Adding images and topic updates for MD for macOS
After Width: | Height: | Size: 11 KiB |
After Width: | Height: | Size: 63 KiB |
After Width: | Height: | Size: 25 KiB |
After Width: | Height: | Size: 42 KiB |
After Width: | Height: | Size: 170 KiB |
After Width: | Height: | Size: 46 KiB |
After Width: | Height: | Size: 64 KiB |
After Width: | Height: | Size: 43 KiB |
After Width: | Height: | Size: 20 KiB |
After Width: | Height: | Size: 29 KiB |
After Width: | Height: | Size: 70 KiB |
After Width: | Height: | Size: 35 KiB |
After Width: | Height: | Size: 85 KiB |
After Width: | Height: | Size: 86 KiB |
After Width: | Height: | Size: 5.2 KiB |
After Width: | Height: | Size: 18 KiB |
After Width: | Height: | Size: 80 KiB |
After Width: | Height: | Size: 22 KiB |
After Width: | Height: | Size: 25 KiB |
After Width: | Height: | Size: 177 KiB |
After Width: | Height: | Size: 36 KiB |
After Width: | Height: | Size: 55 KiB |
After Width: | Height: | Size: 415 KiB |
After Width: | Height: | Size: 94 KiB |
After Width: | Height: | Size: 99 KiB |
After Width: | Height: | Size: 49 KiB |
After Width: | Height: | Size: 46 KiB |
After Width: | Height: | Size: 37 KiB |
After Width: | Height: | Size: 27 KiB |
After Width: | Height: | Size: 61 KiB |
After Width: | Height: | Size: 36 KiB |
After Width: | Height: | Size: 987 B |
After Width: | Height: | Size: 5.7 KiB |
@ -65,8 +65,7 @@ Use the following URL to give consent to submit telemetry: ```https://login.micr
|
|||||||
> You may get an error that a page on ```https://ppe.fresno.wd.microsoft.com``` cannot be opened. Disregard the error as it does not affect the onboarding process.
|
> You may get an error that a page on ```https://ppe.fresno.wd.microsoft.com``` cannot be opened. Disregard the error as it does not affect the onboarding process.
|
||||||
|
|
||||||
|
|
||||||
insert image
|

