mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-13 05:47:23 +00:00
Improve styling
This commit is contained in:
parent
281e117bd2
commit
98f8d1df0a
@ -26,14 +26,14 @@ ms.topic: conceptual
|
|||||||
|
|
||||||
## Prerequisites and system requirements
|
## Prerequisites and system requirements
|
||||||
|
|
||||||
Before you get started, please see [the main Microsoft Defender ATP for Mac page](microsoft-defender-atp-mac.md) for a description of prerequisites and system requirements for the current software version.
|
Before you get started, see [the main Microsoft Defender ATP for Mac page](microsoft-defender-atp-mac.md) for a description of prerequisites and system requirements for the current software version.
|
||||||
|
|
||||||
## Download installation and onboarding packages
|
## Download installation and onboarding packages
|
||||||
|
|
||||||
Download the installation and onboarding packages from Windows Defender Security Center:
|
Download the installation and onboarding packages from Windows Defender Security Center:
|
||||||
|
|
||||||
1. In Windows Defender Security Center, go to **Settings > Machine Management > Onboarding**.
|
1. In Windows Defender Security Center, go to **Settings > Machine Management > Onboarding**.
|
||||||
2. In Section 1 of the page, set operating system to **Linux, macOS, iOS or Android** and Deployment method to **Local script**.
|
2. In Section 1 of the page, set operating system to **Linux, macOS, iOS, and Android** and Deployment method to **Local script**.
|
||||||
3. In Section 2 of the page, select **Download installation package**. Save it as wdav.pkg to a local directory.
|
3. In Section 2 of the page, select **Download installation package**. Save it as wdav.pkg to a local directory.
|
||||||
4. In Section 2 of the page, select **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
|
4. In Section 2 of the page, select **Download onboarding package**. Save it as WindowsDefenderATPOnboardingPackage.zip to the same directory.
|
||||||
|
|
||||||
@ -73,18 +73,18 @@ To complete this process, you must have admin privileges on the machine.
|
|||||||
|
|
||||||

|

|
||||||
|
|
||||||
The installation will proceed.
|
The installation proceeds.
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> If you don't select **Allow**, the installation will proceed after 5 minutes. Defender ATP will be loaded, but real-time protection will be disabled.
|
> If you don't select **Allow**, the installation will proceed after 5 minutes. Defender ATP will be loaded, but real-time protection will be disabled.
|
||||||
|
|
||||||
### Fixing disabled Real Time Protection
|
### Fixing disabled Real-Time Protection
|
||||||
|
|
||||||
If you did not enable Microsoft's driver during installation, then Defender's application will display a banner prompting you to enable it:
|
If you did not enable Microsoft's driver during installation, then the application displays a banner prompting you to enable it:
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
You can also run ```mdatp --health```. It will report if Real Time Protection is enabled but not available:
|
You can also run ```mdatp --health```. It reports if Real-Time Protection is enabled but not available:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mavel-mojave:~ testuser$ mdatp --health
|
mavel-mojave:~ testuser$ mdatp --health
|
||||||
@ -95,15 +95,15 @@ realTimeProtectionEnabled : true
|
|||||||
```
|
```
|
||||||
|
|
||||||
> [!NOTE]
|
> [!NOTE]
|
||||||
> You have a 30 minute window to enable Real Time Protection from the warning banner, immediately following installation.
|
> You have a 30 minute window to enable Real-Time Protection from the warning banner, immediately following installation.
|
||||||
|
|
||||||
The warning banner containing a **Fix** button, which allows you to quickly enable Real Time Protection, without having to open a command prompt. Select the **Fix** button. It will prompt the **Security & Privacy** system window, where you will have to **Allow** system software from developers "Microsoft Corporation".
|
The warning banner contains a **Fix** button, which allows you to quickly enable Real-Time Protection, without having to open a command prompt. Select the **Fix** button. It prompts the **Security & Privacy** system window, where you have to **Allow** system software from developers "Microsoft Corporation".
|
||||||
|
|
||||||
If you don't see a prompt, it means that 30 or more minutes have already passed, and Real Time Protection has still not been enabled:
|
If you don't see a prompt, it means that 30 or more minutes have already passed, and Real-Time Protection has still not been enabled:
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
In this case, you will need to perform the following steps to enable Real Time Protection instead.
|
In this case, you need to perform the following steps to enable Real-Time Protection instead.
