Skip to content

Commit 1e3d3cf

Browse files
committed
Update mac-jamfpro-policies.md
1 parent 6daccaf commit 1e3d3cf

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

defender-endpoint/mac-jamfpro-policies.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -875,7 +875,7 @@ Follow these steps:
875875

876876
11. If you want users to install Defender for Endpoint voluntarily (or on demand), select **Self-Service**.
877877

878-
:::image type="content" source="media/c9f85bba3e96d627fe00fc5a8363b83a.png" alt-text="The Self Service tab for configuration settings." lightbox="media/c9f85bba3e96d627fe00fc5a8363b83a.png":::
878+
:::image type="content" source="media/c9f85bba3e96d627fe00fc5a8363b83a.png" alt-text="The Self Service tab for configuration settings." lightbox="media/c9f85bba3e96d627fe00fc5a8363b83a.png":::
879879

880880
12. Select **Done**.
881881

@@ -888,13 +888,13 @@ Follow these steps:
888888
Jamf requires you to define a set of machines for a configuration profile. You need to make sure that all machines receiving Defender's package, also receive *all* configuration profiles listed above.
889889

890890
> [!WARNING]
891-
> Jamf supports Smart Computer Groups that allow deploying, such as configuration profiles or policies to all machines matching certain criteria evaluated dynamically.
892-
> It is a powerful concept that is widely used for configuration profiles distribution.
891+
> Jamf supports Smart Computer Groups that allow deploying, such as configuration profiles or policies to all machines matching certain criteria evaluated dynamically. It is a powerful concept that is widely used for configuration profiles distribution.
893892
>
894893
> However, keep in mind that these criteria should not include presence of Defender on a machine.
895894
> While using this criterion may sound logical, it creates problems that are difficult to diagnose.
896895
>
897896
> Defender relies on all these profiles at the moment of its installation.
897+
>
898898
> Making configuration profiles depending on Defender's presence effectively delays deployment of configuration profiles, and results in an initially unhealthy product and/or prompts for manual approval of certain application permissions, that are otherwise auto approved by profiles.Deploying a policy with Microsoft Defender's package *after* deploying configuration profiles ensures the end user's best experience, because all required configurations will be applied before the package installs.
899899
900900
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

0 commit comments

Comments
 (0)