Microsoft Defender for Endpoint
Endpoint protection

Manage system extensions using Jamf

In brief

The article now explicitly covers approving system extensions, granting Full Disk Access through Privacy Preferences Policy Control, and configuring network extensions. It also clarifies code requirements and commands for validating and signing configuration profiles.

What Defender admins need to know

Administrators have clearer Jamf procedures and examples for deploying Defender for Endpoint on macOS.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Manage system extensions using Jamf

This article describes how to use Jamf to approve system extensions, grant Full Disk Access through Privacy Preferences Policy Control, and configure the procedures to implement in the process of managing the system extensions to ensurenetwork extension policy for Microsoft Defender for Endpoint works properly on macOS. Complete the prerequisites for deploying Microsoft Defender for Endpoint before you follow these procedures.

Configure system extensions in Jamf

Configure the Jamf system extensions policy

Configure Privacy Preferences Policy Control for Full Disk Access

Add the following Jamf payload to grant Full Disk Access to the Microsoft Defender for Endpoint Security Extension. This policyThe Privacy Preferences Policy Control payload is a prerequisite for running the extension on your device.

  1. Select Options > Privacy Preferences Policy Control.

  2. Use com.microsoft.wdav.epsext as the Identifier and Bundle ID as Bundle type.

  3. Set Code Requirement to the following value:

    identifier com.microsoft.wdav.epsext and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists /*/ and certificate leaf[field.1.2.840.113635.100.6.1.13] //* exists */ and certificate leaf[subject.OU] = UBF8T346G9.
  4. Set App or service to SystemPolicyAllFiles and access to Allow.

Configure the Network Extension policy in Jamf

As part of the Endpoint Detection and Response capabilities, Microsoft Defender for Endpoint on macOS inspects socket traffic and reports this information to the Microsoft Defender portal. The following policy allows the network extension to performinspect socket traffic and report this functionality:information to the Microsoft Defender portal:

  1. Save the following content to your device as com.microsoft.network-extension.mobileconfig using a text editor:
   <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1">
    <dict>
</plist>
  1. Verify that the XML configuration profile content was copied correctly into the com.microsoft.network-extension.mobileconfig file by running the plutil utility in terminal. This command checks whether the mobileconfig file is a valid property list (plist):
$ plutil -lint <PathToFile>/com.microsoft.network-extension.mobileconfig

For example, the following command validates a profile stored in the Documents folder:

$ plutil -lint ~/Documents/com.microsoft.network-extension.mobileconfig
  1. Verify that the plutil -lint command outputs OK. The following sample output confirms the profile file is valid:
<PathToFile>/com.microsoft.network-extension.mobileconfig: OK

1. Follow the instructions in [Jamf technical articles](https://learn.jamf.com/bundle/technical-articles/page/Welcome.html) to create a signing certificate using Jamf's built-in certificate authority.

1. After the Jamf signing certificate is created and installed on your device, run the following command from terminal to sign the configuration profile. Replace `<CertificateName>` with the name of your signing certificate, `<PathToFile>` with the path to the unsigned mobileconfig file, and `<PathToSignedFile>` with the desired output path for the signed file:

```BashCopy
$ security cms -S -N "<CertificateName>" -i <PathToFile>/com.microsoft.network-extension.mobileconfig -o <PathToSignedFile>/com.microsoft.network-extension.signed.mobileconfig

For example, the following command signs a profile stored in the Documents folder using a certificate named SigningCertificate and saves the signed output to the same folder:

$ security cms -S -N "SigningCertificate" -i ~/Documents/com.microsoft.network-extension.mobileconfig -o ~/Documents/com.microsoft.network-extension.signed.mobileconfig