You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
1. Copy the file to your preferred location. For example, `C:\Users\JaneDoe_or_JohnDoe.contoso\Downloads\WindowsDefenderATPOnboardingPackage_macOS_MDM_contoso\JamF\WindowsDefenderATPOnboarding.plist`.
47
+
1. Copy the file to your preferred location. For example, `C:\Users\JaneDoe_or_JohnDoe.contoso\Downloads\WindowsDefenderATPOnboardingPackage_macOS_MDM_contoso\Jamf\WindowsDefenderATPOnboarding.plist`.
48
48
49
-
## Step 2: Create a configuration profile in JamF Pro using the onboarding package
49
+
## Step 2: Create a configuration profile in Jamf Pro using the onboarding package
50
50
51
51
1. Locate the file `WindowsDefenderATPOnboarding.plist` from the previous section.
52
52
53
53
:::image type="content" source="media/plist-onboarding-file.png" alt-text="The Windows Defender ATP Onboarding file." lightbox="media/plist-onboarding-file.png":::
54
54
55
-
1. Sign in to JamF Pro, navigate to **Computers** > **Configuration Profiles**, and select **New**.
55
+
1. Sign in to Jamf Pro, navigate to **Computers** > **Configuration Profiles**, and select **New**.
56
56
57
57
:::image type="content" source="media/jamf-pro-configure-profile.png" alt-text="The page on which you create a new Jamf Pro dashboard." lightbox="media/jamf-pro-configure-profile.png":::
58
58
@@ -106,10 +106,10 @@ Use this article to set up policies for Defender for Endpoint on Mac using Jamf
106
106
107
107
## Step 3: Configure Microsoft Defender for Endpoint settings
108
108
109
-
In this step, we go over *Preferences* so you can configure anti-malware and EDR policies using Microsoft Defender XDR portal ([https://security.microsoft.com](https://security.microsoft.com)) or JamF.
109
+
In this step, we go over *Preferences* so you can configure anti-malware and EDR policies using Microsoft Defender XDR portal ([https://security.microsoft.com](https://security.microsoft.com)) or Jamf.
110
110
111
111
> [!IMPORTANT]
112
-
> Microsoft Defender for Endpoint Security Settings Management policies take precedence over JamF set (and other 3rd party MDM) policies.
112
+
> Microsoft Defender for Endpoint Security Settings Management policies take precedence over Jamf set (and other 3rd party MDM) policies.
113
113
114
114
### 3a. Set policies using Microsoft Defender portal
115
115
@@ -131,9 +131,9 @@ For more information about managing security settings, see the following article
131
131
132
132
-[Manage security settings for Windows, macOS, and Linux natively in Defender for Endpoint](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/manage-security-settings-for-windows-macos-and-linux-natively-in/ba-p/3870617)
133
133
134
-
### 3b. Set policies using JamF
134
+
### 3b. Set policies using Jamf
135
135
136
-
You can either use JamF Pro GUI to edit individual settings of the Microsoft Defender for Endpoint configuration, or use the legacy method by creating a configuration Plist in a text editor, and uploading it to JamF Pro.
136
+
You can either use Jamf Pro GUI to edit individual settings of the Microsoft Defender for Endpoint configuration, or use the legacy method by creating a configuration Plist in a text editor, and uploading it to Jamf Pro.
137
137
138
138
Note that you must use exact `com.microsoft.wdav` as the **Preference Domain**; Microsoft Defender for Endpoint uses only this name and `com.microsoft.wdav.ext` to load its managed settings.
139
139
@@ -219,7 +219,7 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
219
219
- `tags`
220
220
- `hideStatusMenuIcon`
221
221
222
-
For information, see [Property list for JamF full configuration profile](mac-preferences.md#property-list-for-jamf-full-configuration-profile).
222
+
For information, see [Property list for Jamf full configuration profile](mac-preferences.md#property-list-for-jamf-full-configuration-profile).
