Goal
Understand the different features of the macOS Security portal and become familiar with navigating the application.
Video
Key points
-
The macOS Security portal is a web application for managing and monitoring security settings on enrolled computers.
-
Computers can be enrolled by deploying the Jamf Protect agent and relevant configuration profiles with an MDM solution like Jamf Pro.
-
-
The dashboards on the Overview page provide useful alert visualizations and trend metrics.
-
Dashboard elements can be clicked to view more details.
-
-
The Compliance Summary displays the status of all configured rules in the active security baseline.
-
Rules can be filtered for easier viewing and be individually enabled or disabled on the Baseline tab.
-
-
The Computers page displays a detailed list of all enrolled computers for easy inspection.
-
The Alerts page contains a rolling log of every alert triggered by an enrolled computer.
-
Alerts are recorded any time a compromising action occurs on an enrolled computer, and are assigned a severity level by the related analytic.
-
Severity ranges from 0 (Informational) to 3 (High).
-
Alerts can be filtered and sorted for more targeted viewing.
-
-
The Analytics page provides access to all analytics currently configured in the macOS Security portal.
-
Analytics are rules that detect threats and unwanted behaviors on enrolled computers.
-
Many analytics are based on the MITRE ATT&CK® Matrix for macOS.
-
Additional analytics and analytic sets can be configured if needed.
-
-
Plans are security configurations that are deployed to computers via configuration profile.
-
Plans can be viewed, created, and edited within the Plans page.
-
Plans determine which analytics, compliance results, actions, and other configurations should apply to each computer.
-
Each computer should only be assigned one plan.
-
-
Actions determine which analytics, logs, and compliance results are reported to the macOS Security portal or to an external security information and event management (SIEM) system.
-
Actions can be viewed, created, and edited on the Actions page.
-
-
Threat prevention is a built-in malware prevention and remediation tool that detects, blocks, and quarantines malicious processes on enrolled computers.
-
The Threat Prevention page contains details about past and current threat prevention versions, custom prevention list creation capabilities, and access to the Jamf Security Cloud portal for web filtering.
-
-
The macOS Security portal also contains specialized features which may be useful to different organizations, such as removable storage control and local log collection.
-
The Administrative section contains useful tools and information for administrators in the macOS Security portal.
Review
Practice
-
View how many rules are tagged with
CIS Level 1andCIS Level 2.-
Navigate to .
-
In the Filter section, click the CIS Level 1 and CIS Level 2 filter buttons.
-
-
View all new alerts.
-
Navigate to Alerts.
-
In the Filters section, remove any active filters by clicking the X on each filter.
-
In the Filter By field, choose and then .
-
Click the magnifying glass icon or press Return to enable the filter.
-
-
Verify the number of computers with the latest version of endpoint threat prevention.
-
Navigate to .
-
Find the number of computers on the latest version.
-
Resources
Jamf Protect Documentation