Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Use the Microsoft Intune settings catalog to approve the endpoint security and network extensions required by Microsoft Defender for Endpoint on managed macOS devices.
The procedure in this article requires Microsoft Intune. Intune is a separate product that isn't part of Microsoft Defender for Endpoint, and it isn't included in all subscriptions. To use Intune, you need a subscription that includes it, or you can buy it separately as a standalone subscription or add-on. If you don't have Intune, see Configure Microsoft Defender for Endpoint system extension profiles with Jamf Pro. For more information, see Microsoft Intune licensing.
Note
The macOS Extensions template in Intune was deprecated in the August 2024 service release (2408). Policies created with the template continue to work, but you can't create new policies with it.
Use the settings catalog to create policies that configure the macOS System Extensions payload.
Prerequisites
Before you create the policy, verify the following requirements:
- The devices meet the Microsoft Defender for Endpoint on macOS prerequisites.
- The devices are enrolled in Intune by using Automated Device Enrollment or Device enrollment. For more information, see Enrollment guide: Enroll macOS devices in Microsoft Intune.
- Your account has the Intune Policy and Profile Manager role. For more information, see Built-in roles for Microsoft Intune.
Configure the Intune system extensions policy
Create a policy by following the instructions in Create a policy using the settings catalog in Microsoft Intune (link opens in a new window).
When you create the policy on the Policies tab of the Devices | Configuration page in the Microsoft Intune admin center at https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesMenu/~/configuration, by selecting Create >
New policy, use these specific settings:
- Platform: Select macOS.
- Profile type: Select Settings catalog.
In the Settings catalog wizard, add and configure the Defender for Endpoint system extension settings on the Configuration settings tab:
Select Add settings.
In the Settings picker, enter
allowed systemin the search box, and then select Search.Under Browse by category, select System Configuration > System Extensions.
Select the following settings:
- Allowed System Extension Types
- Allowed System Extensions
Close the Settings picker.
Configure Allowed System Extensions:
- In the Allowed System Extensions section, select + Edit instance.
- In the Configure instance flyout, enter the following bundle identifiers, one per box:
com.microsoft.wdav.epsextcom.microsoft.wdav.netext
- For Team Identifier, enter
UBF8T346G9. - Select Save.
Configure Allowed System Extension Types:
- In the Allowed System Extension Types section, select + Edit instance.
- In the Configure instance flyout, enter the following values, one per box:
NetworkEndpointSecurity
- For Team Identifier, enter
UBF8T346G9. - Select Save.
Verify that both entries appear on the Configuration settings tab.
On the Assignments tab, assign the policy to the devices that should receive it. Complete the remaining tabs, and then create the policy.
The next time the targeted devices check in, they receive the system extension settings.