|
||||||
|
|
||||||
1. In Terminal, attempt to install the driver. (The operation will fail)
|
1. In Terminal, attempt to install the driver. (The operation will fail)
|
||||||
```bash
|
```bash
|
||||||
@ -123,7 +123,7 @@ In this case, you will need to perform the following steps to enable Real Time P
|
|||||||
mavel-mojave:~ testuser$ sudo kextutil /Library/Extensions/wdavkext.kext
|
mavel-mojave:~ testuser$ sudo kextutil /Library/Extensions/wdavkext.kext
|
||||||
```
|
```
|
||||||
|
|
||||||
The banner should disappear from the Defender application, and ```mdatp --health``` should now report that Real Time Protection is both enabled and available:
|
The banner should disappear from the Defender application, and ```mdatp --health``` should now report that Real-Time Protection is both enabled and available:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mavel-mojave:~ testuser$ mdatp --health
|
mavel-mojave:~ testuser$ mdatp --health
|
||||||
@ -137,7 +137,7 @@ realTimeProtectionEnabled : true
|
|||||||
|
|
||||||
1. Copy wdav.pkg and WindowsDefenderATPOnboarding.py to the machine where you deploy Microsoft Defender ATP for Mac.
|
1. Copy wdav.pkg and WindowsDefenderATPOnboarding.py to the machine where you deploy Microsoft Defender ATP for Mac.
|
||||||
|
|
||||||
The client machine is not associated with orgId. Note that the orgid is blank.
|
The client machine is not associated with orgId. Note that the *orgId* attribute is blank.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mavel-mojave:wdavconfig testuser$ mdatp --health orgId
|
mavel-mojave:wdavconfig testuser$ mdatp --health orgId
|
||||||
@ -150,7 +150,7 @@ realTimeProtectionEnabled : true
|
|||||||
Generating /Library/Application Support/Microsoft/Defender/com.microsoft.wdav.atp.plist ... (You may be required to enter sudos password)
|
Generating /Library/Application Support/Microsoft/Defender/com.microsoft.wdav.atp.plist ... (You may be required to enter sudos password)
|
||||||
```
|
```
|
||||||
|
|
||||||
3. Verify that the machine is now associated with orgId:
|
3. Verify that the machine is now associated with your organization and reports a valid *orgId*:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
mavel-mojave:wdavconfig testuser$ mdatp --health orgId
|
mavel-mojave:wdavconfig testuser$ mdatp --health orgId
|
||||||
|
@ -24,13 +24,12 @@ ms.topic: conceptual
|
|||||||
|
|
||||||
## Prerequisites and system requirements
|
## Prerequisites and system requirements
|
||||||
|
|
||||||
Before you get started, please see [the main Microsoft Defender ATP for Mac page](microsoft-defender-atp-mac.md) for a description of prerequisites and system requirements for the current software version.
|
Before you get started, see [the main Microsoft Defender ATP for Mac page](microsoft-defender-atp-mac.md) for a description of prerequisites and system requirements for the current software version.
|
||||||
|
|
||||||
## Approach
|
## Approach
|
||||||
|
|
||||||
Your organization may use a Mobile Device Management (MDM) solution we do not officially support.
|
If your organization uses a Mobile Device Management (MDM) solution that is not officially supported, this does not mean you are unable to deploy or run Microsoft Defender ATP for Mac.
|
||||||
This does not mean you will be unable to deploy or run Microsoft Defender ATP for Mac.
|
However, Microsoft is not able to provide support for deploying or managing Defender via these solutions.
|
||||||
However, we will not be able to provide support for deploying or managing Defender via these solutions.
|
|
||||||
|
|
||||||
Microsoft Defender ATP for Mac does not depend on any vendor-specific features. It can be used with any MDM solution that supports the following features:
|
Microsoft Defender ATP for Mac does not depend on any vendor-specific features. It can be used with any MDM solution that supports the following features:
|
||||||
|
|
||||||
@ -40,39 +39,38 @@ Microsoft Defender ATP for Mac does not depend on any vendor-specific features.
|
|||||||
|
|
||||||
The majority of modern MDM solutions include these features, however, they may call them differently.
|
The majority of modern MDM solutions include these features, however, they may call them differently.
