To improve a computer's security, kernel extensions installed with or after the installation of macOS 10.13 or later require user consent to load. This is known as User Approved Kernel Extension Loading. Any user can approve a kernel extension, even if they do not have administrator privileges.
Kernel extensions do not require authorization if they meet some of the following criteria:
Kernel extensions were on the computer before the upgrade to macOS 10.13 or later.
Kernel extensions are replacing previously approved extensions.
Kernel extensions are allowed to load without user consent by using the
spctlcommand while booted to macOS Recovery.Kernel extensions are installed on a computer enrolled in Mobile Device Management (MDM).
Kernel extensions are allowed to load via MDM configuration. Starting with macOS High Sierra 10.13.2, you can use MDM to specify a list of kernel extensions which will load without user consent. This option requires a computer running macOS 10.13.2 or later which is either enrolled in MDM via Automated Device Enrollment (formerly DEP) or whose MDM enrollment is User Approved.
Before you can safelist kernel extensions, you must find the team identifier and the bundle identifier for each kernel extension you want to safelist.