Join our Newsletter — 33% off our NHI Course

Standalone Variant

The standalone variant is the default macOS package for installing Tailscale outside the Mac App Store. It is designed to balance security and usability for most users by using modern system extension based VPN support. In practice, it is the recommended starting point unless device management or deployment constraints require another option.

What the standalone variant is for

The standalone variant is the default macOS package for installing Tailscale outside the Mac App Store. It is the usual starting point for individual users and many small teams because it balances security, usability, and straightforward deployment without extra management constraints.

Its main practical value is that it uses modern system extension based VPN support rather than older extension models, which aligns better with current macOS security expectations and reduces friction during install and use. That makes it the general-purpose choice when you want the standard desktop experience rather than a managed distribution path.

For readers comparing package types, the key question is not whether the standalone build is “more secure” in the abstract, but whether it fits the device management model. If the answer is yes, it is usually the simplest option to deploy and operate.

How it differs from managed or store-based options

The standalone variant differs mainly in packaging and administration rather than in the core service it connects to. The choice is about how Tailscale is installed, updated, and governed on macOS, not about changing the network overlay itself.

In practice, a standalone install is better suited to devices that are not bound to a strict enterprise deployment workflow. If the environment depends on App Store distribution, endpoint management policies, or a tightly controlled software catalog, another package may be a better fit.

The technical trade-off is familiar in endpoint software: a broadly usable default gives most users the fewest steps, while managed variants usually exist to satisfy policy, deployment, or fleet-control requirements. That is why the standalone package is the default, but not the only legitimate path.

Security and operational implications

The security significance of the standalone variant is mostly about the trust boundary between the application, the operating system, and the way VPN functionality is exposed to the user. A system extension based design is generally preferable to older approaches because it works within the platform’s current security model.

That said, a convenient default still needs normal endpoint discipline. The installation channel, update hygiene, and device posture matter because the package becomes part of the host’s trusted software set. For general identity and access context, NHIs outnumber human identities by 25x to 50x in modern enterprises, which is one reason control choices around software distribution and endpoint trust keep expanding in importance, especially when systems also handle machine or service access patterns.

Where the subject touches broader access governance, the same operational lesson applies: choose the package that matches how the device is controlled, not just how it is used. A “default” installer can still be the wrong choice if it bypasses required management, auditing, or deployment workflows.

When to choose it, and when not to

Choose the standalone variant when you want the standard macOS experience, do not need App Store distribution, and are not constrained by device management requirements. It is the sensible default for most individual installs and many lightweight deployments.

Do not choose it simply because it is the default if your environment requires centralized software rollout, policy enforcement, or a controlled installation channel. In those cases, the better option is the one that fits the fleet, not the one that is easiest for a single user.

Practitioner note: The right package choice is usually a governance decision as much as a technical one, because install path, update control, and endpoint policy often matter more than the client’s visible features.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS 4 — Secure Configuration of Enterprise Assets and Software Standalone package choice affects approved software deployment and endpoint configuration.
Recommendation — Use CIS 4 to standardize the approved macOS install path and keep endpoint software consistent.
NIST CSF 2.0 PR.AC — Access Control The package supports secure access to the VPN client through device and software trust boundaries.
GV.PO — Policy Package selection is driven by deployment and device-management policy constraints.
PR.IP — Information Protection Processes and Procedures Install and update handling are part of the operating procedure for the client package.
Recommendation — Apply PR.AC controls to ensure the chosen macOS package aligns with device access policy. Define policy for when the standalone variant is permitted versus when managed deployment is required. Document installation and update procedures for the selected macOS distribution channel.