardware evidencePermission modelWhat compatibility doesn't prove
Intego ONEmacOS 12.4+; Sequoia 15 and Tahoe 26 named; Intel or Apple silicon; 8 GB RAM; 2 GB storageFull Disk Access plus Network Extension/content-filter approvalThat antivirus, definitions and firewall loaded after restart
Intego X9 suiteCurrent downloads list macOS 10.13+; current Tahoe component builds requiredVirusBarrier Full Disk Access; component-specific approvals and updatesThat every separately installed utility is current or native
Free VirusBarrier ScannerApp Store says macOS 10.13+; no Tahoe-specific or processor claim on the listingSandboxed, user-granted scan locations; no paid real-time/network modelPaid-suite real-time protection or full-disk visibility

If you're choosing rather than repairing the product, our ONE-versus-X9 guide maps the generation and feature differences, while the free-versus-paid analysis covers the Scanner's practical ceiling. This page owns the compatibility and permission proof, not the buying verdict.

Identify the app, processor and exact build before changing anything

Start with three screenshots or notes: About This Mac, the Intego product name, and every app/component version. “Intego” alone isn't enough. ONE appears as one current app; X9 installations can contain VirusBarrier, NetBarrier, Washing Machine, Personal Backup and ContentBarrier at different builds; the free Scanner comes from the Mac App Store.

Record the macOS major and point release, Intel or Apple silicon, available RAM/storage, current protection status, last successful update and exact error text. On X9, use Intego's current download and requirements page as the build reference, not an old installer filename or receipt.

This inventory keeps the repair reversible. If the prompt starts after an OS update, you can distinguish a lost permission from an outdated binary; if only NetBarrier is failing, you don't need to erase VirusBarrier evidence; and if the Mac is managed, an administrator gets a useful packet instead of “Intego stopped working.”

Intego ONE: current Tahoe, Sequoia and hardware requirements

Intego's current ONE setup guide applies to macOS 12.4 or later and explicitly names Sequoia 15.x and Tahoe 26. It lists Intel or Apple-silicon processors, 8 GB of RAM and 2 GB of free storage. The current ONE features page repeats the same platform floor.

That's an installation floor, not a performance guarantee for a nearly full or unhealthy Mac. Leave enough free space for macOS itself, app updates, quarantine and scans; complete a backup before a major OS change. If the Mac can't run an Apple-supported release safely, “X9 still installs on 10.13” shouldn't be mistaken for an endorsement of an obsolete operating system.

ONE setup requires Full Disk Access and a Network System Extension/content-filter approval. Those controls live in different System Settings areas and serve different jobs. The antivirus can lack protected-file visibility while the network filter is enabled, or the reverse, so test both states after the first restart.

X9 on Tahoe: use the stricter official matrix, then update past it

Intego's current download page lists X9 from macOS 10.13, but Tahoe support is component-specific. The awkward part is that Intego currently exposes two official Tahoe tables with different minimum versions. The older-address support matrix is stricter than the newer-address Tahoe article.

X9 componentConservative Tahoe floorLatest visible build checked Aug. 7Action
VirusBarrier10.9.9910.9.100Update before OS change
NetBarrier10.9.3810.9.38Confirm exact build
Washing Machine10.9.2710.9.27Confirm exact build
Personal Backup10.9.2910.9.29Confirm exact build
ContentBarrier10.9.2810.9.28Confirm exact build
NetUpdate10.9.37Use latest offered buildUpdate engine first
Common Components10.9.42Use latest offered buildDon't compare only app icons

We use the stricter table as a conservative floor because it can't lower the reader's safety margin, and the current visible application builds already meet it. Still, a minimum isn't a target. Run NetUpdate and install every current component before Tahoe; after the OS change, compare again and verify the engines, not just the version label.

If one X9 utility is below the table while VirusBarrier is current, don't say “the bundle is compatible.” X9's separate-app architecture is exactly why the inventory needs every component. Our installation and setup guide covers authenticated downloads and activation if the update route turns into a reinstall.

The free Scanner has a wider OS floor and a narrower promise

Apple's current VirusBarrier Scanner listing requires macOS 10.13 or later. It also says the Mac App Store sandbox restricts the app to locations the user explicitly grants, and that removal can be limited by the current user's permissions. That isn't the same trust model as paid real-time VirusBarrier.

The listing doesn't make a Tahoe-specific certification or explicit Intel/Apple-silicon statement. We therefore don't copy ONE's Tahoe and processor language onto the Scanner. If the App Store offers the current build to the Mac, install it through the store, grant only the locations you intend to scan, run a test scan and treat the result as on-demand evidence—not background protection.

