Skip to content

Commit 31b0ca6

Browse files
committed
Update mac-jamfpro-policies.md
1 parent 17e08c4 commit 31b0ca6

File tree

1 file changed

+27
-27
lines changed

1 file changed

+27
-27
lines changed

defender-endpoint/mac-jamfpro-policies.md

Lines changed: 27 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -610,13 +610,13 @@ Alternatively, you can download [fulldisk.mobileconfig](https://github.com/micro
610610

611611
2. On the **General** tab, specify the following details:
612612

613-
- **Name**: `MDATP MDAV System Extensions`
614-
- **Description**: `MDATP system extensions`
615-
- **Category**: `None`
616-
- **Distribution Method**: `Install Automatically`
617-
- **Level**: `Computer Level`
613+
- **Name**: `MDATP MDAV System Extensions`
614+
- **Description**: `MDATP system extensions`
615+
- **Category**: `None`
616+
- **Distribution Method**: `Install Automatically`
617+
- **Level**: `Computer Level`
618618

619-
:::image type="content" source="media/sysext-new-profile.png" alt-text="The configuration settings sysext new profile." lightbox="media/sysext-new-profile.png":::
619+
:::image type="content" source="media/sysext-new-profile.png" alt-text="The configuration settings sysext new profile." lightbox="media/sysext-new-profile.png":::
620620

621621
3. In **System Extensions** select **Configure**.
622622

@@ -659,39 +659,38 @@ As part of the Endpoint Detection and Response capabilities, Microsoft Defender
659659

660660
> [!NOTE]
661661
> These steps are applicable on macOS 11 (Big Sur) or later. Even though Jamf supports notifications on macOS version 10.15 or later, Defender for Endpoint on Mac requires macOS 11 or later.
662+
662663
1. In the Jamf Pro dashboard, select **Computers**, then **Configuration Profiles**.
663664

664665
2. Select **New**, and enter the following details for **Options**:
665666

666-
- On the **General** tab, specify the following values:
667-
- **Name**: `Microsoft Defender Network Extension`
668-
- **Description**: `macOS 11 (Big Sur) or later`
669-
- **Category**: `None *(default)*`
670-
- **Distribution Method**: `Install Automatically *(default)*`
671-
- **Level**: `Computer Level *(default)*`
667+
3. On the **General** tab, specify the following values:
672668

673-
- On the **Content Filter** tab, specify the following values:
674-
- **Filter Name**: `Microsoft Defender Content Filter`
675-
- **Identifier**: `com.microsoft.wdav`
676-
- Leave **Service Address**, **Organization**, **User Name**, **Password**, **Certificate** blank (**Include** is *not* selected)
677-
- **Filter Order**: `Inspector`
678-
- **Socket Filter**: `com.microsoft.wdav.netext`
679-
- **Socket Filter Designated Requirement**: `identifier "com.microsoft.wdav.netext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = UBF8T346G9`
680-
- Leave **Network Filter** fields blank (**Include** is *not* selected)
669+
- **Name**: `Microsoft Defender Network Extension`
670+
- **Description**: `macOS 11 (Big Sur) or later`
671+
- **Category**: `None *(default)*`
672+
- **Distribution Method**: `Install Automatically *(default)*`
673+
- **Level**: `Computer Level *(default)*`
681674

682-
Note that **Identifier**, **Socket Filter** and **Socket Filter Designated Requirement** exact values as specified above.
675+
4. On the **Content Filter** tab, specify the following values:
683676

684-
:::image type="content" source="media/netext-create-profile.png" alt-text="The mdatpmdav configuration setting." lightbox="media/netext-create-profile.png":::
677+
- **Filter Name**: `Microsoft Defender Content Filter`
678+
- **Identifier**: `com.microsoft.wdav`
679+
- Leave **Service Address**, **Organization**, **User Name**, **Password**, **Certificate** blank (**Include** is *not* selected)
680+
- **Filter Order**: `Inspector`
681+
- **Socket Filter**: `com.microsoft.wdav.netext`
682+
- **Socket Filter Designated Requirement**: `identifier "com.microsoft.wdav.netext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = UBF8T346G9`
683+
- Leave **Network Filter** fields blank (**Include** is *not* selected)
685684

686-
3. Select the **Scope** tab.
685+
Note that **Identifier**, **Socket Filter** and **Socket Filter Designated Requirement** exact values as specified above.
687686

688-
:::image type="content" source="media/0df36fc308ba569db204ee32db3fb40a.png" alt-text="The configuration settings sco tab." lightbox="media/0df36fc308ba569db204ee32db3fb40a.png":::
687+
:::image type="content" source="media/netext-create-profile.png" alt-text="The mdatpmdav configuration setting." lightbox="media/netext-create-profile.png":::
689688

690-
4. Select **+ Add**.
689+
5. Select the **Scope** tab.
691690

692-
5. Select **Computer Groups** > under **Group Name** > select **Contoso's Machine Group**.
691+
:::image type="content" source="media/0df36fc308ba569db204ee32db3fb40a.png" alt-text="The configuration settings sco tab." lightbox="media/0df36fc308ba569db204ee32db3fb40a.png":::
693692

694-
6. Select **+ Add**.
693+
6. Select **+ Add**. Select **Computer Groups**, and then under **Group Name**, select **Contoso's Machine Group**. Then select **+ Add**.
695694

696695
:::image type="content" source="media/0dde8a4c41110dbc398c485433a81359.png" alt-text="The configuration settings adim." lightbox="media/0dde8a4c41110dbc398c485433a81359.png":::
697696

@@ -710,6 +709,7 @@ Alternatively, you can download [netfilter.mobileconfig](https://github.com/micr
710709
> [!CAUTION]
711710
> macOS 13 (Ventura) contains new privacy enhancements. Beginning with this version, by default, applications cannot run in background without explicit consent. Microsoft Defender for Endpoint must run its daemon process in background.
712711
> > This configuration profile grants Background Service permissions to Microsoft Defender for Endpoint. If you previously configured Microsoft Defender for Endpoint through Jamf, we recommend you update the deployment with this configuration profile.
712+
713713
Download [**background_services.mobileconfig**](https://raw.githubusercontent.com/microsoft/mdatp-xplat/master/macos/mobileconfig/profiles/background_services.mobileconfig) from [our GitHub repository](https://github.com/microsoft/mdatp-xplat/tree/master/macos/mobileconfig/profiles).
714714

715715
Upload downloaded mobileconfig to Jamf Configuration Profiles as described in [Deploying Custom Configuration Profiles using Jamf Pro|Method 2: Upload a Configuration Profile to Jamf Pro](https://www.jamf.com/jamf-nation/articles/648/deploying-custom-configuration-profiles-using-jamf-pro).

0 commit comments

Comments
 (0)