mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-16 02:43:43 +00:00
Update mac-jamfpro-policies.md
To fix suggestions
This commit is contained in:
@ -80,7 +80,7 @@ You'll need to take the following steps:
|
||||
|
||||
2. In the Jamf Pro dashboard, select **New**.
|
||||
|
||||

|
||||

|
||||
|
||||
3. Enter the following details:
|
||||
|
||||
@ -97,9 +97,9 @@ You'll need to take the following steps:
|
||||
|
||||
5. Select **Upload File (PLIST file)** then in **Preference Domain** enter: `com.microsoft.wdav.atp`.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
7. Select **Open** and select the onboarding file.
|
||||
|
||||
@ -118,17 +118,17 @@ You'll need to take the following steps:
|
||||
|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
11. Select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||
|
||||
12. Select **Done**.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||
|
||||
@ -268,7 +268,7 @@ You'll need to take the following steps:
|
||||
|
||||
3. In the Jamf Pro dashboard, select **General**.
|
||||
|
||||

|
||||

|
||||
|
||||
4. Enter the following details:
|
||||
|
||||
@ -280,33 +280,33 @@ You'll need to take the following steps:
|
||||
- Distribution Method: Install Automatically(default)
|
||||
- Level: Computer Level(default)
|
||||
|
||||

|
||||

|
||||
|
||||
5. In **Application & Custom Settings** select **Configure**.
|
||||
|
||||

|
||||

|
||||
|
||||
6. Select **Upload File (PLIST file)**.
|
||||
|
||||

|
||||

|
||||
|
||||
7. In **Preferences Domain**, enter `com.microsoft.wdav`, then select **Upload PLIST File**.
|
||||
|
||||

|
||||

|
||||
|
||||
8. Select **Choose File**.
|
||||
|
||||

|
||||

|
||||
|
||||
9. Select the **MDATP_MDAV_configuration_settings.plist**, then select **Open**.
|
||||
|
||||

|
||||

|
||||
|
||||
10. Select **Upload**.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
>[!NOTE]
|
||||
>If you happen to upload the Intune file, you'll get the following error:<br>
|
||||
@ -315,29 +315,29 @@ You'll need to take the following steps:
|
||||
|
||||
11. Select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||
12. The file is uploaded.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
13. Select the **Scope** tab.
|
||||
|
||||

|
||||

|
||||
|
||||
14. Select **Contoso's Machine Group**.
|
||||
|
||||
15. Select **Add**, then select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
16. Select **Done**. You'll see the new **Configuration profile**.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## Step 4: Configure notifications settings
|
||||
@ -360,45 +360,45 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
- Distribution Method: Install Automatically(default)
|
||||
- Level: Computer Level(default)
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
5. Select **Upload File (PLIST file)**.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
6. Select **Choose File** > **MDATP_MDAV_Notification_Settings.plist**.
|
||||
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||

|
||||

|
||||
|
||||
7. Select **Open** > **Upload**.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||

|
||||

|
||||
|
||||
8. Select the **Scope** tab, then select **Add**.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
9. Select **Contoso's Machine Group**.
|
||||
|
||||
10. Select **Add**, then select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||

|
||||
|
||||
11. Select **Done**. You'll see the new **Configuration profile**.
|
||||

|
||||

|
||||
|
||||
## Step 5: Configure Microsoft AutoUpdate (MAU)
|
||||
|
||||
@ -427,7 +427,7 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
|
||||
3. In the Jamf Pro dashboard, select **General**.
|
||||
|
||||

|
||||

|
||||
|
||||
4. Enter the following details:
|
||||
|
||||
@ -441,54 +441,54 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
|
||||
5. In **Application & Custom Settings** select **Configure**.
|
||||
|
||||

|
||||

|
||||
|
||||
6. Select **Upload File (PLIST file)**.
|
||||
|
||||

|
||||

|
||||
|
||||
7. In **Preference Domain** enter: `com.microsoft.autoupdate2`, then select **Upload PLIST File**.
|
||||
|
||||

|
||||

|
||||
|
||||
8. Select **Choose File**.
|
||||
|
||||

|
||||

|
||||
|
||||
9. Select **MDATP_MDAV_MAU_settings.plist**.
|
||||
|
||||

|
||||

|
||||
|
||||
10. Select **Upload**.
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
11. Select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||
12. Select the **Scope** tab.
|
||||
|
||||

