Microsoft Defender for Endpoint
Endpoint protection

Set up the Microsoft Defender for Endpoint on macOS policies in Jamf Pro

In brief

The article now provides expanded guidance for onboarding, antivirus and EDR settings, notifications, Microsoft AutoUpdate, permissions, system extensions, network extensions, and deployment profiles. It also clarifies GUI and legacy configuration methods, schema usage, and required bundle and socket-filter values.

What Defender admins need to know

Administrators deploying Defender with Jamf Pro should follow the clarified configuration steps and verify the specified identifiers and schema settings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Set up the Microsoft Defender for Endpoint on macOS policies in Jamf Pro

Use thisThis article walks you through creating the Jamf Pro configuration profiles and policies needed to set up policies fordeploy and manage Microsoft Defender for Endpoint on macOS. The steps cover onboarding, antivirus and EDR settings, notifications, Microsoft AutoUpdate, Full Disk Access, system extensions, network extensions, background services, Bluetooth permissions, and package deployment. IT administrators who manage macOS usingdevices through Jamf Pro.Pro should follow these steps to ensure Defender for Endpoint is fully configured and protected.

Step 1: Get the Microsoft Defender for Endpoint onboarding package

Step 2: Create a configuration profile in Jamf Pro using the onboarding package

  1. Locate the WindowsDefenderATPOnboarding.plist file that you extracted from the onboarding package in Step 1 (steps 3–5).1.

    :::image type="content" source="media/plist-onboarding-file.png" alt-text="The Windows Defender ATP Onboarding file." lightbox="media/plist-onboarding-file.png":::

Step 3: Configure Microsoft Defender for Endpoint settings

InUse this step, we go over Preferences so you canstep to configure anti-malware and EDR policies usingthrough the Microsoft Defender portal or Jamf.

Use the Microsoft Defender portal to create and assign macOS security policies to your devices.

Before you begin, complete the setup described in Configure Microsoft Defender for Endpoint in Intune before setting the security policies using Microsoft Defender..

  1. In the Microsoft Defender portal, go to Configuration management > Endpoint security policies > Mac policies > Create new policy.

  2. Under Select Platform, select macOS.

You must use exact com.microsoft.wdav as the Preference Domain. Microsoft Defender for Endpoint uses only this name and com.microsoft.wdav.ext to load its managed settings. (The com.microsoft.wdav.ext version can be used in rare cases when you prefer to use GUI method, but also need to configure a setting that hasn't been added to the schema yet.)

Configure Defender settings using the Jamf Pro GUI method

Use this method to import Defender's JSON schema into Jamf Pro and configure settings through the GUI.

  1. Download the Microsoft Defender for Endpoint schema.json file from Defender's GitHub repository and save it locally. Jamf Pro uses this schema to a local file:populate the available configuration settings in the GUI:

    curl -o ~/Documents/schema.json https://raw.githubusercontent.com/microsoft/mdatp-xplat/master/macos/schema/schema.json
    
     :::image type="content" source="media/dd55405106da0dfc2f50f8d4525b01c8.png" alt-text="The page on which you complete the Configuration settings." lightbox="media/dd55405106da0dfc2f50f8d4525b01c8.png":::
    

Microsoft Defender for Endpoint adds new settings over time. These newNew Defender for Endpoint settings are added to the schema, and a new version is published to GitHub. To get updates, download an updated schema and edit your existing configuration profile. On the Application & Custom Settings tab, select Edit schema.

LegacyConfigure Defender settings using the legacy method

Use the legacy method to manually create a configuration plist in a text editor and upload it to Jamf Pro.

  • Bundle ID: com.microsoft.autoupdate.fba
  1. Configure the rest of the settings toUse the same values mentioned earlierfrom the previous step for the remaining settings.

    :::image type="content" source="media/4bac6ce277aedfb4a674f2d9fcb2599a.png" alt-text="The configuration settings mdatpmdav notifications mau." lightbox="media/4bac6ce277aedfb4a674f2d9fcb2599a.png":::

    Now youYou now have two tables with notification configurations,entries: one for Bundle ID: com.microsoft.wdav.tray, and anotherone for Bundle ID: com.microsoft.autoupdate.fba. While youYou can configureadjust alert settings perto fit your requirements,needs. However, both Bundle IDs must be exactlymatch the same as described before,values shown here exactly, and the Include switch must be On for Notifications.

  2. Select the Scope tab, and then select Add.

    • Socket Filter Designated Requirement: identifier "com.microsoft.wdav.netext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = UBF8T346G9
    • Leave Network Filter fields blank (Include isn't* selected)

    NoteVerify that Identifier is set to com.microsoft.wdav, **Socket Filter,Filter is set to com.microsoft.wdav.netext, and Socket Filter Designated Requirement exact values as specified earlier.matches the code-signing requirement shown in the preceding list.

    :::image type="content" source="media/netext-create-profile.png" alt-text="The mdatpmdav configuration setting." lightbox="media/netext-create-profile.png":::

    :::image type="content" source="media/netext-final.png" alt-text="The configuration settings netext - final." lightbox="media/netext-final.png":::

Alternatively, you can download netfilter.mobileconfig and upload it to Jamf Configuration Profiles as described in Deploying Custom Configuration Profiles using Jamf Pro

Step 9: Configure Background Services

Download background_services.mobileconfig from the Microsoft Defender for Endpoint macOS mobileconfig profiles repository.

Download bluetooth.mobileconfig from the Microsoft Defender for Endpoint macOS mobileconfig profiles repository.

  • You need to have at least one signing certificate installed into your KeyChain, even a self-signed certificate works. To find the certificate name you need to sign the configuration profile, list the available code-signing identities:

    > /usr/bin/security find-identity -p codesigning -v
         4 valid identities found
    

Choose any of the listed signing identities, and provide the quoted certificate name as the -N parameter:

/usr/bin/security cms -S -N "DevCert" -i bluetooth.mobileconfig -o bluetooth-signed.mobileconfig

## Step 11: Schedule scans with Microsoft Defender for Endpoint on macOS

Follow the instructions in [Schedule scans with Microsoft Defender for Endpoint on macOS](mac-schedule-scan.md).

## Step 12: Deploy Microsoft Defender for Endpoint on macOS

Upload the Microsoft Defender for Endpoint package to Jamf Pro and create a deployment policy to distribute it to your macOS devices.

Jamf Pro provides a way to ensure the correct order. You can create a smart group for machines that already received Microsoft Defender's configuration profile, and install Microsoft Defender's package only to those machines (and as soon as they receive this profile).

To create the smart group and scope the package policy, follow these steps:

  1. Create a smart group. In a new browser window, open Smart Computers Groups.

    :::image type="content" source="media/632aaab79ae18d0d2b8e0c16b6ba39e2.png" alt-text="The policies page." lightbox="media/632aaab79ae18d0d2b8e0c16b6ba39e2.png":::

Verify configuration profile scope for all Defender profiles

Jamf requires you to define a set of machines for each configuration profile. Make sure that all machines that get the Defender package also get all of these profiles:

  • Onboarding (Step 2)
  • Defender for Endpoint settings (Step 3)
  • Notifications (Step 4)
  • Microsoft AutoUpdate (Step 5)
  • Full Disk Access (Step 6)
  • System extensions (Step 7)
  • Network extension (Step 8)
  • Background services (Step 9)
  • Bluetooth permissions (Step 10)