macOS: Operation not permitted — Terminal/app lacks Full Disk Access (TCC privacy protection)
macOS privacy protection (TCC) blocked access to protected folders (Desktop, Documents, Downloads, Mail, Photos, external volumes) for the Terminal or app.
Seen on:
macOS
Meaning
Even sudo can’t bypass TCC. Grant the app (Terminal, iTerm, VS Code, your backup tool or cron’s /usr/sbin/cron) Full Disk Access or the specific folder permission in System Settings → Privacy & Security.
Common causes
- Terminal/IDE lacks Full Disk Access
- Background tool (cron, launchd job) without permission
- Accessing ~/Library/Mail, Safari, Messages data
- SIP-protected system locations (cannot be changed)
⚡ Quick fix
- System Settings → Privacy & Security → Full Disk Access → add the app
- Restart the app after granting
- Avoid writing to SIP-protected paths (/System, /usr except /usr/local)
Detailed fix by platform
Shell
- bash
# check SIP status (protected system paths cannot be modified) csrutil status # reset a privacy permission so macOS asks again tccutil reset All com.apple.Terminal
How to diagnose
- App — Which app/process is running the command?
- Path — Protected folder or SIP path?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026