在 macOS 上使用移动设备管理部署 Elastic Defend
要以静默方式安装和部署 Elastic Defend,您需要为 Elastic Endpoint(执行 Elastic Defend 威胁监视和预防的已安装组件)配置移动设备管理 (MDM) 配置文件。这使您可以预先批准 Elastic Endpoint 系统扩展,并为所有必要的组件授予完全磁盘访问权限。
本页说明如何使用 Jamf 以静默方式部署 Elastic Defend。
在 Jamf 中,为 Elastic Endpoint 创建配置文件。按照以下步骤配置此配置文件
选择 System Extensions 选项,为 Elastic Endpoint 配置文件配置系统扩展策略。
确保选中了 Allow users to approve system extensions。
在 Allowed Team IDs and System Extensions 部分,添加 Elastic Endpoint 系统扩展
- (可选)为 Elastic Endpoint 系统扩展输入 Display Name。
- 从 System Extension Types 下拉菜单中,选择 Allowed System Extensions。
- 在 Team Identifier 下,输入
2BT3HPN62Z。 - 在 Allowed System Extensions 下,输入
co.elastic.systemextension。
保存配置。
选择 Content Filter 选项,为 Elastic Endpoint 配置文件配置网络扩展策略。
在 Filter Name 下,输入
ElasticEndpoint。在 Identifier 下,输入
co.elastic.endpoint。在 Socket Filter 部分,填写以下字段
Socket Filter Bundle Identifier:输入
co.elastic.systemextensionSocket Filter Designated Requirement:输入以下内容
identifier "co.elastic.systemextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "2BT3HPN62Z"
在 Network Filter 部分,填写以下字段
Network Filter Bundle Identifier:输入
co.elastic.systemextensionNetwork Filter Designated Requirement:输入以下内容
identifier "co.elastic.systemextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "2BT3HPN62Z"
保存配置。
选择 Notifications 选项,为 Elastic Endpoint 配置文件配置通知中心策略。
在 App Name 下,输入
Elastic Security.app。在 Bundle ID 下,输入
co.elastic.alert。在 Settings 部分,包含具有以下设置的选项
- Critical Alerts:启用
- Notifications:启用
- Banner alert type:持久
- Notifications on Lock Screen:显示
- Notifications in Notification Center:显示
- Badge app icon:显示
- Play sound for notifications:启用
保存配置。
选择 Privacy Preferences Policy Control 选项,为 Elastic Endpoint 配置文件配置完全磁盘访问权限策略。
添加具有以下详细信息的新条目
在 Identifier 下,输入
co.elastic.systemextension。从 Identifier Type 下拉菜单中,选择 Bundle ID。
在 Code Requirement 下,输入以下内容
identifier "co.elastic.systemextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "2BT3HPN62Z"确保选中了 Validate the Static Code Requirement。
在 APP or SERVICE 下,选择
SystemPolicyAllFiles并将其设置为Allow。
添加具有以下详细信息的第二个条目
在 Identifier 下,输入
co.elastic.endpoint。从 Identifier Type 下拉菜单中,选择 Bundle ID。
在 Code Requirement 下,输入以下内容
identifier "co.elastic.endpoint" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "2BT3HPN62Z"确保选中了 Validate the Static Code Requirement。
在 APP or SERVICE 下,选择
SystemPolicyAllFiles并将其设置为Allow。
添加具有以下详细信息的第三个条目
在 Identifier 下,输入
co.elastic.elastic-agent。从 Identifier Type 下拉菜单中,选择 Bundle ID。
在 Code Requirement 下,输入以下内容
identifier "co.elastic.elastic-agent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "2BT3HPN62Z"确保选中了 Validate the Static Code Requirement。
在 APP or SERVICE 下,选择
SystemPolicyAllFiles并将其设置为Allow。
保存配置。
完成这些步骤后,生成移动配置文件并将其安装到 macOS 机器上。安装配置文件后,无需用户交互即可部署 Elastic Defend。