Skip to content

Commit 17e08c4

Browse files
committed
Update mac-jamfpro-policies.md
1 parent 732291b commit 17e08c4

File tree

1 file changed

+37
-38
lines changed

1 file changed

+37
-38
lines changed

defender-endpoint/mac-jamfpro-policies.md

Lines changed: 37 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -398,38 +398,39 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
398398

399399
:::image type="content" source="media/c9820a5ff84aaf21635c04a23a97ca93.png" alt-text="The new macOS configuration profile page." lightbox="media/c9820a5ff84aaf21635c04a23a97ca93.png":::
400400

401-
- On the **Notifications** tab, select **Add**, and specify the following values:
402-
- **Bundle ID**: `com.microsoft.wdav.tray`
403-
- **Critical Alerts**: Select **Disable**
404-
- **Notifications**: Select **Enable**
405-
- **Banner alert type**: Select **Include** and **Temporary** *(default)*
406-
- **Notifications on lock screen**: Select **Hide**
407-
- **Notifications in Notification Center**: Select **Display**
408-
- **Badge app icon**: Select **Display**
401+
3. On the **Notifications** tab, select **Add**, and specify the following values:
409402

410-
:::image type="content" source="media/7f9138053dbcbf928e5182ee7b295ebe.png" alt-text="The configuration settings mdatpmdav notifications tray." lightbox="media/7f9138053dbcbf928e5182ee7b295ebe.png":::
403+
- **Bundle ID**: `com.microsoft.wdav.tray`
404+
- **Critical Alerts**: Select **Disable**
405+
- **Notifications**: Select **Enable**
406+
- **Banner alert type**: Select **Include** and **Temporary** *(default)*
407+
- **Notifications on lock screen**: Select **Hide**
408+
- **Notifications in Notification Center**: Select **Display**
409+
- **Badge app icon**: Select **Display**
411410

412-
- On the **Notifications** tab, select **Add** one more time, and then scroll down to **New Notifications Settings**
413-
- **Bundle ID**: `com.microsoft.autoupdate.fba`
414-
- Configure the rest of the settings to the same values mentioned earlier
411+
:::image type="content" source="media/7f9138053dbcbf928e5182ee7b295ebe.png" alt-text="The configuration settings mdatpmdav notifications tray." lightbox="media/7f9138053dbcbf928e5182ee7b295ebe.png":::
415412

416-
:::image type="content" source="media/4bac6ce277aedfb4a674f2d9fcb2599a.png" alt-text="The configuration settings mdatpmdav notifications mau." lightbox="media/4bac6ce277aedfb4a674f2d9fcb2599a.png":::
413+
4. On the **Notifications** tab, select **Add** one more time, and then scroll down to **New Notifications Settings**.
417414

418-
Note that now you have two tables with notification configurations, one for **Bundle ID: com.microsoft.wdav.tray**, and another for **Bundle ID: com.microsoft.autoupdate.fba**. While you can configure alert settings per your requirements, Bundle IDs must be exactly the same as described before, and **Include** switch must be **On** for **Notifications**.
415+
- **Bundle ID**: `com.microsoft.autoupdate.fba`
419416

420-
3. Select the **Scope** tab, and then select **Add**.
417+
5. Configure the rest of the settings to the same values mentioned earlier
421418

422-
:::image type="content" source="media/441aa2ecd36abadcdd8aed03556080b5.png" alt-text="The page on which you can add values for the configuration settings." lightbox="media/441aa2ecd36abadcdd8aed03556080b5.png":::
419+
:::image type="content" source="media/4bac6ce277aedfb4a674f2d9fcb2599a.png" alt-text="The configuration settings mdatpmdav notifications mau." lightbox="media/4bac6ce277aedfb4a674f2d9fcb2599a.png":::
420+
421+
Note that now you have two tables with notification configurations, one for **Bundle ID: com.microsoft.wdav.tray**, and another for **Bundle ID: com.microsoft.autoupdate.fba**. While you can configure alert settings per your requirements, Bundle IDs must be exactly the same as described before, and **Include** switch must be **On** for **Notifications**.
422+
423+
6. Select the **Scope** tab, and then select **Add**.
423424

424-
4. Select **Contoso's Machine Group**.
425+
:::image type="content" source="media/441aa2ecd36abadcdd8aed03556080b5.png" alt-text="The page on which you can add values for the configuration settings." lightbox="media/441aa2ecd36abadcdd8aed03556080b5.png":::
425426

426-
5. Select **Add**, and then select **Save**.
427+
7. Select **Contoso's Machine Group**. Select **Add**, and then select **Save**.
427428

428429
:::image type="content" source="media/09a275e321268e5e3ac0c0865d3e2db5.png" alt-text="The page on which you can save values for the configuration settings contoso machine group." lightbox="media/09a275e321268e5e3ac0c0865d3e2db5.png":::
429430

430431
:::image type="content" source="media/4d2d1d4ee13d3f840f425924c3df0d51.png" alt-text="The page that displays the completion notification of the configuration settings." lightbox="media/4d2d1d4ee13d3f840f425924c3df0d51.png":::
431432

432-
6. Select **Done**. You should see the new **Configuration profile**.
433+
8. Select **Done**. You should see the new **Configuration profile**.
433434

434435
:::image type="content" source="media/633ad26b8bf24ec683c98b2feb884bdf.png" alt-text="The completed configuration settings." lightbox="media/633ad26b8bf24ec683c98b2feb884bdf.png":::
435436