|
||||

|
||||
|
||||
13. Select **Add**.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
14. Select **Done**.
|
||||
|
||||

|
||||

|
||||
|
||||
## Step 6: Grant full disk access to Microsoft Defender for Endpoint
|
||||
|
||||
1. In the Jamf Pro dashboard, select **Configuration Profiles**.
|
||||
|
||||

|
||||

|
||||
|
||||
2. Select **+ New**.
|
||||
|
||||
@ -502,11 +502,11 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
- Level: Computer level
|
||||
|
||||
|
||||

|
||||

|
||||
|
||||
4. In **Configure Privacy Preferences Policy Control** select **Configure**.
|
||||
|
||||

|
||||

|
||||
|
||||
5. In **Privacy Preferences Policy Control**, enter the following details:
|
||||
|
||||
@ -515,11 +515,11 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
- Code Requirement: `identifier "com.microsoft.wdav" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = UBF8T346G9`
|
||||
|
||||
|
||||

|
||||

|
||||
|
||||
6. Select **+ Add**.
|
||||
|
||||

|
||||

|
||||
|
||||
- Under App or service: Set to **SystemPolicyAllFiles**
|
||||
|
||||
@ -527,11 +527,11 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
|
||||
7. Select **Save** (not the one at the bottom right).
|
||||
|
||||

|
||||

|
||||
|
||||
8. Click the `+` sign next to **App Access** to add a new entry.
|
||||
|
||||

|
||||

|
||||
|
||||
9. Enter the following details:
|
||||
|
||||
@ -541,7 +541,7 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
|
||||
10. Select **+ Add**.
|
||||
|
||||

|
||||

|
||||
|
||||
- Under App or service: Set to **SystemPolicyAllFiles**
|
||||
|
||||
@ -549,19 +549,19 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
|
||||
11. Select **Save** (not the one at the bottom right).
|
||||
|
||||

|
||||

|
||||
|
||||
12. Select the **Scope** tab.
|
||||
|
||||

|
||||

|
||||
|
||||
13. Select **+ Add**.
|
||||
|
||||

|
||||

|
||||
|
||||
14. Select **Computer Groups** > under **Group Name** > select **Contoso's MachineGroup**.
|
||||
|
||||

|
||||

|
||||
|
||||
15. Select **Add**.
|
||||
|
||||
@ -569,9 +569,9 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
|
||||
17. Select **Done**.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## Step 7: Approve Kernel extension for Microsoft Defender for Endpoint
|
||||
@ -590,11 +590,11 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
- Distribution Method: Install Automatically
|
||||
- Level: Computer Level
|
||||
|
||||

|
||||

|
||||
|
||||
3. In **Configure Approved Kernel Extensions** select **Configure**.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
4. In **Approved Kernel Extensions** Enter the following details:
|
||||
@ -602,11 +602,11 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
- Display Name: Microsoft Corp.
|
||||
- Team ID: UBF8T346G9
|
||||
|
||||

|
||||

|
||||
|
||||
5. Select the **Scope** tab.
|
||||
|
||||

|
||||

|
||||
|
||||
6. Select **+ Add**.
|
||||
|
||||
@ -614,15 +614,15 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
|
||||
8. Select **+ Add**.
|
||||
|
||||

|
||||

|
||||
|
||||
9. Select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||
10. Select **Done**.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## Step 8: Approve System extensions for Microsoft Defender for Endpoint
|
||||
@ -641,11 +641,11 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
- Distribution Method: Install Automatically
|
||||
- Level: Computer Level
|
||||
|
||||

|
||||

|
||||
|
||||
3. In **System Extensions** select **Configure**.
|
||||
|
||||

|
||||

|
||||
|
||||
4. In **System Extensions** enter the following details:
|
||||
|
||||
@ -656,11 +656,11 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
- **com.microsoft.wdav.epsext**
|
||||
- **com.microsoft.wdav.netext**
|
||||
|
||||

|
||||

|
||||
|
||||
5. Select the **Scope** tab.
|
||||
|
||||

|
||||

|
||||
|
||||
6. Select **+ Add**.
|
||||
|
||||
@ -668,15 +668,15 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||
|
||||
8. Select **+ Add**.
|
||||
|
||||

|
||||

|
||||
|
||||
9. Select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||
10. Select **Done**.
|
||||
|
||||