|
||||||
|
|
||||||
You can deploy Defender without the last requirement from the list above, however:
|
You can deploy Defender without the last requirement from the preceding list, however:
|
||||||
|
|
||||||
- You won't be able to collect status in a centralized way
|
- You will not be able to collect status in a centralized way
|
||||||
- If you decide to uninstall Defender, you'll need to logon to the client machine locally as an administrator
|
- If you decide to uninstall Defender, you'll need to logon to the client machine locally as an administrator
|
||||||
|
|
||||||
## Deployment
|
## Deployment
|
||||||
|
|
||||||
Most MDM solution use the same model for managing macOS machines, with similar terminology.
|
Most MDM solutions use the same model for managing macOS machines, with similar terminology. Use [JAMF-based deployment](microsoft-defender-atp-mac-install-with-jamf.md) as a template.
|
||||||
Use [JAMF-based deployment](microsoft-defender-atp-mac-install-with-jamf.md) as a template.
|
|
||||||
|
|
||||||
### Package
|
### Package
|
||||||
|
|
||||||
Configure deployment of a [required application package](microsoft-defender-atp-mac-install-with-jamf.md#package),
|
Configure deployment of a [required application package](microsoft-defender-atp-mac-install-with-jamf.md#package),
|
||||||
with the installation package (wdav.pkg) downloaded from [ATP](microsoft-defender-atp-mac-install-with-jamf.md#download-installation-and-onboarding-packages).
|
with the installation package (wdav.pkg) downloaded from [Microsoft Defender Security Center](microsoft-defender-atp-mac-install-with-jamf.md#download-installation-and-onboarding-packages).
|
||||||
|
|
||||||
Your MDM solution can allow you uploading of an arbitrary application package, or require you to wrap it into a custom package first.
|
Use the instructions associated with your MDM solution to deploy the package to your enterprise.
|
||||||
|
|
||||||
### License settings
|
### License settings
|
||||||
|
|
||||||
Setup [a system configuration profile](microsoft-defender-atp-mac-install-with-jamf.md#configuration-profile).
|
Set up [a system configuration profile](microsoft-defender-atp-mac-install-with-jamf.md#configuration-profile).
|
||||||
Your MDM solution may call it something like "Custom Settings Profile", as Microsoft Defender ATP for Mac is not part of macOS.
|
Your MDM solution may call it something like "Custom Settings Profile", as Microsoft Defender ATP for Mac is not part of macOS.
|
||||||
|
|
||||||
Use the property list, jamf/WindowsDefenderATPOnboarding.plist, which can extracted from an onboarding package downloaded from [ATP](microsoft-defender-atp-mac-install-with-jamf.md#download-installation-and-onboarding-packages).
|
Use the property list, jamf/WindowsDefenderATPOnboarding.plist, which can extracted from an onboarding package downloaded from [Microsoft Defender Security Center](microsoft-defender-atp-mac-install-with-jamf.md#download-installation-and-onboarding-packages).
|
||||||
Your system may support an arbitrary property list in XML format. You can just upload the jamf/WindowsDefenderATPOnboarding.plist file as-is in that case.
|
Your system may support an arbitrary property list in XML format. You can upload the jamf/WindowsDefenderATPOnboarding.plist file as-is in that case.
|
||||||
Alternatively, it may require you to convert the property list to a different format first.
|
Alternatively, it may require you to convert the property list to a different format first.
|
||||||
|
|
||||||
Note that your custom profile would have an id, name or domain attribute. You must use exactly "com.microsoft.wdav.atp".
|
Typically, your custom profile has an id, name, or domain attribute. You must use exactly "com.microsoft.wdav.atp" for this value.
|
||||||
MDM will use it to deploy the settings file to **/Library/Managed Preferences/com.microsoft.wdav.atp.plist** on a client machine, and Defender will use this file for loading onboarding info.
|
MDM uses it to deploy the settings file to **/Library/Managed Preferences/com.microsoft.wdav.atp.plist** on a client machine, and Defender uses this file for loading the onboarding info.
|
||||||
|
|
||||||
### KEXT
|
### Kernel extension (kext) policy
|
||||||
|
|
||||||
Setup a KEXT or kernel extension policy. Use team identifier **UBF8T346G9** to whitelist kernel extensions provided by Microsoft.
|
Set up a KEXT or kernel extension policy. Use team identifier **UBF8T346G9** to whitelist kernel extensions provided by Microsoft.
|
||||||
|
|
||||||
## Was it successful?
|
## Check installation status
|
||||||
|
|
||||||
Run [mdatp](microsoft-defender-atp-mac-install-with-jamf.md#check-onboarding-status) on a client machine.
