mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-19 08:47:22 +00:00
step four five six
This commit is contained in:
parent
010e0788ea
commit
35f77ab7ec
@ -1,7 +1,7 @@
|
||||
---
|
||||
title: Setup the Microsoft Defender ATP for macOS policies in Jamf Pro
|
||||
description: Learn how to setup the Microsoft Defender ATP for macOS policies in Jamf Pro
|
||||
keywords: microsoft, defender, atp, mac, installation, deploy, uninstallation, intune, jamfpro, macos, catalina, mojave, high sierra
|
||||
keywords: policies, microsoft, defender, atp, mac, installation, deploy, uninstallation, intune, jamfpro, macos, catalina, mojave, high sierra
|
||||
search.product: eADQiWindows 10XVcnh
|
||||
search.appverid: met150
|
||||
ms.prod: w10
|
||||
@ -428,8 +428,181 @@ These steps are applicable of macOS 10.15 (Catalina) or newer.
|
||||

|
||||
|
||||
9. Select **Done**. You'll see the new **Configuration profile**.
|
||||

|
||||

|
||||
|
||||
## Step 4: Configure Microsoft AutoUPdate (MAU)
|
||||
|
||||
|
||||
1. In the Jamf Pro dashboard, select **General**.
|
||||
|
||||

|
||||
|
||||
|
||||
- Name: MDATP MDAV MAU settings
|
||||
- Description: Microsoft AutoUpdate settings for MDATP for macOS
|
||||
- Category: None (default)
|
||||
- Distribution Method: Install Automatically(default)
|
||||
- Level: Computer Level(default)
|
||||
|
||||
2. In **Application & Custom Settings** select **Configure**.
|
||||
|
||||

|
||||
|
||||
3. Select **Upload File (PLIST file)**.
|
||||
|
||||

|
||||
|
||||
4. In **Preference Domain** enter: `com.microsoft.autoupdate2`.
|
||||
|
||||

|
||||
|
||||
5. Select **Upload PLIST File**.
|
||||
|
||||

|
||||
|
||||
6. Select **Choose File** > **MDATP_MDAV_settings.plist**.
|
||||
|
||||

|
||||
|
||||
7. Select **Upload**.
|
||||

|
||||
|
||||

|
||||
|
||||
8. Select **Save**.
|
||||
|
||||

|
||||
|
||||
9. Select the **Scope** tab.
|
||||
|
||||

|
||||
|
||||
10. Select **Add**.
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
11. Select **Done**.
|
||||
|
||||

|
||||
|
||||
## Step 5: Grant full disk access to Microsoft Defender ATP
|
||||
|
||||
1. In the Jamf Pro dashboard, select the **Scope** tab.
|
||||
|
||||

|
||||
|
||||
2. Select **+ New**.
|
||||
|
||||
3. Enter the following details:
|
||||
|
||||
- Name: MDATP MDAV - grnat Full Disk Access to EDR and AV
|
||||
- Description: On macOS Catalina or newer, the new Privacy Preferences Policy Control
|
||||
- Category: None
|
||||
- Distribution method: Install Automatically
|
||||
- Level: Computer level
|
||||
|
||||
|
||||

|
||||
|
||||
4. In **Application & Custom Settings** select **Configure**.
|
||||
|
||||

|
||||
|
||||
5. In **Privacy Preferences Policy Control**, enter the following details:
|
||||
|
||||
- Identifier: `com.microsoft.wdav`
|
||||
- Identifier Type: Bundle ID
|
||||
- Code Requirement: identifier `com.microsoft.wdav` and anchor apple generic and
|
||||
certificate 1[field.1.2.840.113635.100.6.2.6] /\* exists \*/ and certificate
|
||||
leaf[field.1.2.840.113635.100.6.1.13] /\* exists \*/ and certificate
|
||||
leaf[subject.OU] = UBF8T346G9
|
||||
|
||||
|
||||

|
||||
|
||||
6. Select **+ Add**.
|
||||
|
||||

|
||||
|
||||
|
||||
- Under App or service: Set to **SystemPolicyAllFiles**
|
||||
|
||||
- Under "access": Set to **Allow**
|
||||
|
||||
7. Select **Save** (not the one at the bottom right).
|
||||
|
||||

|
||||
|
||||
8. Select the **Scope** tab.
|
||||
|
||||

|
||||
|
||||
9. Select **+ Add**.
|
||||
|
||||

|
||||
|
||||
10. Select **Computer Groups** > under **Group Name** > select **Contoso's MachineGroup**.
|
||||
|
||||

|
||||
|
||||
11. Select **Add**.
|
||||
|
||||
12. Select **Save**.
|
||||
|
||||
13. Select **Done**.
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
|
||||
## Step 6: Approve Kernel extension for Microsoft Defender ATP
|
||||
|
||||
1. In the **Configuration Profiles**, select **+ New**.
|
||||
|
||||

|
||||
|
||||
2. Enter the following values:
|
||||
|
||||
- Name: MDATP MDAV Kernel Extension
|
||||
- Description: MDATP kernel extension (kext)
|
||||
- Category: None
|
||||
- Distribution Method: Install Automatically
|
||||
- Level: Computer Level
|
||||
|
||||

|
||||
|
||||
3. In **Configure Approved Kernel Extensions** select **Configure**.
|
||||
|
||||

|
||||
|
||||

|
||||
|
||||
4. In **Approved Kernel Extensions** enter the following values:
|
||||
|
||||
- Display Name: Microsoft Corp.
|
||||
- Team ID: UBF8T346G9
|
||||
|
||||
5. Select the **Scope** tab.
|
||||
|
||||

|
||||
|
||||
6. Select **+ Add**.
|
||||
|
||||
7. Select **Computer Groups** > under **Group Name** > select **Contoso's Machine Group**.
|
||||
|
||||
8. Select **+ Add**.
|
||||
|
||||

|
||||
|
||||
Select on “Save”
|
||||
|
||||

|
||||
|
||||
Select on “Done”
|
||||
|
||||

|
||||
|
Loading…
x
Reference in New Issue
Block a user