|
||||

|
||||
|
||||
## Step 9: Configure Network Extension
|
||||
|
||||
@ -704,19 +704,19 @@ As part of the Endpoint Detection and Response capabilities, Microsoft Defender
|
||||
|
||||
5. Select **Choose File** and select `microsoft.network-extension.signed.mobileconfig`.
|
||||
|
||||

|
||||

|
||||
|
||||
6. Select **Upload**.
|
||||
|
||||

|
||||

|
||||
|
||||
7. After uploading the file, you are redirected to a new page to finalize the creation of this profile.
|
||||
|
||||

|
||||

|
||||
|
||||
8. Select the **Scope** tab.
|
||||
|
||||

|
||||

|
||||
|
||||
9. Select **+ Add**.
|
||||
|
||||
@ -724,15 +724,15 @@ As part of the Endpoint Detection and Response capabilities, Microsoft Defender
|
||||
|
||||
11. Select **+ Add**.
|
||||
|
||||

|
||||

|
||||
|
||||
12. Select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||
13. Select **Done**.
|
||||
|
||||

|
||||

|
||||
|
||||
## Step 10: Schedule scans with Microsoft Defender for Endpoint for Mac
|
||||
Follow the instructions on [Schedule scans with Microsoft Defender for Endpoint for Mac](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/mac-schedule-scan-atp).
|
||||
@ -741,22 +741,22 @@ Follow the instructions on [Schedule scans with Microsoft Defender for Endpoint
|
||||
|
||||
1. Navigate to where you saved `wdav.pkg`.
|
||||
|
||||

|
||||

|
||||
|
||||
2. Rename it to `wdav_MDM_Contoso_200329.pkg`.
|
||||
|
||||

|
||||

|
||||
|
||||
3. Open the Jamf Pro dashboard.
|
||||
|
||||

|
||||

|
||||
|
||||
4. Select your computer and click the gear icon at the top, then select **Computer Management**.
|
||||
|
||||

|
||||

|
||||
|
||||
5. In **Packages**, select **+ New**.
|
||||

|
||||

|
||||
|
||||
6. In **New Package** Enter the following details:
|
||||
|
||||
@ -765,7 +765,7 @@ Follow the instructions on [Schedule scans with Microsoft Defender for Endpoint
|
||||
- Category: None (default)
|
||||
- Filename: Choose File
|
||||
|
||||

|
||||

|
||||
|
||||
Open the file and point it to `wdav.pkg` or `wdav_MDM_Contoso_200329.pkg`.
|
||||
|
||||
@ -779,75 +779,75 @@ Follow the instructions on [Schedule scans with Microsoft Defender for Endpoint
|
||||
|
||||
**Limitations tab**<br> Keep default values.
|
||||
|
||||

|
||||

|
||||
|
||||
8. Select **Save**. The package is uploaded to Jamf Pro.
|
||||
|
||||

|
||||

|
||||
|
||||
It can take a few minutes for the package to be available for deployment.
|
||||
|
||||

|
||||

|
||||
|
||||
9. Navigate to the **Policies** page.
|
||||
|
||||

|
||||

|
||||
|
||||
10. Select **+ New** to create a new policy.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
11. In **General** Enter the following details:
|
||||
|
||||
- Display name: MDATP Onboarding Contoso 200329 v100.86.92 or later
|
||||
|
||||

|
||||

|
||||
|
||||
12. Select **Recurring Check-in**.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
13. Select **Save**.
|
||||
|
||||
14. Select **Packages > Configure**.
|
||||
|
||||

|
||||

|
||||
|
||||
15. Select the **Add** button next to **Microsoft Defender Advanced Threat Protection and Microsoft Defender Antivirus**.
|
||||
|
||||

|
||||

|
||||
|
||||
16. Select **Save**.
|
||||
|
||||

|
||||

|
||||
|
||||
17. Select the **Scope** tab.
|
||||
|
||||

|
||||

|
||||
|
||||
18. Select the target computers.
|
||||
|
||||

|
||||

|
||||
|
||||
**Scope**
|
||||
|
||||
Select **Add**.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
**Self-Service**
|
||||
|
||||

|
||||

|
||||
|
||||
19. Select **Done**.
|
||||
|
||||

|
||||

|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
|
||||
|
Reference in New Issue
Block a user