Goal
Configure threat prevention, app watchlist, and app blocking policies to meet an organization's needs and risk tolerance.
Video
Key points
-
Three policies in the Jamf Security Cloud portal offer web threat prevention and mobile device protection:
-
Threat prevention policy
-
App watchlist
-
App blocking
-
-
The threat prevention policy determines how threats are reported and remediated.
-
Each threat category can be set to Active mode, where users and administrators can be notified of threats, or Log-only mode, where events only appear in the security event log.
-
The severity level of threats can be raised or lowered to meet an organization's risk tolerance.
-
If alerts are enabled, administrators receive daily or weekly email notifications while users receive notifications via the Jamf Trust app.
-
Auto response can automatically resolve threats upon detection.
-
-
Custom threat intelligence can be configured to allow or block network resources such as domains, IP addresses, and URLs.
-
The app watchlist is a selection of apps to keep under observation for installation by users.
-
Daily or weekly summaries can be emailed to administrators who have security notifications turned on.
-
-
App blocking can be used to block all traffic from specific apps identified by their bundle ID.
Review
To view answers, click arrow next to each question.
Practice
-
Create a custom threat prevention policy for the Marketing department.
-
Navigate to .
-
In the Group level pop-up menu, choose .
-
Enter Marketing in the Group name field.
-
Experiment with policy settings.
-
-
Add Telegram to the app watchlist.
-
Navigate to .
-
In the App package name field, enter ph.telegra.Telegraph.
-
Click Add.
-
Click Save.
-
-
Add Telegram to the app blocklist.
-
Navigate to .
-
In the Add apps to block field, enter ph.telegra.Telegraph.
-
Click Add app blocks.
-
Click Save and apply.
-
-
Remove Telegram from the app watchlist.
-
Navigate to .
-
Click the X button on the row for Telegram.
-
Click Save.
-
-
Remove Telegram from the app blocklist.
-
Navigate to .
-
Click Remove on the row for Telegram's bundle ID, ph.telegra.Telegraph.
-
Click Save and apply.
-
Resources
Jamf Protect Documentation