|
||||||
|
|
||||||
|
|
||||||
## Deploy Microsoft Defender ATP for Mac
|
## Deploy Microsoft Defender ATP for Mac
|
||||||
Use any of the supported methods to deploy Microsoft Defender ATP for Mac
|
Use any of the supported methods to deploy Microsoft Defender ATP for Mac
|
||||||
@ -81,7 +80,7 @@ Download the installation and onboarding packages from Windows Defender Security
|
|||||||
4. In Section 2 of the page, click **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
|
4. In Section 2 of the page, click **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
|
||||||
5. Download IntuneAppUtil from https://docs.microsoft.com/en-us/intune/lob-apps-macos.
|
5. Download IntuneAppUtil from https://docs.microsoft.com/en-us/intune/lob-apps-macos.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
|
|
||||||
6. From a command prompt, verify that you have the three files.
|
6. From a command prompt, verify that you have the three files.
|
||||||
@ -126,17 +125,18 @@ You need no special provisioning for a Mac machine beyond a standard Company Por
|
|||||||
|
|
||||||
You'll be asked to confirm device management.
|
You'll be asked to confirm device management.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
Click the **Continue** button, and your Management Profile is displayed as verified:
|
Click the **Continue** button, and your Management Profile is displayed as verified:
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
You can enroll additional machines. Optionally, you can do it later, after system configuration and application package are provisioned.
|
You can enroll additional machines. Optionally, you can do it later, after system configuration and application package are provisioned.
|
||||||
|
|
||||||
In Intune, open the **Manage > Devices > All devices** blade.
|
In Intune, open the **Manage > Devices > All devices** blade.
|
||||||
You'll see your machine:
|
You'll see your machine:
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
|
|
||||||
### Create System Configuration profiles
|
### Create System Configuration profiles
|
||||||
1. In Intune open the **Manage > Device configuration** blade. Click **Manage > Profiles > Create Profile**.
|
1. In Intune open the **Manage > Device configuration** blade. Click **Manage > Profiles > Create Profile**.
|
||||||
@ -144,7 +144,7 @@ image
|
|||||||
3. Open the configuration profile and upload intune/kext.xml. This file was created during the Generate settings step above.
|
3. Open the configuration profile and upload intune/kext.xml. This file was created during the Generate settings step above.
|
||||||
4. Click **OK**.
|
4. Click **OK**.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
5. **Click Manage > Assignments**. In the **Include** tab, click **Assign to All Users & All devices**.
|
5. **Click Manage > Assignments**. In the **Include** tab, click **Assign to All Users & All devices**.
|
||||||
7. Repeat these steps with the second profile.
|
7. Repeat these steps with the second profile.
|
||||||
@ -153,7 +153,7 @@ image
|
|||||||
|
|
||||||
After Intune changes are propagated to the enrolled machines, you'll see it on the **Monitor > Device status** blade:
|
After Intune changes are propagated to the enrolled machines, you'll see it on the **Monitor > Device status** blade:
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
### Publish application
|
### Publish application
|
||||||
|
|
||||||
@ -163,37 +163,38 @@ image
|
|||||||
4. Click **Configure** and add the required information.
|
4. Click **Configure** and add the required information.
|
||||||
5. Use **macOS Sierra 10.12** as the minimum OS. Other settings can be any other value.
|
5. Use **macOS Sierra 10.12** as the minimum OS. Other settings can be any other value.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
6. Click **OK** and **Add**.
|
6. Click **OK** and **Add**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
7. It will take a while to upload the package. After it's done, click the name and then go to **Assignments** and **Add group**.
|
1. It will take a while to upload the package. After it's done, click the name and then go to **Assignments** and **Add group**.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
8. Change **Assignment type=Required**.
|
8. Change **Assignment type=Required**.
|
||||||
9. Click **Included Groups**. Select M**ake this app required for all devices=Yes**. Click **Select group to include** and add a group that contains the users you want to target. Select **OK** and **Save**.
|
9. Click **Included Groups**. Select M**ake this app required for all devices=Yes**. Click **Select group to include** and add a group that contains the users you want to target. Select **OK** and **Save**.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
10. After some time the application will be published to all enrolled machines. You'll see it on the **Monitor > Device** install status blade:
|
10. After some time the application will be published to all enrolled machines. You'll see it on the **Monitor > Device** install status blade:
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
### Verify client machine state
|
### Verify client machine state
|
||||||
1. After the configuration profiles are deployed to your machines, on your Mac device, open **System Preferences > Profiles**.
|
1. After the configuration profiles are deployed to your machines, on your Mac device, open **System Preferences > Profiles**.
|
||||||
|
|
||||||
image
|

|
||||||
|

|
||||||
2. Verify the three profiles listed there:
|
2. Verify the three profiles listed there:
|
||||||
|

|
||||||
image
|
|
||||||
|
|
||||||
|
|
||||||
3. The Management Profile should be the Intune system profile.
|
3. The Management Profile should be the Intune system profile.
|
||||||
4. wdav-config and wdav-kext are system configuration profiles that we added in Intune.
|
4. wdav-config and wdav-kext are system configuration profiles that we added in Intune.
|
||||||
5. You should also see the Microsoft Defender icon in the top-right corner:
|
5. You should also see the Microsoft Defender icon in the top-right corner:
|
||||||
|