|
Run [mdatp](microsoft-defender-atp-mac-install-with-jamf.md#check-onboarding-status) on a client machine to check the onboarding status.
|
||||||
|
@ -67,7 +67,7 @@ The detailed log will be saved to /Library/Logs/Microsoft/mdatp/install.log. If
|
|||||||
|
|
||||||
There are several ways to uninstall Microsoft Defender ATP for Mac. Please note that while centrally managed uninstall is available on JAMF, it is not yet available for Microsoft Intune.
|
There are several ways to uninstall Microsoft Defender ATP for Mac. Please note that while centrally managed uninstall is available on JAMF, it is not yet available for Microsoft Intune.
|
||||||
|
|
||||||
### Within the GUI
|
### Interactive uninstallation
|
||||||
|
|
||||||
- Open **Finder > Applications**. Right click on **Microsoft Defender ATP > Move to Trash**.
|
- Open **Finder > Applications**. Right click on **Microsoft Defender ATP > Move to Trash**.
|
||||||
|
|
||||||
@ -101,7 +101,7 @@ Important tasks, such as controlling product settings and triggering on-demand s
|
|||||||
|
|
||||||
In the Microsoft Defender ATP portal, you'll see two categories of information:
|
In the Microsoft Defender ATP portal, you'll see two categories of information:
|
||||||
|
|
||||||
- AV alerts, including:
|
- Antivirus alerts, including:
|
||||||
- Severity
|
- Severity
|
||||||
- Scan type
|
- Scan type
|
||||||
- Device information (hostname, machine identifier, tenant identifier, app version, and OS type)
|
- Device information (hostname, machine identifier, tenant identifier, app version, and OS type)
|
||||||
|
@ -27,9 +27,9 @@ This topic describes how to install, configure, update, and use Microsoft Defend
|
|||||||
|
|
||||||
## What’s new in the latest release
|
## What’s new in the latest release
|
||||||
|
|
||||||
Since opening the public preview, we've been working non-stop to enhance the product, by listening to customer feedback. We've added management features and more granular controls for diagnostic data collection, refined the user experience, and fixed bugs.
|
Since the announcement of the public preview, Microsoft has been working non-stop to enhance the product, by listening to customer feedback. We've added management features and more granular controls for diagnostic data collection, refined the user experience, and fixed bugs.
|
||||||
|
|
||||||
If you have any feedback, please submit it to us by opening Microsoft Defender ATP for Mac on your device and navigating to **Help** > **Send feedback**.
|
If you have any feedback that you would like to share, submit it by opening Microsoft Defender ATP for Mac on your device and navigating to **Help** > **Send feedback**.
|
||||||
|
|
||||||
## How to install Microsoft Defender ATP for Mac
|
## How to install Microsoft Defender ATP for Mac
|
||||||
|
|
||||||
@ -38,7 +38,7 @@ If you have any feedback, please submit it to us by opening Microsoft Defender A
|
|||||||
- You must have a Microsoft Defender ATP subscription.
|
- You must have a Microsoft Defender ATP subscription.
|
||||||
- You must have access to the Microsoft Defender Security Center portal.
|
- You must have access to the Microsoft Defender Security Center portal.
|
||||||
- You should have beginner-level experience in macOS and BASH scripting.
|
- You should have beginner-level experience in macOS and BASH scripting.
|
||||||
- If doing a manual deployment, you must have administrative privileges on the device.
|
- In case of manual deployment, you must have administrative privileges on the device.
|
||||||
|
|
||||||
### System requirements
|
### System requirements
|
||||||
|
|
||||||
@ -46,11 +46,11 @@ If you have any feedback, please submit it to us by opening Microsoft Defender A
|
|||||||
> The three most recent released versions of macOS are supported. Beta versions of macOS are not supported.
|
> The three most recent released versions of macOS are supported. Beta versions of macOS are not supported.
|
||||||
|
|
||||||
- Supported macOS versions: 10.14 (Mojave), 10.13 (High Sierra), 10.12 (Sierra)
|
- Supported macOS versions: 10.14 (Mojave), 10.13 (High Sierra), 10.12 (Sierra)
|
||||||
- Disk space: 650MB
|
- Disk space: 650 MB
|
||||||
|
|
||||||
After you've enabled the service, you may need to configure your network or firewall to allow outbound connections between it and your endpoints.