This distinction matters in troubleshooting. Full Disk Access instructions for ONE or the deep X9 bundle path aren't generic fixes for an App Store sandbox. If the Scanner can't reach another user's files or a protected location, its documented scope may be the explanation rather than a broken paid license.

Intel versus Apple silicon: separate the Mac from the installed components

ONE officially lists both processor families. For X9, Intego states in its own VirusBarrier technical article that VirusBarrier runs natively on Intel and Apple-silicon Macs. That supports the antivirus engine claim, but it isn't a blanket certificate for every old utility or installer someone has carried forward for years.

On a migrated Mac, check each component after installation. A copied application icon can open while its helper, extension or permission state is missing. Download the current generation from the authenticated account, update the components, restart and verify protection; don't treat Migration Assistant or Rosetta's presence as the validation step.

The Mac also has to be supported by the operating system itself. Intego can't make an unsupported Mac model eligible for Tahoe or restore Apple's security-update lifecycle. If the hardware depends on an unofficial patcher, that's outside the vendor compatibility statement and shouldn't be presented as an ordinary supported configuration.

Wait before upgrading when the evidence is incomplete

A public-release compatibility statement doesn't promise support for a developer or public beta. Wait if the vendor hasn't named the stable release, an X9 component is below the conservative floor, NetUpdate can't complete, the existing scanner is already disabled, the backup is unverified, or the Mac is managed and the extension policy is unknown.

Also pause when the system is in the middle of another security change: account transfer, X9-to-ONE upgrade, failed uninstall or storage repair. Layering a major macOS upgrade onto an unresolved license or permission problem destroys the clean before/after evidence that makes support useful.

There's no prize for being first. Update the security software, record a healthy baseline, finish a recoverable backup, and then install the stable OS release. That sequence is faster than diagnosing three moving parts after the fact.

Update macOS without breaking Intego: eight-step workflow

  1. Identify the Intego generation. Record whether the installed product is Intego ONE, an X9 component or the free App Store Scanner; don't borrow requirements or permission paths from another generation.
  2. Record the Mac and app state. Save the macOS version, Intel or Apple-silicon processor, every Intego component version, update status, permission state and any exact error before changing the system.
  3. Update Intego before macOS. Install the latest supported ONE or X9 application and component updates, restart when requested and confirm the app opens before starting the operating-system upgrade.
  4. Make a current backup. Complete and verify a Time Machine or equivalent backup so a failed OS or security-software transition is recoverable without deleting diagnostic evidence.
  5. Install only a stable supported macOS release. Avoid assuming that a beta build is covered by a vendor statement for the public Tahoe or Sequoia release, and check managed-Mac policy before proceeding.
  6. Recheck both permission gates. After the upgrade, verify Full Disk Access separately from Network Extensions or content filtering; reapprove only the specific Intego application when macOS asks.
  7. Prove the protection engines loaded. Open Intego and verify the app and definitions are current, real-time antivirus is active, network protection is active where included, and a scan completes into history.
  8. Restart and verify persistence. Restart once more, repeat the protection checks and keep a redacted evidence packet if a permission prompt, disabled scanner or network loop returns.

The two restarts are intentional. The first lets the OS and extension changes settle; the final restart tests persistence. If protection works only until reboot, the setup isn't finished even when every settings toggle looked green during the session.

Keep the evidence redacted. Version numbers, menu states and error text help; account passwords, X9 serials, hardware serials, private filenames and other users' device records don't. If a license move is part of the change, use the account and device-transfer guide before erasing the old Mac.

What Full Disk Access actually opens—and why antivirus needs it

Apple's Privacy & Security guide defines Full Disk Access as access to all files, including protected app data from Mail, Messages, Safari and Home, Time Machine backups and certain administrative settings for all users. It's broader than the nearby Files & Folders control.

Antivirus needs that visibility to inspect protected locations, but the breadth is also why approval should be deliberate. Install from Intego's authenticated account or the App Store, confirm the app identity, and grant the permission only to the intended app. A search ad, lookalike “support” download or random helper should never receive broad disk access merely because it uses the Intego name.

Full Disk Access is permission, not performance. It doesn't prove definitions are current, real-time scanning is active, the network filter loaded or a test scan can finish. Those are separate observations in the verification section below.

Grant Full Disk Access to Intego ONE on current macOS

Open ONE and use its setup prompt to reach System Settings. On current macOS, go to Privacy & Security → Full Disk Access, find Intego ONE and turn it on. macOS may ask for the local administrator password; that credential belongs to the Mac, not the Intego account.