|
||||||
## JAMF based deployment
|
## JAMF based deployment
|
||||||
### Prerequsites
|
### Prerequsites
|
||||||
You need to be familiar with JAMF administration tasks, have a JAMF tenant, and know how to deploy packages. This includes a properly configured distribution point. JAMF has many alternative ways to complete the same task. These instructions provide you an example for most common processes. Your organization might use a different workflow.
|
You need to be familiar with JAMF administration tasks, have a JAMF tenant, and know how to deploy packages. This includes a properly configured distribution point. JAMF has many alternative ways to complete the same task. These instructions provide you an example for most common processes. Your organization might use a different workflow.
|
||||||
@ -206,7 +207,7 @@ Download the installation and onboarding packages from Windows Defender Security
|
|||||||
3. In Section 2 of the page, click **Download installation package**. Save it as wdav.pkg to a local directory.
|
3. In Section 2 of the page, click **Download installation package**. Save it as wdav.pkg to a local directory.
|
||||||
4. In Section 2 of the page, click **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
|
4. In Section 2 of the page, click **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
5. From a command prompt, verify that you have the two files.
|
5. From a command prompt, verify that you have the two files.
|
||||||
Extract the contents of the .zip files:
|
Extract the contents of the .zip files:
|
||||||
@ -240,7 +241,7 @@ The configuration profile contains one custom settings payload that includes:
|
|||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
> You must use exactly "com.microsoft.wdav.atp" as the Preference Domain.
|
> You must use exactly "com.microsoft.wdav.atp" as the Preference Domain.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
#### Approved Kernel Extension
|
#### Approved Kernel Extension
|
||||||
|
|
||||||
@ -248,14 +249,14 @@ To approve the kernel extension:
|
|||||||
1. In **Computers > Configuration Profiles** click **Options > Approved Kernel Extensions**.
|
1. In **Computers > Configuration Profiles** click **Options > Approved Kernel Extensions**.
|
||||||
2. Use **UBF8T346G9** for Team Id.
|
2. Use **UBF8T346G9** for Team Id.
|
||||||
|
|
||||||
Image
|

|
||||||
|
|
||||||
#### Configuration Profile's Scope
|
#### Configuration Profile's Scope
|
||||||
Configure the appropriate scope to specify the machines that will receive this configuration profile.
|
Configure the appropriate scope to specify the machines that will receive this configuration profile.
|
||||||
|
|
||||||
In the Configuration Profiles, click **Scope > Targets**. Select the appropriate Target computers.
|
In the Configuration Profiles, click **Scope > Targets**. Select the appropriate Target computers.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
Save the **Configuration Profile**.
|
Save the **Configuration Profile**.
|
||||||
|
|
||||||
@ -264,7 +265,7 @@ Use the **Logs** tab to monitor deployment status for each enrolled machine.
|
|||||||
#### Package
|
#### Package
|
||||||
1. Create a package in **Settings > Computer Management > Packages**.
|
1. Create a package in **Settings > Computer Management > Packages**.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
2. Upload wdav.pkg to the Distribution Point.
|
2. Upload wdav.pkg to the Distribution Point.
|
||||||
3. In the **filename** field, enter the name of the package. For example, wdav.pkg.
|
3. In the **filename** field, enter the name of the package. For example, wdav.pkg.
|
||||||
@ -272,7 +273,7 @@ image
|
|||||||
#### Policy
|
#### Policy
|
||||||
Your policy should contain a single package for Microsoft Defender.
|
Your policy should contain a single package for Microsoft Defender.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
Configure the appropriate scope to specify the computers that will receive this policy.
|
Configure the appropriate scope to specify the computers that will receive this policy.
|
||||||
|
|
||||||
@ -286,12 +287,12 @@ You need no special provisioning for a macOS computer beyond the standard JAMF E
|
|||||||
|
|
||||||
1. Open the machine details, from **General** tab, and make sure that **User Approved MDM** is set to **Yes**. If it's set to No, the user needs to open **System Preferences > Profiles** and click **Approve** on the MDM Profile.
|
1. Open the machine details, from **General** tab, and make sure that **User Approved MDM** is set to **Yes**. If it's set to No, the user needs to open **System Preferences > Profiles** and click **Approve** on the MDM Profile.
|
||||||
|
|
||||||
image
|