223
223
224
224
```XML
225
225
<?xml version="1.0" encoding="UTF-8"?>
@@ -324,7 +324,7 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
324
324
325
325
2. Save the file as `MDATP_MDAV_configuration_settings.plist`.
326
326
327
-
1. In the JamF Pro dashboard, open **Computers**, and their **Configuration Profiles**. Select **New** and switch to the **General** tab.
327
+
1. In the Jamf Pro dashboard, open **Computers**, and their **Configuration Profiles**. Select **New** and switch to the **General** tab.
328
328
329
329
:::image type="content" source="media/644e0f3af40c29e80ca1443535b2fe32.png" alt-text="The page displaying a new profile." lightbox="media/644e0f3af40c29e80ca1443535b2fe32.png":::
330
330
@@ -398,8 +398,8 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
398
398
## Step 4: Configure notifications settings
399
399
400
400
> [!NOTE]
401
-
> These steps are applicable on macOS 11 (Big Sur) or later. Even though JamF supports notifications on macOS version 10.15 or later, Defender for Endpoint on Mac requires macOS 11 or later.
402
-
1. In the JamF Pro dashboard, select **Computers**, then **Configuration Profiles**.
401
+
> These steps are applicable on macOS 11 (Big Sur) or later. Even though Jamf supports notifications on macOS version 10.15 or later, Defender for Endpoint on Mac requires macOS 11 or later.
402
+
1. In the Jamf Pro dashboard, select **Computers**, then **Configuration Profiles**.
403
403
404
404
2. Select **New**, and then, on the **General** tab, for **Options**, specify the following details:
405
405
@@ -471,7 +471,7 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
@@ -528,7 +528,7 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
528
528
529
529
## Step 6: Grant full disk access to Microsoft Defender for Endpoint
530
530
531
-
1. In the JamF Pro dashboard, select**Configuration Profiles**.
531
+
1. In the Jamf Pro dashboard, select**Configuration Profiles**.
532
532
533
533
:::image type="content" source="media/264493cd01e62c7085659d6fdc26dc91.png" alt-text="The profile for which settings are to be configured." lightbox="media/264493cd01e62c7085659d6fdc26dc91.png":::
534
534
@@ -611,7 +611,7 @@ Microsoft Defender for Endpoint adds new settings over time. These new settings
Alternatively, you can download [fulldisk.mobileconfig](https://github.com/microsoft/mdatp-xplat/blob/master/macos/mobileconfig/profiles/fulldisk.mobileconfig) and upload it to JamF Configuration Profiles as described in [Deploying Custom Configuration Profiles using Jamf Pro|Method 2: Upload a Configuration Profile to JamF Pro](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro).
614
+
Alternatively, you can download [fulldisk.mobileconfig](https://github.com/microsoft/mdatp-xplat/blob/master/macos/mobileconfig/profiles/fulldisk.mobileconfig) and upload it to Jamf Configuration Profiles as described in [Deploying Custom Configuration Profiles using Jamf Pro|Method 2: Upload a Configuration Profile to Jamf Pro](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro).
615
615
616
616
> [!NOTE]
617
617
> Full Disk Access granted through Apple MDM Configuration Profile is not reflected in System Settings => Privacy & Security => Full Disk Access.
@@ -672,8 +672,8 @@ Alternatively, you can download [fulldisk.mobileconfig](https://github.com/micro
672
672
As part of the Endpoint Detection and Response capabilities, Microsoft Defender for Endpoint on macOS inspects socket traffic and reports this information to the Microsoft Defender portal.
673
673
674
674
> [!NOTE]
675
-
> These steps are applicable on macOS 11 (Big Sur) or later. Even though JamF supports notifications on macOS version 10.15 or later, Defender for Endpoint on Mac requires macOS 11 or later.
676
-
1. In the JamF Pro dashboard, select**Computers**,then**Configuration Profiles**.
675
+
> These steps are applicable on macOS 11 (Big Sur) or later. Even though Jamf supports notifications on macOS version 10.15 or later, Defender for Endpoint on Mac requires macOS 11 or later.
