From f47e779f8389fd66ae729c30f42c5631af455b9c Mon Sep 17 00:00:00 2001 From: martyav Date: Wed, 1 Apr 2020 17:53:21 -0400 Subject: [PATCH 01/28] added first version of summary table to mdatp for macos via intune --- .../mac-install-with-intune.md | 16 +++++++++++++++- .../mac-install-with-jamf.md | 1 + 2 files changed, 16 insertions(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/mac-install-with-intune.md b/windows/security/threat-protection/microsoft-defender-atp/mac-install-with-intune.md index 6a79d9fca6..526162d489 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/mac-install-with-intune.md +++ b/windows/security/threat-protection/microsoft-defender-atp/mac-install-with-intune.md @@ -24,6 +24,7 @@ ms.topic: conceptual - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for Mac](microsoft-defender-atp-mac.md) This topic describes how to deploy Microsoft Defender ATP for Mac through Intune. A successful deployment requires the completion of all of the following steps: + - [Download installation and onboarding packages](#download-installation-and-onboarding-packages) - [Client device setup](#client-device-setup) - [Create System Configuration profiles](#create-system-configuration-profiles) @@ -340,8 +341,21 @@ Solution: Follow the steps above to create a device profile using WindowsDefende ## Logging installation issues -For more information on how to find the automatically generated log that is created by the installer when an error occurs, see [Logging installation issues](mac-resources.md#logging-installation-issues) . +For more information on how to find the automatically generated log that is created by the installer when an error occurs, see [Logging installation issues](mac-resources.md#logging-installation-issues). ## Uninstallation See [Uninstalling](mac-resources.md#uninstalling) for details on how to remove Microsoft Defender ATP for Mac from client devices. + +## Quick summary + +The following table summarizes the steps you would need to take to deploy and manage Microsoft Defender ATP for Macs, via Intune + +| Step(s) | How? | Sample names | References | BundleIdentifier | +|-|-|-|-|-| +| 1. Onboard the 'onboarding package' (WindowsDefenderATPOnboarding.plist) | Using the new Microsoft Edge browser, browse to https://securitycenter.microsoft.com

Settings (gear icon) -> under "Machine Management" -> Onboarding -> macOS -> Mobile Device Management / Microsoft Intune

Click on "Download onboarding package" (WindowsDefenderATPOnboardingPackage.zip)

Rename WindowsDefenderATPOnboardingPackage.zip to

WindowsDefenderATPOnboardingPackage_macOS_MDM_contoso.zip

Extract WindowsDefenderATPOnboardingPackage_macOS_MDM_contoso.zip to e.g.

*C:\Users\JaneDoe_or_JohnDoe.contoso\Downloads\WindowsDefenderATPOnboardingPackage_macOS_MDM_contoso\intune\WindowsDefenderATPOnboarding.xml*

| WindowsDefenderATPOnboarding__MDATP_wdav.atp.xml | Download installation and onboarding [packages](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/mac-install-with-intune#download-installation-and-onboarding-packages) | com.microsoft.wdav.atp | +| 2. Approve Kernel Extension for Microsoft Defender ATP | You have to download it from securitycenter.microsoft.com

Settings (gear icon) -> under "Machine Management" -> Onboarding -> macOS -> Mobile Device Management / Microsoft Intune

Click on "Download onboarding package" (WindowsDefenderATPOnboardingPackage.zip)

Rename WindowsDefenderATPOnboardingPackage.zip to

WindowsDefenderATPOnboardingPackage_macOS_MDM_contoso.zip

Extract WindowsDefenderATPOnboardingPackage_macOS_MDM_contoso.zip

to e.g. *C:\Users\JaneDoe_or_JohnDoe.contoso\Downloads\WindowsDefenderATPOnboardingPackage_macOS_MDM_contoso\intune\kext.xml*

| MDATP_KExt.xml | Download installation and onboarding [packages](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-install-with-intune#download-installation-and-onboarding-packages) | | +| 3. Grant full disk access to Microsoft Defender ATP | | MDATP_tcc_Catalina_or_newer.xml | See Step 8 under [Create system configuration profiles](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-install-with-intune#create-system-configuration-profiles) on this page | com.microsoft.wdav.tcc | +| 4. Configure Microsoft AutoUpdate (MAU) | | MDATP_Microsoft_AutoUpdate.xml | Intune – Set [preferences](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-updates#intune) for Microsoft AutoUpdate | com.microsoft.autoupdate2 | +| 5. Microsoft Defender ATP configuration settings