You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/evaluate-microsoft-defender-antivirus.md
+18-5Lines changed: 18 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -9,7 +9,7 @@ ms.author: ewalsh
9
9
ms.reviewer: yongrhee
10
10
manager: deniseb
11
11
ms.custom: nextgen
12
-
ms.date: 10/18/2018
12
+
ms.date: 01/28/2025
13
13
ms.subservice: ngp
14
14
ms.collection:
15
15
- m365-security
@@ -39,12 +39,12 @@ You can choose to configure and evaluate each setting independently, or all at o
39
39
40
40
The guide is available:
41
41
42
-
-[Evaluate Microsoft Defender Antivirus using PowerShell](microsoft-defender-antivirus-using-powershell.md)
43
-
-in PDF format for offline viewing: [Download the guide in PDF format](https://www.microsoft.com/download/details.aspx?id=54795).
42
+
-[Evaluate Microsoft Defender Antivirus using PowerShell](microsoft-defender-antivirus-using-powershell.md).
43
+
-In PDF format for offline viewing: [Download the guide in PDF format](https://www.microsoft.com/download/details.aspx?id=54795).
44
44
45
45
You can also download a PowerShell that will enable all the settings described in the guide automatically. You can obtain the script alongside the PDF download above, or individually from PowerShell Gallery:
46
46
47
-
-[Download the PowerShell script to automatically configure the settings](https://www.powershellgallery.com/packages/WindowsDefender_InternalEvaluationSettings)
47
+
-[Download the PowerShell script to automatically configure the settings](https://aka.ms/wdeppscript).
48
48
49
49
> [!IMPORTANT]
50
50
> The guide is currently intended for single-machine evaluation of Microsoft Defender Antivirus. Enabling all of the settings in this guide may not be suitable for real-world deployment.
@@ -62,9 +62,22 @@ You can also download a PowerShell that will enable all the settings described i
62
62
> -[Configure Defender for Endpoint on Android features](android-configure.md)
63
63
> -[Configure Microsoft Defender for Endpoint on iOS features](ios-configure-features.md)
64
64
65
-
## Related topics
65
+
## Related articles
66
+
67
+
- Evaluate Microsoft Defender Antivirus using [Microsoft Defender Endpoint Security Settings Management (Endpoint security policies) ](/defender-endpoint/evaluate-mda-using-mde-security-settings-management)
68
+
69
+
- Evaluate Microsoft Defender Antivirus using [Group Policy](/defender-endpoint/evaluate-mdav-using-gp)
70
+
71
+
- Evaluate Microsoft Defender Antivirus using [Powershell](/defender-endpoint/microsoft-defender-antivirus-using-powershell)
72
+
73
+
-[Advanced technologies](/defender-endpoint/adv-tech-of-mdav) at the core of Microsoft Defender Antivirus
74
+
75
+
-[Microsoft Defender Antivirus compatibility with other security products](/defender-endpoint/microsoft-defender-antivirus-compatibility)
76
+
77
+
-[Microsoft Defender Antivirus and non-Microsoft antivirus solutions without Defender for Endpoint](/defender-endpoint/defender-antivirus-compatibility-without-mde)
66
78
67
79
-[Microsoft Defender Antivirus in Windows 10](microsoft-defender-antivirus-windows.md)
80
+
68
81
-[Deploy Microsoft Defender Antivirus](deploy-manage-report-microsoft-defender-antivirus.md)
69
82
70
83
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]
Copy file name to clipboardExpand all lines: defender-endpoint/mac-device-control-jamf.md
+32-16Lines changed: 32 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ ms.collection:
15
15
ms.topic: conceptual
16
16
ms.subservice: macos
17
17
search.appverid: met150
18
-
ms.date: 04/30/2024
18
+
ms.date: 01/31/2025
19
19
---
20
20
21
21
# Deploy and manage Device Control using JAMF
@@ -31,49 +31,65 @@ ms.date: 04/30/2024
31
31
32
32
> Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial.](https://signup.microsoft.com/create-account/signup?products=7f379fee-c4f9-4278-b0a1-e4c8c2fcdf7e&ru=https://aka.ms/MDEp2OpenTrial?ocid=docs-wdatp-exposedapis-abovefoldlink)
33
33
34
-
Microsoft Defender for Endpoint Device Control feature enables you to audit, allow, or prevent the read, write, or execute access to removable storage, and allows you to manage iOS and Portable device and Bluetooth media with or without exclusions.
