Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Mass Deployment and Configuration of Security Permissions via MDM and Mac OS Big Sur

    • Updated:
    • 25 Feb 2021
    • Product/Version:
    • Apex One (Mac)
    • Platform:
    • Macintosh Big Sur
Summary

This article is intended for generating the MDM profile for Apex Mac Agents running Big Sur.

Details
Public

Steps on creating an MDM profile for Mac OS Big Sur and Airwatch / JAMF:

Open up Jamf or Airwatch MDM Server and go to Device > Profiles to add a new Mac OS Profile (Needed to be specified which OS the profile is for to prevent format issues)

Open the MDM console to access the device profile page

Go to Security and Privacy and have the Gatekeeper to select “Anywhere” or allow apps outside Mac App store.

o to Security and Privacy and have the Gatekeeper to select “Anywhere” or allow apps outside Mac App store

On the Kernel Extension Policy, Check the Allow User Overrides, and indicate the Allowed Kernel Extensions for Apex Mac Service:

o to Security and Privacy and have the Gatekeeper to select “Anywhere” or allow apps outside Mac App store

  • identifier "com.trendmicro.icore" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = E8P47U2H32    
  • identifier "com.trendmicro.tmsm.MainUI" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = E8P47U2H32
  •  identifier "com.trendmicro.icore.es" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = E8P47U2H32

Apple Identifier in exact keywords: 

Identifier "com.apple.systemevents" and anchor apple

Apply the Apple Identifier

Apply the System Profiles to target mac machines alongside

1 or 2 restart is still needed for it to take effect on the machines.

NOTE: The steps still not includes the automation for Apex Mac Toolbar extension and . There is a separate profile available to use on the other reference article, which also includes the profile configuration for older versions of Mac OS: Information needed when configuring MDM Profile for Apex One (Mac)

Premium
Internal
Partner
Rating:
Category:
Configure; Deploy
Solution Id:
000285787
Feedback
Did this article help you?

Thank you for your feedback!


*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.