Lesson 12: Network and Mobile Endpoint Security - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Configure threat prevention, app watchlist, and app blocking policies to meet an organization's needs and risk tolerance.

Video

Key points

  • Three policies in the Jamf Security Cloud portal offer web threat prevention and mobile device protection:

    • Threat prevention policy

    • App watchlist

    • App blocking

  • The threat prevention policy determines how threats are reported and remediated.

    • Each threat category can be set to Active mode, where users and administrators can be notified of threats, or Log-only mode, where events only appear in the security event log.

    • The severity level of threats can be raised or lowered to meet an organization's risk tolerance.

    • If alerts are enabled, administrators receive daily or weekly email notifications while users receive notifications via the Jamf Trust app.

    • Auto response can automatically resolve threats upon detection.

  • Custom threat intelligence can be configured to allow or block network resources such as domains, IP addresses, and URLs.

  • The app watchlist is a selection of apps to keep under observation for installation by users.

    • Daily or weekly summaries can be emailed to administrators who have security notifications turned on.

  • App blocking can be used to block all traffic from specific apps identified by their bundle ID.

Review

To view answers, click arrow next to each question.

  1. Users receive notifications via the Jamf Trust app.
  2. Administrators receive daily or weekly summaries via email.
  3. App blocking uses an app's bundle ID to block traffic.

Practice

  1. Create a custom threat prevention policy for the Marketing department.

    1. Navigate to Policies > Security > Threat prevention policy.

    2. In the Group level pop-up menu, choose "Create new group".

    3. Enter Marketing in the Group name field.

    4. Experiment with policy settings.

  2. Add Telegram to the app watchlist.

    1. Navigate to Policies > Security > App watchlist.

    2. In the App package name field, enter ph.telegra.Telegraph.

    3. Click Add.

    4. Click Save.

  3. Add Telegram to the app blocklist.

    1. Navigate to Policies > Security > App blocking.

    2. In the Add apps to block field, enter ph.telegra.Telegraph.

    3. Click Add app blocks.

    4. Click Save and apply.

  4. Remove Telegram from the app watchlist.

    1. Navigate to Policies > Security > App watchlist.

    2. Click the X button on the row for Telegram.

    3. Click Save.

  5. Remove Telegram from the app blocklist.

    1. Navigate to Policies > Security > App blocking.

    2. Click Remove on the row for Telegram's bundle ID, ph.telegra.Telegraph.

    3. Click Save and apply.

Resources

Jamf Protect Documentation