Lesson 7: Introduction to the macOS Security Portal - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Understand the different features of the macOS Security portal and become familiar with navigating the application.

Video

Key points

  • The macOS Security portal is a web application for managing and monitoring security settings on enrolled computers.

    • Computers can be enrolled by deploying the Jamf Protect agent and relevant configuration profiles with an MDM solution like Jamf Pro.

  • The dashboards on the Overview page provide useful alert visualizations and trend metrics.

    • Dashboard elements can be clicked to view more details.

  • The Compliance Summary displays the status of all configured rules in the active security baseline.

    • Rules can be filtered for easier viewing and be individually enabled or disabled on the Baseline tab.

  • The Computers page displays a detailed list of all enrolled computers for easy inspection.

  • The Alerts page contains a rolling log of every alert triggered by an enrolled computer.

    • Alerts are recorded any time a compromising action occurs on an enrolled computer, and are assigned a severity level by the related analytic.

    • Severity ranges from 0 (Informational) to 3 (High).

    • Alerts can be filtered and sorted for more targeted viewing.

  • The Analytics page provides access to all analytics currently configured in the macOS Security portal.

    • Analytics are rules that detect threats and unwanted behaviors on enrolled computers.

    • Many analytics are based on the MITRE ATT&CK® Matrix for macOS.

    • Additional analytics and analytic sets can be configured if needed.

  • Plans are security configurations that are deployed to computers via configuration profile.

    • Plans can be viewed, created, and edited within the Plans page.

    • Plans determine which analytics, compliance results, actions, and other configurations should apply to each computer.

    • Each computer should only be assigned one plan.

  • Actions determine which analytics, logs, and compliance results are reported to the macOS Security portal or to an external security information and event management (SIEM) system.

    • Actions can be viewed, created, and edited on the Actions page.

  • Threat prevention is a built-in malware prevention and remediation tool that detects, blocks, and quarantines malicious processes on enrolled computers.

    • The Threat Prevention page contains details about past and current threat prevention versions, custom prevention list creation capabilities, and access to the Jamf Security Cloud portal for web filtering.

  • The macOS Security portal also contains specialized features which may be useful to different organizations, such as removable storage control and local log collection.

  • The Administrative section contains useful tools and information for administrators in the macOS Security portal.

Review

To view answers, click arrow next to each question.
  1. The Alerts page contains a rolling log of all alerts triggered by every enrolled computer, which can be filtered and sorted by severity and other criteria.
  2. Threat prevention protects computers by detecting, blocking, and quarantining malicious processes, and is regularly updated to include new threats.
  3. A plan determines which analytics, insights, actions, and other configurations should apply to each computer. A computer should only be assigned one plan at a time.

Practice

  1. View how many rules are tagged with CIS Level 1 and CIS Level 2.

    1. Navigate to Compliance > Baseline.

    2. In the Filter section, click the CIS Level 1 and CIS Level 2 filter buttons.

  2. View all new alerts.

    1. Navigate to Alerts.

    2. In the Filters section, remove any active filters by clicking the X on each filter.

    3. In the Filter By field, choose "Status" and then "New".

    4. Click the magnifying glass icon or press Return to enable the filter.

  3. Verify the number of computers with the latest version of endpoint threat prevention.

    1. Navigate to Threat Prevention > Endpoint Threat Prevention.

    2. Find the number of computers on the latest version.

Resources

Jamf Protect Documentation