@@ -458,7 +459,7 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
458459

459460
2. Save it as `MDATP_MDAV_MAU_settings.plist`.
460461

461-
1. In the Jamf Pro dashboard, select **General**.
462+
3. In the Jamf Pro dashboard, select **General**.
462463

463464
:::image type="content" source="media/eaba2a23dd34f73bf59e826217ba6f15.png" alt-text="The configuration settings." lightbox="media/eaba2a23dd34f73bf59e826217ba6f15.png":::
464465

@@ -538,18 +539,18 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
538539

539540
5. In **Privacy Preferences Policy Control**, enter the following details:
540541

541-
- **Identifier**: `com.microsoft.wdav`
542-
- **Identifier Type**: `Bundle ID`
543-
- **Code Requirement**: `identifier "com.microsoft.wdav" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = UBF8T346G9`
542+
- **Identifier**: `com.microsoft.wdav`
543+
- **Identifier Type**: `Bundle ID`
544+
- **Code Requirement**: `identifier "com.microsoft.wdav" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = UBF8T346G9`
544545

545546
:::image type="content" source="media/22cb439de958101c0a12f3038f905b27.png" alt-text="The configuration setting privacy preference policy control details." lightbox="media/22cb439de958101c0a12f3038f905b27.png":::
546547

547548
6. Select **+ Add**.
548549

549550
:::image type="content" source="media/bd93e78b74c2660a0541af4690dd9485.png" alt-text="The configuration setting add system policy all files option." lightbox="media/bd93e78b74c2660a0541af4690dd9485.png":::
550551

551-
- Under **App or service**, select **SystemPolicyAllFiles**.
552-
- Under **access**, select **Allow**.
552+
- Under **App or service**, select **SystemPolicyAllFiles**.
553+
- Under **access**, select **Allow**.
553554

554555
7. Select **Save** (not the one at the bottom right).
555556

@@ -561,38 +562,36 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
561562

562563
9. Enter the following details:
563564

564-
- **Identifier**: `com.microsoft.wdav.epsext`
565-
- **Identifier Type**: `Bundle ID`
566-
- **Code Requirement**: `identifier "com.microsoft.wdav.epsext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = UBF8T346G9`
565+
- **Identifier**: `com.microsoft.wdav.epsext`
566+
- **Identifier Type**: `Bundle ID`
567+
- **Code Requirement**: `identifier "com.microsoft.wdav.epsext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = UBF8T346G9`
567568

568569
10. Select **+ Add**.
569570

570571
:::image type="content" source="media/tcc-epsext-entry.png" alt-text="The configuration setting tcc epsext entry." lightbox="media/tcc-epsext-entry.png":::
571572

572-
- Under **App or service**, select **SystemPolicyAllFiles**.
573-
- Under **access**, select **Allow**.
573+
- Under **App or service**, select **SystemPolicyAllFiles**.
574+
- Under **access**, select **Allow**.
574575

575576
11. Select **Save** (not the one at the bottom right).
576577

577-
:::image type="content" source="media/tcc-epsext-entry2.png" alt-text="The other instance of configuration setting tcc epsext." lightbox="media/tcc-epsext-entry2.png":::
578+
:::image type="content" source="media/tcc-epsext-entry2.png" alt-text="The other instance of configuration setting tcc epsext." lightbox="media/tcc-epsext-entry2.png":::
578579

579580
12. Select the **Scope** tab.
580581

581-
:::image type="content" source="media/2c49b16cd112729b3719724f581e6882.png" alt-text="The page depicting the scope for the configuration setting." lightbox="media/2c49b16cd112729b3719724f581e6882.png":::
582+
:::image type="content" source="media/2c49b16cd112729b3719724f581e6882.png" alt-text="The page depicting the scope for the configuration setting." lightbox="media/2c49b16cd112729b3719724f581e6882.png":::
582583

583584
13. Select **+ Add**.
584585

585-
:::image type="content" source="media/57cef926d1b9260fb74a5f460cee887a.png" alt-text="The page depicting the configuration setting." lightbox="media/57cef926d1b9260fb74a5f460cee887a.png":::
586+
:::image type="content" source="media/57cef926d1b9260fb74a5f460cee887a.png" alt-text="The page depicting the configuration setting." lightbox="media/57cef926d1b9260fb74a5f460cee887a.png":::
586587

587588
14. Select **Computer Groups**, and under **Group Name**, select **Contoso's MachineGroup**.
588589

589-
:::image type="content" source="media/368d35b3d6179af92ffdbfd93b226b69.png" alt-text="The configuration setting contoso machine group." lightbox="media/368d35b3d6179af92ffdbfd93b226b69.png":::
590-
591-
15. Select **Add**.
590+
:::image type="content" source="media/368d35b3d6179af92ffdbfd93b226b69.png" alt-text="The configuration setting contoso machine group." lightbox="media/368d35b3d6179af92ffdbfd93b226b69.png":::
592591

593-
16. Select **Save**.
592+
15. Select **Add**. Then select **Save**.
594593

595-
17. Select **Done**.
594+
16. Select **Done**.
596595

597596
:::image type="content" source="media/809cef630281b64b8f07f20913b0039b.png" alt-text="The configuration setting contoso machine-group." lightbox="media/809cef630281b64b8f07f20913b0039b.png":::
598597

0 commit comments

Comments
 (0)