178: Deploy MDM based policies for EDR/AV
Overview
Deploying MDM-based policies for Endpoint Detection and Response (EDR) and Antivirus (AV) on macOS devices using Microsoft Intune involves several steps. Here's a detailed overview:
Steps to Deploy MDM-Based Policies for EDR/AV on macOS
-
Prerequisites and System Requirements:
- Ensure you have the necessary licenses for Microsoft Defender for Endpoint.
- Verify that macOS devices meet the system requirements¹.
-
Create System Configuration Profiles:
- In the Intune admin center, navigate to Devices > Configuration profiles.
- Create profiles for system extensions, network extensions, full disk access, and other necessary configurations.
-
Approve System Extensions:
- Go to Devices > Configuration profiles and create a new profile.
- Select macOS as the platform and Extensions as the profile type.
- Add the required system extensions.
-
Deploy Microsoft Defender for Endpoint:
- Download the onboarding package from the Microsoft Defender Security Center.
- Deploy the package using Intune by creating a new app and assigning it to the relevant device groups.
-
Configure EDR Policies:
- In the Intune admin center, go to Endpoint security > Endpoint detection and response.
- Create and configure EDR policies, including onboarding packages and other settings.
Benefits
- Enhanced Security: Provides advanced threat detection and response capabilities, improving overall security posture.
- Centralized Management: Simplifies the management of security policies across all macOS devices from a single console.
- Compliance: Helps ensure devices comply with organizational security policies and regulatory requirements.