|
||||||
image
|

|
||||||
|
|
||||||
After some time, the machine's User Approved MDM status will change to Yes.
|
After some time, the machine's User Approved MDM status will change to Yes.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
You can enroll additional machines now. Optionally, can do it after system configuration and application packages are provisioned.
|
You can enroll additional machines now. Optionally, can do it after system configuration and application packages are provisioned.
|
||||||
|
|
||||||
@ -304,18 +305,17 @@ You can monitor the deployment status in the Logs tab:
|
|||||||
- Pending means that the deployment is scheduled but has not yet happened
|
- Pending means that the deployment is scheduled but has not yet happened
|
||||||
- Completed means that the deployment succeeded and is no longer scheduled
|
- Completed means that the deployment succeeded and is no longer scheduled
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
|
|
||||||
#### Status on client machine
|
#### Status on client machine
|
||||||
After the Configuration Profile is deployed, you'll see the profile on the machine in the **System Preferences > Profiles >** Name of Configuration Profile.
|
After the Configuration Profile is deployed, you'll see the profile on the machine in the **System Preferences > Profiles >** Name of Configuration Profile.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
After the policy is applied, you'll see the Microsoft Defender icon in the macOS status bar in the top-right corner.
|
After the policy is applied, you'll see the Microsoft Defender icon in the macOS status bar in the top-right corner.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
|
|
||||||
You can monitor policy installation on a machine by following the JAMF's log file:
|
You can monitor policy installation on a machine by following the JAMF's log file:
|
||||||
|
|
||||||
@ -348,7 +348,7 @@ orgid effective : 79109c9d-83bb-4f3e-9152-8d75ee59ae22
|
|||||||
|
|
||||||
Create a script in **Settings > Computer Management > Scripts**.
|
Create a script in **Settings > Computer Management > Scripts**.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
For example, this script removes Microsoft Defender ATP from the /Applications directory:
|
For example, this script removes Microsoft Defender ATP from the /Applications directory:
|
||||||
|
|
||||||
@ -368,7 +368,7 @@ echo "Done!"
|
|||||||
#### Uninstalling with a policy
|
#### Uninstalling with a policy
|
||||||
Your policy should contain a single script:
|
Your policy should contain a single script:
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
Configure the appropriate scope in the Scope tab to specify the machines that will receive this policy.
|
Configure the appropriate scope in the Scope tab to specify the machines that will receive this policy.
|
||||||
|
|
||||||
@ -391,7 +391,7 @@ Download the installation and onboarding packages from Windows Defender Security
|
|||||||
3. In Section 2 of the page, click **Download installation package**. Save it as wdav.pkg to a local directory.
|
3. In Section 2 of the page, click **Download installation package**. Save it as wdav.pkg to a local directory.
|
||||||
4. In Section 2 of the page, click **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
|
4. In Section 2 of the page, click **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
5. From a command prompt, verify that you have the two files.
|
5. From a command prompt, verify that you have the two files.
|
||||||
Extract the contents of the .zip files:
|
Extract the contents of the .zip files:
|
||||||
@ -413,20 +413,20 @@ To complete this process, you must have admin privileges on the machine.
|
|||||||
|
|
||||||
2. Navigate to the downloaded wdav.pkg in Finder and open it.
|
2. Navigate to the downloaded wdav.pkg in Finder and open it.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
3. Click **Continue**, agree with the License terms, and enter the password when prompted.
|
3. Click **Continue**, agree with the License terms, and enter the password when prompted.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
>![IMPORTANT]
|
>![IMPORTANT]
|
||||||
> You will be prompted to allow a driver from Microsoft to be installed (either "System Exception Blocked" or "Installation is on hold…" or both. The driver must be allowed to be installed.
|
> You will be prompted to allow a driver from Microsoft to be installed (either "System Exception Blocked" or "Installation is on hold<6C>" or both. The driver must be allowed to be installed.
|
||||||
|
|
||||||
image
|
|
||||||
|
|
||||||
|

|
||||||
4. Click **Open Security Preferences** or **Open System Preferences > Security & Privacy**. Click **Allow**:
|
4. Click **Open Security Preferences** or **Open System Preferences > Security & Privacy**. Click **Allow**:
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
|
|
||||||
The installation will proceed.
|
The installation will proceed.
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
@ -457,7 +457,7 @@ The installation will proceed.
|
|||||||
```
|
```
|
||||||
After installation, you'll see the Microsoft Defender icon in the macOS status bar in the top-right corner.
|
After installation, you'll see the Microsoft Defender icon in the macOS status bar in the top-right corner.
|
||||||
|
|
||||||
image
|

|
||||||
|
|
||||||
## Uninstallation
|
## Uninstallation
|
||||||
### Removing Microsoft Defender ATP from Mac devices
|
### Removing Microsoft Defender ATP from Mac devices
|
||||||
|