|
After you've enabled the service, you may need to configure your network or firewall to allow outbound connections between it and your endpoints.
|
||||||
|
|
||||||
The following table lists the services and their associated URLs that your network must be able to connect to. You should ensure there are no firewall or network filtering rules that would deny access to these URLs, or you may need to create an *allow* rule specifically for them:
|
The following table lists the services and their associated URLs that your network must be able to connect to. You should ensure that there are no firewall or network filtering rules that would deny access to these URLs, or you may need to create an *allow* rule specifically for them:
|
||||||
|
|
||||||
| Service | Description | URL |
|
| Service | Description | URL |
|
||||||
| -------------- | ------------------------------------ | -------------------------------------------------------------------- |
|
| -------------- | ------------------------------------ | -------------------------------------------------------------------- |
|
||||||
@ -64,7 +64,7 @@ If you prefer the command line, you can also check the connection by running the
|
|||||||
curl -w ' %{url_effective}\n' 'https://x.cp.wd.microsoft.com/api/report' 'https://cdn.x.cp.wd.microsoft.com/ping'
|
curl -w ' %{url_effective}\n' 'https://x.cp.wd.microsoft.com/api/report' 'https://cdn.x.cp.wd.microsoft.com/ping'
|
||||||
```
|
```
|
||||||
|
|
||||||
The output from this command should look like this:
|
The output from this command should be similar to the following:
|
||||||
|
|
||||||
> `OK https://x.cp.wd.microsoft.com/api/report`
|
> `OK https://x.cp.wd.microsoft.com/api/report`
|
||||||
>
|
>
|
||||||
@ -77,15 +77,15 @@ The output from this command should look like this:
|
|||||||
|
|
||||||
There are several methods and deployment tools that you can use to install and configure Microsoft Defender ATP for Mac.
|
There are several methods and deployment tools that you can use to install and configure Microsoft Defender ATP for Mac.
|
||||||
|
|
||||||
In general you'll need to take the following steps:
|
In general you need to take the following steps:
|
||||||
|
|
||||||
- Ensure you have a Microsoft Defender ATP subscription and have access to the Microsoft Defender ATP Portal
|
- Ensure that you have a Microsoft Defender ATP subscription and have access to the Microsoft Defender ATP Portal
|
||||||
- Deploy Microsoft Defender ATP for Mac using one of the following deployment methods:
|
- Deploy Microsoft Defender ATP for Mac using one of the following deployment methods:
|
||||||
- Via third party management tools:
|
- Via third-party management tools:
|
||||||
- [Microsoft Intune-based deployment](microsoft-defender-atp-mac-install-with-intune.md)
|
- [Microsoft Intune-based deployment](microsoft-defender-atp-mac-install-with-intune.md)
|
||||||
- [JAMF-based deployment](microsoft-defender-atp-mac-install-with-jamf.md)
|
- [JAMF-based deployment](microsoft-defender-atp-mac-install-with-jamf.md)
|
||||||
- [Other MDM products](microsoft-defender-atp-mac-install-with-other-mdm.md)
|
- [Other MDM products](microsoft-defender-atp-mac-install-with-other-mdm.md)
|
||||||
- Via the command line tool:
|
- Via the command-line tool:
|
||||||
- [Manual deployment](microsoft-defender-atp-mac-install-manually.md)
|
- [Manual deployment](microsoft-defender-atp-mac-install-manually.md)
|
||||||
|
|
||||||
## How to update Microsoft Defender ATP for Mac
|
## How to update Microsoft Defender ATP for Mac
|
||||||
@ -100,6 +100,6 @@ Guidance for how to configure the product in enterprise environments is availabl
|
|||||||
|
|
||||||
## Resources
|
## Resources
|
||||||
|
|
||||||
- For additional information about logging, uninstalling, or known issues, see our [Resources](microsoft-defender-atp-mac-resources.md) page.
|
- For more information about logging, uninstalling, or known issues, see the [Resources](microsoft-defender-atp-mac-resources.md) page.
|
||||||
|
|
||||||
- [Privacy for Microsoft Defender ATP for Mac](microsoft-defender-atp-mac-privacy.md)
|
- [Privacy for Microsoft Defender ATP for Mac](microsoft-defender-atp-mac-privacy.md)
|
||||||
|
Loading…
x
Reference in New Issue
Block a user