34
+
Device control in Microsoft Defender for Endpoint on macOS enables you to audit, allow, or prevent the read, write, or execute access to removable storage. Device control also allows you to manage iOS and portable devices and Bluetooth media, with or without exclusions.
35
35
36
36
## Licensing requirements
37
37
38
-
Before you get started with Removable Storage Access Control, you must confirm your [Microsoft 365 subscription](https://www.microsoft.com/microsoft-365/compare-microsoft-365-enterprise-plans?rtc=3). To access and use Removable Storage Access Control, you must have Microsoft 365 E3.
38
+
Before you begin, confirm your subscription. To access and use device control, your subscription must include Defender for Endpoint Plan 1. For more information, see the following resources:
-[Understand subscriptions and licenses in Microsoft 365 for business](/microsoft-365/commerce/licenses/subscriptions-and-licenses)
39
42
40
43
[!INCLUDE [Microsoft Defender for Endpoint third-party tool support](../includes/support.md)]
41
44
42
45
## Deploy policy by using JAMF
43
46
44
-
### Step 1: Create policy JSON
47
+
### Step 1: Creating a JSON policy
48
+
49
+
Device Control on Mac is defined through a JSON policy. This policy should have the appropriate groups, rules, and settings defined to tailor specific customer conditions. For example, some enterprise organizations might need to block all removable media devices entirely, while others might have specific exceptions for a vendor or serial number. Microsoft has a [local GitHub repository](https://github.com/microsoft/mdatp-devicecontrol/tree/main/macOS/policy/samples"https://github.com/microsoft/mdatp-devicecontrol/tree/main/macos/policy/samples") that you can use to build your policies.
50
+
51
+
For more information about settings, rules, and groups, see [Device Control for macOS](mac-device-control-overview.md).
52
+
53
+
### Step 2: Validating a JSON policy
45
54
46
-
Now, you have 'groups' and 'rules' and 'settings', combine 'settings' and 'groups' and rules into one JSON, here's the demo file: [https://github.com/microsoft/mdatp-devicecontrol/blob/main/macOS/policy/samples/deny_removable_media_except_kingston.json](https://github.com/microsoft/mdatp-devicecontrol/blob/main/macOS/policy/samples/deny_removable_media_except_kingston.json). Make sure to validate your policy with the JSON schema so your policy format is correct: [https://github.com/microsoft/mdatp-devicecontrol/blob/main/macOS/policy/device_control_policy_schema.json](https://github.com/microsoft/mdatp-devicecontrol/blob/main/macOS/policy/device_control_policy_schema.json).
55
+
You must validate your JSON policy after it's created to ensure there are no syntax or configuration errors. A schema for device control policies is available in [our GitHub repository](https://github.com/microsoft/mdatp-devicecontrol/blob/main/macOS/policy/device_control_policy_schema.json"https://github.com/microsoft/mdatp-devicecontrol/blob/main/macos/policy/device_control_policy_schema.json"). The Defender for Endpoint application has built-in functionality to compare your JSON to the defined schema.
47
56
48
-
See [Device Control for macOS](mac-device-control-overview.md) for information about settings, rules, and groups.
57
+
1. Save your configuration on a local device as a `.json` file.
49
58
50
-
### Step 2: Update MDE Preferences Schema
59
+
2. Ensure you have access to `mdatp` commands. If your device is already onboarded, then you should have this functionality.