676
+
1. In the Jamf Pro dashboard, select**Computers**,then**Configuration Profiles**.
677
677
678
678
2. Select **New**, and enter the following details for**Options**:
679
679
@@ -717,16 +717,16 @@ As part of the Endpoint Detection and Response capabilities, Microsoft Defender
Alternatively, you can download [netfilter.mobileconfig](https://github.com/microsoft/mdatp-xplat/blob/master/macos/mobileconfig/profiles/netfilter.mobileconfig) and upload it to JamF Configuration Profiles as described in [Deploying Custom Configuration Profiles using JamF Pro|](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro)
720
+
Alternatively, you can download [netfilter.mobileconfig](https://github.com/microsoft/mdatp-xplat/blob/master/macos/mobileconfig/profiles/netfilter.mobileconfig) and upload it to Jamf Configuration Profiles as described in [Deploying Custom Configuration Profiles using Jamf Pro|](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro)
721
721
722
722
## Step 9: Configure Background Services
723
723
724
724
> [!CAUTION]
725
725
> macOS 13 (Ventura) contains new privacy enhancements. Beginning with this version, by default, applications cannot run in background without explicit consent. Microsoft Defender forEndpoint must run its daemon processin background.
726
-
>> This configuration profile grants Background Service permissions to Microsoft Defender for Endpoint. If you previously configured Microsoft Defender for Endpoint through JamF, we recommend you update the deployment with this configuration profile.
726
+
>> This configuration profile grants Background Service permissions to Microsoft Defender for Endpoint. If you previously configured Microsoft Defender for Endpoint through Jamf, we recommend you update the deployment with this configuration profile.
727
727
Download [**background_services.mobileconfig**](https://raw.githubusercontent.com/microsoft/mdatp-xplat/master/macos/mobileconfig/profiles/background_services.mobileconfig) from [our GitHub repository](https://github.com/microsoft/mdatp-xplat/tree/master/macos/mobileconfig/profiles).
728
728
729
-
Upload downloaded mobileconfig to JamF Configuration Profiles as described in [Deploying Custom Configuration Profiles using JamF Pro|Method 2: Upload a Configuration Profile to JamF Pro](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro).
729
+
Upload downloaded mobileconfig to Jamf Configuration Profiles as described in [Deploying Custom Configuration Profiles using Jamf Pro|Method 2: Upload a Configuration Profile to Jamf Pro](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro).
730
730
731
731
## Step 10: Grant Bluetooth Permissions
732
732
@@ -736,8 +736,8 @@ Upload downloaded mobileconfig to JamF Configuration Profiles as described in [D
736
736
Download [bluetooth.mobileconfig](https://github.com/microsoft/mdatp-xplat/blob/master/macos/mobileconfig/profiles/bluetooth.mobileconfig) from [GitHub repository](https://github.com/microsoft/mdatp-xplat/tree/master/macos/mobileconfig/profiles).
737
737
738
738
> [!WARNING]
739
-
> Current version of JamF Pro does not support this kind of payload yet. If you upload this mobileconfig as-is, JamF Pro will remove unsupported payload,
740
-
> and it will fail to apply to client machines. You need to sign downloaded mobileconfig first, after that JamF Pro will consider it "sealed" and will not
739
+
> Current version of Jamf Pro does not support this kind of payload yet. If you upload this mobileconfig as-is, Jamf Pro will remove unsupported payload,
740
+
> and it will fail to apply to client machines. You need to sign downloaded mobileconfig first, after that Jamf Pro will consider it "sealed" and will not
741
741
> tamper with it. See instructions below:
742
742
- You need to have at least one signing certificate installed into your KeyChain, even a self-signed certificate works. You can inspect what you have with:
- Now you can upload the generated bluetooth-signed.mobileconfig to JamF Pro as described in [Deploying Custom Configuration Profiles using JamF Pro|Method 2: Upload a Configuration Profile to JamF Pro](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro).
