These issues usually come from system security policy, signature validation, installer-directory permissions, or administrator access required by TUN or service components. First verify the installer source and architecture, then follow the original system prompt to grant access. Once the source is trusted, grant only the permission requested by the current prompt. Neither Windows nor macOS requires permanently disabling system protection.
SmartScreen, a macOS security warning, or directory permissions?
Read the system message carefully. Signature validation, read-only directories, and service-component permissions are different problems with different solutions.
- Is Windows blocking the app through SmartScreen or security software?
- Does macOS say the developer cannot be verified?
- Is the client installed in a read-only directory?
- Do TUN, service mode, or startup at login require additional permission?(See TUN device guide)
How to clear the block on Windows and macOS
- Verify the installer source before responding to the system security prompt
- On Windows, install in a standard user directory and, if necessary, launch once as administrator
- On macOS, allow the verified app under Privacy & Security in System Settings(See Security and Privacy FAQ)
- Read the client's permission documentation before enabling TUN or service mode
Do not disable long-term security protections just to bypass a prompt
Grant administrator access only to a trusted client and trusted version
A permission prompt does not indicate whether nodes or subscriptions work
