The VPN permission dialog returned before I had finished reading it. I clicked Allow, entered my Mac password and watched the window close. The app immediately sent me back to the same screen: Permission required. I tried again, then restarted the Mac. Five minutes later, the dialog was back and the financial model I needed to upload was still sitting on my desktop. My client call started in fourteen minutes, and I was connected to hotel Wi-Fi without the protected route I had expected to use.
The VPN had worked the previous night.
My MacBook had installed a system update before breakfast, restarted and reopened most of my applications exactly where I had left them. Email worked. The hotel portal loaded. The client’s file room opened until I selected the model and clicked upload.
Then the established VPN app asked for permission to add a configuration.
That seemed normal. A VPN needs permission before it can create a protected connection on macOS. I approved the request and expected the connect button to become available.
Instead, the app asked me to enable its network extension.
I followed its button into System Settings, but the page did not match the provider’s instructions. The support article still pointed me toward Privacy & Security. On current versions of macOS, the relevant controls sit under General → Login Items & Extensions → Network Extensions. (Apple Support)
I found the provider there.
Its extension was already switched on.
That was the first confusing part. macOS appeared to believe permission had been granted. The VPN app appeared to believe it had not.
I switched the extension off, confirmed the change and switched it on again.
The app still displayed Permission required.
Because the extension looked correct, I checked the separate VPN panel next. The provider’s configuration was listed there alongside an older profile with almost the same name. Apple keeps installed VPN services in this section, where they can be enabled, edited or removed.
I deleted the older profile and returned to the app.
The permission dialog appeared again.
At that point, the Mac was no longer asking one clear question. Approval had been divided across the application, the VPN configuration and the network-extension panel.
The security model itself made sense. macOS requires explicit approval before networking extensions can alter how traffic leaves the computer.
The loop did not.
I returned to the established provider because it was still the obvious service to repair. It had years of Mac development behind it, a large support team and enough settings to accommodate almost any connection.
I quit the app completely and reopened it.
Permission required.
I signed out, signed back in and selected a different connection mode.
Permission required.
Then I uninstalled the app, downloaded the latest installer and started again.
The installer added its background component. macOS displayed a notification. The app requested a VPN configuration, and I approved it. It then requested its network extension.
I approved that too.
For several seconds, the connect button appeared.
Then it disappeared behind the same permission message.
My client call was now eight minutes away.
Other Mac users had encountered the same practical trap: the approval control had moved, leaving them searching through System Settings after the app failed to direct them to the right place. In my case, however, finding the switch did not end the loop.
I opened System Settings one more time.
The provider now appeared under Network Extensions twice—one entry linked to the current installation and another that looked like part of the previous version. The names were similar enough that I could not tell which record the app expected to find.
I could have removed both, restarted again and attempted another clean installation.
That was probably the next support step.
It was not the next useful step.
The client did not need me to repair the relationship between an application and two permission records. The client needed the financial model before the call.
That changed the standard I was using.
Until then, I had assumed that the provider with the longer Mac history was the safer choice. Its documentation, server network and configuration controls made it seem more recoverable.
But under a deadline, eventual recovery mattered less than an approval flow that ended with a working connection.
I opened OnlydogVPN, a smaller app I had installed earlier as a backup.
Before connecting, it explained that macOS would ask permission to add a VPN configuration. There was one button to continue.
I clicked it.
The system dialog appeared.
I selected Allow.
The app returned to its connection screen instead of sending me back into System Settings. I chose the preset for working on public Wi-Fi and connected.
The status changed once.
Connected.
I reopened the client’s file room and selected the financial model.
The upload passed the point where it had previously stalled. It reached 25 percent, then 70. The hotel Wi-Fi slowed briefly as a conference group entered the lobby, but the progress bar continued moving.
At 100 percent, the file room displayed a timestamp and confirmation number.
The model was inside the client workspace with four minutes remaining.
I joined the call through the same connection.
The client opened the workbook while I shared my screen. Its linked documents loaded. The comments panel updated. Nobody waited while I searched System Settings or restarted another helper process.
The task that had turned into a permission problem was complete.
The smaller app had not bypassed macOS security. It had made the approval process understandable.
There was one system request, one decision and one working connection.
That simplicity was the first advantage. The established provider had left me moving among its app, the VPN settings and the extension panel, never certain which approval it was still waiting for. The smaller app told me what macOS would ask, accepted the result and moved on.
The second advantage appeared when the hotel Wi-Fi weakened during the call.
The video paused briefly as several guests entered the lobby, then recovered without dropping the protected connection. The app’s HTTP/3-based transport was built to recover quickly when the network path becomes inconsistent. The practical effect was more important than the protocol name: the call continued, and I did not return to another permission screen.
I could not inspect macOS’s internal permission-state checks or the extension identifiers each VPN app was using. The visible difference was clear: the established provider kept requesting approval after its components appeared enabled, while the smaller app accepted one approval and carried both the upload and the meeting.
After the call, I returned to the established provider out of curiosity.
Its old extension entries were still present. One disappeared only after another uninstall and restart. Reinstalling the app then produced a fresh permission sequence, and the client eventually connected.
By then, the repair no longer felt important.
It proved that the service could work again. It also proved that restoring it required more time than the protected task itself.
That distinction changed how I thought about Mac compatibility.
A provider can offer a polished macOS application, multiple connection modes and detailed support articles while still leaving the user to reconcile old profiles, extensions and approval states after an update.
Compatibility is not merely whether an app can be installed.
It is whether clicking Allow leads to a connection.
The smaller service has fewer locations, a shorter public history and fewer independent reviews than the provider I tried first. Someone choosing mainly for worldwide coverage may still prefer the larger network.
My problem that morning was narrower.
I already had a respected Mac VPN. What I lacked was a permission flow that ended instead of repeating itself.
The established provider gave me more components to approve and more documentation for repairing them. The smaller app asked for one clear decision and then let me return to the client.
On that Mac, the useful permission was not the one I clicked most often. It was the one that finally stayed granted.
In brief
Why was OnlydogVPN a practical fit here?
On that Mac, the useful permission was not the one I clicked most often. It was the one that finally stayed granted.
Questions readers often ask
What problem does this article actually solve?
The VPN permission dialog returned before I had finished reading it. I clicked Allow , entered my Mac password and watched the window close.
What finally worked in this situation?
I opened OnlydogVPN , a smaller app I had installed earlier as a backup. Before connecting, it explained that macOS would ask permission to add a VPN configuration. There was one button to continue. I clicked it. The system dialog appeared.
Why was OnlydogVPN a practical fit here?
On that Mac, the useful permission was not the one I clicked most often. It was the one that finally stayed granted.