760
+
- Now you can upload the generated bluetooth-signed.mobileconfig to Jamf Pro as described in [Deploying Custom Configuration Profiles using Jamf Pro|Method 2: Upload a Configuration Profile to Jamf Pro](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro).
761
761
762
762
> [!NOTE]
763
763
> Bluetooth granted through Apple MDM Configuration Profile is not reflected in System Settings => Privacy & Security => Bluetooth.
@@ -781,9 +781,9 @@ Follow the instructions on [Schedule scans with Microsoft Defender for Endpoint
:::image type="content" source="media/990742cd9a15ca9fdd37c9f695d1b9f4.png" alt-text="The configuration settings for jamfpro." lightbox="media/990742cd9a15ca9fdd37c9f695d1b9f4.png":::
786
+
:::image type="content" source="media/990742cd9a15ca9fdd37c9f695d1b9f4.png" alt-text="The configuration settings for Jamf pro." lightbox="media/990742cd9a15ca9fdd37c9f695d1b9f4.png":::
787
787
788
788
4. Select your computer and selectthe gear icon at the top, and thenselect**Computer Management**.
789
789
@@ -813,7 +813,7 @@ Follow the instructions on [Schedule scans with Microsoft Defender for Endpoint
813
813
814
814
:::image type="content" source="media/56dac54634d13b2d3948ab50e8d3ef21.png" alt-text="The limitation tab for the configuration settings." lightbox="media/56dac54634d13b2d3948ab50e8d3ef21.png":::
815
815
816
-
1. Select **Save**. The package is uploaded to JamF Pro.
816
+
1. Select **Save**. The package is uploaded to Jamf Pro.
817
817
818
818
:::image type="content" source="media/33f1ecdc7d4872555418bbc3efe4b7a3.png" alt-text="The configuration settings pack uploading process for the package related to the configuration settings." lightbox="media/33f1ecdc7d4872555418bbc3efe4b7a3.png":::
819
819
@@ -855,7 +855,7 @@ Follow the instructions on [Schedule scans with Microsoft Defender for Endpoint
855
855
856
856
For a better user experience, configuration profiles to enrolled machines must be installed before Microsoft Defender's package. In most cases JamF Pro pushes configuration profiles immediately, and those policies are executed after some time (that is, during check-in). However, in some cases, configuration profiles deployment can be deployed with a significant delay (that is, if a user's machine is locked).
857
857
858
-
JamF Pro provides a way to ensure the correct order. You can create a smart group for machines that already received Microsoft Defender's configuration profile, and install Microsoft Defender's package only to those machines (and as soon as they receive this profile).
858
+
Jamf Pro provides a way to ensure the correct order. You can create a smart group for machines that already received Microsoft Defender's configuration profile, and install Microsoft Defender's package only to those machines (and as soon as they receive this profile).
859
859
860
860
Follow these steps:
861
861
@@ -901,10 +901,10 @@ Follow the instructions on [Schedule scans with Microsoft Defender for Endpoint
901
901
902
902
## Configuration profile scope
903
903
904
-
JamF requires you to define a set of machines for a configuration profile. You need to make sure that all machines receiving Defender's package, also receive *all* configuration profiles listed above.
904
+
Jamf requires you to define a set of machines for a configuration profile. You need to make sure that all machines receiving Defender's package, also receive *all* configuration profiles listed above.
905
905
906
906
> [!WARNING]
907
-
>JAMF supports Smart Computer Groups that allow deploying, such as configuration profiles or policies to all machines matching certain criteria evaluated dynamically.
907
+
>Jamf supports Smart Computer Groups that allow deploying, such as configuration profiles or policies to all machines matching certain criteria evaluated dynamically.
908
908
> It is a powerful concept that is widely used for configuration profiles distribution.
909
909
>
910
910
> However, keep in mind that these criteria should not include presence of Defender on a machine.
0 commit comments