Skip to content

Commit d52f4ab

Browse files
Merge pull request #1324 from beflamm/docs-editor/mac-install-with-intune-1726076927
Update system extensions guidance
2 parents cbe6892 + 335e86d commit d52f4ab

File tree

3 files changed

+31
-39
lines changed

3 files changed

+31
-39
lines changed

defender-endpoint/mac-install-with-intune.md

Lines changed: 31 additions & 39 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.collection:
1414
ms.topic: conceptual
1515
ms.subservice: macos
1616
search.appverid: met150
17-
ms.date: 08/21/2024
17+
ms.date: 09/12/2024
1818
---
1919

2020
# Deploy Microsoft Defender for Endpoint on macOS with Microsoft Intune
@@ -63,34 +63,40 @@ In the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2
6363

6464
1. Under **Configuration profiles**, select **Create Profile**.
6565

66-
This profile is needed for Big Sur (11) or later. It's ignored on older versions of macOS, because they use the kernel extension.
67-
6866
1. On the **Policies** tab, select **Create** > **New Policy**.
6967

7068
1. Under **Platform**, select **macOS**.
7169

72-
1. Under **Profile type**, select **Templates**.
73-
74-
1. Under **Template name**, select **Extensions**.
70+
1. Under **Profile type**, select **Settings catalog**.
7571

7672
1. Select **Create**.
7773

78-
1. On the **Basics** tab, **Name** the profile. For example, `SysExt-prod-macOS-Default-MDE`.
74+
1. On the **Basics** tab, **Name** the profile and enter a **Description.**
7975

8076
1. Select **Next**.
8177

82-
1. On the **Configuration settings** tab, expand **System Extensions** and add the following entries in the **Allowed system extensions** section:
78+
1. On the **Configuration settings tab,** select **+Add settings.**
8379

84-
|Bundle identifier|Team identifier|
85-
|---|---|
86-
|`com.microsoft.wdav.epsext`|`UBF8T346G9`|
87-
|`com.microsoft.wdav.netext`|`UBF8T346G9`|
80+
1. Under **Template name**, select **Extensions**.
81+
82+
1. In the **Settings picker**, expand the **System Configuration** category, and then select **System Extensions** > **Allowed System Extensions:**
83+
84+
![Screenshot showing the Settings Picker](media/mac-install-with-intune/screenshot-2024-09-11-at-1.41.09 pm.png)
85+
86+
1. Close the Settings picker, and then select **+ Edit instance**.
87+
88+
1. Configure the following entries in the **Allowed system extensions** section:
89+
90+
|Allowed System Extensions|Team Identifier|
91+
|---|---|
92+
|`com.microsoft.wdav.epsext`|`UBF8T346G9`|
93+
|`com.microsoft.wdav.netext`|`UBF8T346G9`|
94+
95+
![Screenshot showing allowed system extensions](media/mac-install-with-intune/image003.png)
8896

89-
:::image type="content" source="../defender-endpoint/media/mac-system-extension-intune2.png" alt-text="Screenshot that shows the settings of the system's extension." lightbox="../defender-endpoint/media/mac-system-extension-intune2.png":::
90-
9197
1. Select **Next**.
9298

93-
1. On the **Assignments** tab, assign the profile to a group where the macOS devices and/or users are located, or **All Users** and **All devices**.
99+
1. On the **Assignments** tab, assign the profile to a group where the macOS devices or users are located.
94100

95101
1. Review the configuration profile. Select **Create**.
96102

@@ -572,27 +578,13 @@ See [Uninstalling](mac-resources.md#uninstalling) for details on how to remove M
572578

573579
## Recommended content
574580

575-
[Add Microsoft Defender for Endpoint to macOS devices using Microsoft Intune](/mem/intune/apps/apps-advanced-threat-protection-macos?source=recommendations)
576-
577-
Learn about adding Microsoft Defender for Endpoint to macOS devices using Microsoft Intune.
578-
579-
[Examples of device control policies for Intune](mac-device-control-intune.md)
580-
<br>Learn how to use device control policies using examples that can be used with Intune.
581-
582-
[Configure Microsoft Defender for Endpoint on iOS features](ios-configure-features.md)
583-
<br>Describes how to deploy Microsoft Defender for Endpoint on iOS features.
584-
585-
[Deploy Microsoft Defender for Endpoint on iOS with Microsoft Intune](ios-install.md)
586-
<br>Describes how to deploy Microsoft Defender for Endpoint on iOS using an app.
587-
588-
[Configure Microsoft Defender for Endpoint in Microsoft Intune](/mem/intune/protect/advanced-threat-protection-configure?source=recommendations)
589-
<br>Describes connecting to Defender for Endpoint, onboarding devices, assigning compliance for risk levels, and conditional access policies.
590-
591-
[Troubleshoot issues and find answers on FAQs related to Microsoft Defender for Endpoint on iOS](ios-troubleshoot.md)
592-
<br>Troubleshooting and FAQ - Microsoft Defender for Endpoint on iOS.
593-
594-
[Configure Microsoft Defender for Endpoint on Android features](android-configure.md)
595-
<br>Describes how to configure Microsoft Defender for Endpoint on Android.
596-
597-
[Manage Defender for Endpoint on Android devices in Intune - Azure](/mem/intune/protect/advanced-threat-protection-manage-android?source=recommendations)
598-
<br>Configure Microsoft Defender for Endpoint web protection on Android devices managed by Microsoft Intune.
581+
|Article | Description |
582+
|---|---|
583+
| [Add Microsoft Defender for Endpoint to macOS devices using Microsoft Intune](/mem/intune/apps/apps-advanced-threat-protection-macos?source=recommendations) | Learn about adding Microsoft Defender for Endpoint to macOS devices using Microsoft Intune |
584+
| [Examples of device control policies for Intune](mac-device-control-intune.md) | Learn how to use device control policies using examples that can be used with Intune |
585+
| [Configure Microsoft Defender for Endpoint on iOS features](ios-configure-features.md) | Describes how to deploy Microsoft Defender for Endpoint on iOS features |
586+
| [Deploy Microsoft Defender for Endpoint on iOS with Microsoft Intune](ios-install.md) | Describes how to deploy Microsoft Defender for Endpoint on iOS using an app |
587+
| [Configure Microsoft Defender for Endpoint in Microsoft Intune](/mem/intune/protect/advanced-threat-protection-configure?source=recommendations) | Describes connecting to Defender for Endpoint, onboarding devices, assigning compliance for risk levels, and conditional access policies |
588+
| [Troubleshoot issues and find answers on FAQs related to Microsoft Defender for Endpoint on iOS](ios-troubleshoot.md) | Troubleshooting and FAQ - Microsoft Defender for Endpoint on iOS |
589+
| [Configure Microsoft Defender for Endpoint on Android features](android-configure.md) | Describes how to configure Microsoft Defender for Endpoint on Android |
590+
| [Manage Defender for Endpoint on Android devices in Intune - Azure](/mem/intune/protect/advanced-threat-protection-manage-android?source=recommendations) | Configure Microsoft Defender for Endpoint web protection on Android devices managed by Microsoft Intune |
394 KB
Loading
218 KB
Loading

0 commit comments

Comments
 (0)