51
60
52
-
The [MDE Preferences schema](https://github.com/microsoft/mdatp-xplat/blob/master/macos/schema/schema.json) is updated to include the new `deviceControl/policy` key. The existing MDE Preferences configuration profile should be updated to use the new schema file's content.
61
+
3. Run `mdatp device-control policy validate --path <pathtojson>`.
62
+
63
+
### Step 3: Update your Defender for Endpoint preferences Schema
64
+
65
+
The [Defender for Endpoint preferences schema](https://github.com/microsoft/mdatp-xplat/blob/master/macos/schema/schema.json) includes the new `deviceControl/policy` key. The existing Defender for Endpoint preferences configuration profile should be updated to use the new schema file's content.
53
66
54
67
:::image type="content" source="media/macos-device-control-jamf-mde-preferences-schema.png" alt-text="Shows where to edit the Microsoft Defender for Endpoint Preferences Schema to update." lightbox="media/macos-device-control-jamf-mde-preferences-schema.png":::
55
68
56
-
### Step 3: Add Device Control Policy to MDE Preferences
69
+
### Step 4: Add the device control policy to Defender for Endpoint preferences
57
70
58
-
A new 'Device Control' property is now available to add to the UX.
71
+
A new device control property is now available to add to the user experience.
59
72
60
-
1.Select the topmost **Add/Remove properties** button, then select **Device Control** and press**Apply**.
73
+
1.In your Jamf console, select **Add/Remove properties**, select **Device Control**, and then select**Apply**.
61
74
62
-
:::image type="content" source="media/macos-device-control-jamf-device-control-property.png" alt-text="Shows how to add Device Control in Microsoft Defender for Endpoint" lightbox="media/macos-device-control-jamf-device-control-property.png":::
75
+
:::image type="content" source="media/macos-device-control-jamf-device-control-property.png" alt-text="Shows how to add Device Control in Microsoft Defender for Endpoint" lightbox="media/macos-device-control-jamf-device-control-property.png":::
63
76
64
-
2.Next, scroll down until you see the **Device Control** property (it's the bottommost entry), and select **Add/Remove properties** directly underneath it.
77
+
2.Scroll down until you see the **Device Control** property (it's at the bottom of the list), and then select **Add/Remove properties**.
65
78
66
79
3. Select **Device Control Policy**, and then select **Apply**.
67
80
68
-
:::image type="content" source="media/macos-device-control-jamf-device-control-add-remove-property.png" alt-text="Shows how to apply Device Control Policy in Microsoft Defender for Endpoint." lightbox="media/macos-device-control-jamf-device-control-add-remove-property.png":::
81
+
:::image type="content" source="media/macos-device-control-jamf-device-control-add-remove-property.png" alt-text="Shows how to apply Device Control Policy in Microsoft Defender for Endpoint." lightbox="media/macos-device-control-jamf-device-control-add-remove-property.png":::
69
82
70
-
4.To finish, copy and paste the Device Control policy JSON into the text box, and save your changes to the configuration profile.
83
+
4.Copy and paste your device control policy JSON into the text box.
71
84
72
-
:::image type="content" source="media/macos-device-control-jamf-device-control-policy-json.png" alt-text="Shows where to add the Device Control policy JSON in Microsoft Defender for Endpoint." lightbox="media/macos-device-control-jamf-device-control-policy-json.png":::
85
+
:::image type="content" source="media/macos-device-control-jamf-device-control-policy-json.png" alt-text="Shows where to add the Device Control policy JSON in Microsoft Defender for Endpoint." lightbox="media/macos-device-control-jamf-device-control-policy-json.png":::
86
+
87
+
5. Save your changes.
73
88
74
89
## See also
75
90
76
91
-[Device Control for macOS](mac-device-control-overview.md)
77
92
-[Deploy and manage Device Control using Intune](mac-device-control-intune.md)
78
93
-[macOS Device Control frequently asked questions (FAQ)](mac-device-control-faq.md)
94
+
79
95
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]
0 commit comments