Return to ONE rather than assuming the control propagated. Complete the remaining setup, update the app and definitions, and check that antivirus protection reports active. If ONE immediately asks again, capture the prompt, restart once, then use the app-specific remove/re-add branch—not a broad reset of every program's privacy database.

Don't follow an X9 tutorial that tells you to browse inside virusbarrier.bundle. ONE is a different product generation and the current vendor instructions identify the ONE app directly. Mixing the paths can add the wrong binary or leave the actual app unapproved.

Grant Full Disk Access to VirusBarrier X9 without mixing macOS eras

Intego's X9 Full Disk Access guide separates settings eras. On Ventura and later, open System Settings → Privacy & Security → Full Disk Access, enable VirusBarrier and approve with the Mac administrator password. On Mojave through Monterey, use System Preferences → Security & Privacy → Privacy → Full Disk Access and add the application there.

The vendor publishes a deep manual fallback through /Library/Intego/virusbarrier.bundle when X9 can't be dragged into the older list. Treat it as an X9-specific fallback, not the default route and not a ONE/Scanner instruction. First confirm the current app version and follow the direct application prompt.

After approval, reopen VirusBarrier and inspect the real-time scanner. A visible list entry is necessary but not sufficient, particularly after an OS update. If the engine remains disabled, preserve the error and move down the repair ladder rather than toggling randomly.

The Network Extension is a second, independent gate

ONE's network protection is managed under General → Login Items & Extensions → Network Extensions, not under Full Disk Access. Apple's current extensions guide explains that network extensions can provide VPN and content-filter behavior; endpoint-security extensions are a separate category.

Open Network Extensions, view by app or category, enable Intego ONE, authenticate if asked and allow network content filtering. Then return to ONE and confirm the network protection state. A green network switch with the firewall still inactive is evidence of an incomplete load, not a reason to keep clicking the same control.

If the permission request loops, Intego's network-prompt guide starts with this exact extension check, then uses restart and reinstall branches. It doesn't turn Full Disk Access into a substitute for the network approval.

Verify protection after the switches: five pieces of evidence

Full Disk Access and Network Extension gates followed by Intego protection verification
Editorial permission-proof map, not a macOS or Intego screenshot. The settings paths and verification checklist in the text are the accessible source of record.

First, confirm the application and every relevant X9 component are current. Second, update malware definitions and record the successful timestamp. Third, confirm real-time antivirus reports active without a Full Disk Access warning. Fourth, confirm network protection reports active if the plan includes it. Fifth, run an ordinary quick or targeted scan and verify the result appears in scan history.

Restart the Mac and repeat the state checks. You don't need to download live malware or disable macOS security to prove the product works. A completed normal scan, current definitions, persistent real-time state and active network filter are useful, low-risk evidence.

For a deeper product verdict, our current Intego review separates lab evidence from local configuration. A lab certificate can support detection performance for a tested product/build; it can't prove that this Mac granted the right permissions today.

Why a green toggle can coexist with a disabled scanner

macOS stores privacy approvals separately from the application process that consumes them. An OS update, app replacement, changed bundle identity or stale permission record can leave a switch visible while the active helper can't use the approval. Current macOS community threads report similar “enabled but still prompting” behavior across unrelated apps; that's directional evidence, not proof of an Intego-wide defect.

Intego itself documents a Ventura case where VirusBarrier loses Full Disk Access and Real-Time Scanner is disabled or fails to load. Its first repair is specific: remove VirusBarrier from the FDA list, reopen the app and follow its prompts to add it again. This rebuilds the app-specific relationship instead of changing every privacy decision on the Mac.

The same reasoning applies to network protection. Confirm the extension under Login Items & Extensions, allow the content filter, restart and inspect ONE. If the loop remains, the next useful evidence is version, extension state and error—not ten more screenshots of the same green control.

Use a repair ladder with the smallest blast radius first

SymptomFirst safe branchProof after repair
Unsupported/unknown Tahoe buildUpdate all components; compare with stricter matrixCurrent versions survive restart
FDA warning or scanner disabledRemove/re-add only ONE or VirusBarrier approvalReal-time state active; scan completes
Network permission loopsEnable ONE under Network Extensions; allow filterNetwork protection active after restart
App update can't completePreserve error; use authenticated latest installerVersion and definitions current
State breaks after every rebootSupported reinstall; avoid manual component deletionPermissions and engines persist twice
Managed approval is unavailableSend evidence to MDM administratorApproved policy and loaded extension
All app-specific repairs failVendor support with redacted packet; plan broad reset only if directedOther software approvals accounted for

The vendor's real-time-scanner page also prints a broad tccutil all-files reset and warns that it resets permissions for all software. We deliberately don't reproduce the executable command. It has a much larger blast radius than removing one Intego entry and can force unrelated backup, accessibility, terminal and security tools to request approval again.

If support or an administrator decides the broad reset is necessary, first record current privacy approvals, finish a backup, close sensitive work and plan the reauthorization window. Never combine it with disabling SIP, lowering startup security or deleting arbitrary files from `/Library`; those aren't ordinary ONE/X9 permission fixes.

Managed work and school Macs need policy, not a bypass

Apple's system-extension deployment guide explains that device management can allow or restrict extensions and can prevent users from approving their own. On a company or school Mac, a missing control or rejected approval may be intended policy rather than a local malfunction.

Send the administrator the Mac model/processor, macOS version, ONE/X9 generation, exact application and component builds, the extension category, the prompt or error and the time it occurred. Redact account passwords, serial numbers, private paths and unrelated device records. Ask whether the current Intego team identifier and required endpoint/network extensions are approved by policy.

Don't bypass MDM, disable System Integrity Protection or reduce Apple-silicon startup security to make a current ONE prompt disappear. Those changes expand risk and may violate organizational policy. The correct finish is a managed approval plus the same post-restart engine verification used on a personal Mac.

Intego macOS compatibility and Full Disk Access FAQ

Does Intego work with macOS Tahoe 26?

Yes, but the answer depends on the product generation and build. Intego ONE officially supports Tahoe 26 on macOS 12.4-or-later Macs. X9 has a Tahoe component matrix; because two official Intego pages currently publish different minimums, use the stricter listed floor and install the latest available X9 components before upgrading.

Does Intego work on Apple silicon Macs?

Intego ONE explicitly supports Intel and Apple-silicon processors. Intego also states that VirusBarrier X9 runs natively on both architectures. That doesn't automatically certify every old X9 utility or archived installer, so update each installed component and verify it after restart.

What is the oldest macOS version Intego supports?

Current ONE documentation starts at macOS 12.4. Current X9 download listings start at macOS 10.13 High Sierra. The free VirusBarrier Scanner App Store listing also says macOS 10.13 or later, but its sandbox and feature model differ from paid real-time protection.

Does Intego need Full Disk Access?

Paid antivirus protection needs it to inspect protected data that macOS keeps behind privacy controls, including data from Mail, Messages and Safari. Apple describes Full Disk Access as broad access, so grant it only to the verified Intego app you intentionally installed—not to a lookalike downloaded from search.

Is Full Disk Access the same as the Intego network extension?

No. Full Disk Access controls protected-file access under Privacy & Security. The network extension or content filter is managed under General → Login Items & Extensions and handles network protection. ONE can need both; turning on one doesn't enable the other.

Why does Intego still ask for Full Disk Access when the switch is on?

The stored permission can become stale after an OS or app update. Record the current state, update Intego, restart, remove only the specific Intego entry from Full Disk Access, reopen the app and follow its prompt to add it again. Then verify the scanner rather than trusting the switch alone.

Why is VirusBarrier Real-Time Scanner disabled after a macOS update?

Intego documents an update case in which VirusBarrier lost Full Disk Access and the real-time scanner failed to load. Re-add the specific VirusBarrier approval first, then verify current app and definition versions. Use reinstall or vendor support before any broad all-app permission reset.

Should I run a tccutil reset to fix Intego permissions?

Not as a routine first fix. Intego's own page warns that its published SystemPolicyAllFiles reset affects permissions for all software on the Mac. Use the app-specific remove/re-add route, updates, restart and supported reinstall first; use a broad reset only with a recovery plan and informed vendor or administrator direction.

Does the free VirusBarrier Scanner have the same permissions as ONE or X9?

No. The App Store Scanner is sandboxed and can scan only locations the user grants; removal can also be limited by the current user's permissions. It isn't a substitute for the paid products' real-time and network-permission model, and its listing doesn't make a Tahoe-specific certification claim.

What if I can't approve Intego on a work or school Mac?

The Mac may be managed by MDM, which can allow or restrict system, endpoint-security and network extensions. Capture the macOS version, Intego generation/build, exact extension category and prompt, then contact the organization administrator. Don't bypass management, disable SIP or reduce startup security.

Bottom line: compatibility is a matrix; protection is a test

ONE, X9 and the free Scanner don't share one compatibility answer. Match the exact generation to its published OS and hardware evidence, update before macOS, use the stricter X9 Tahoe matrix where Intego's own pages conflict, and never transfer paid-suite claims to the sandboxed Scanner.

Then prove the local result. Full Disk Access opens protected files; the Network Extension handles network filtering; neither green switch alone proves the engines loaded. Current versions, current definitions, active real-time and network states, a completed scan/history entry and persistence after restart are the finish line.