Enabling Tamper Prevention with Jamf Protect

Jamf Protect Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Tamper prevention is enabled by default in new plans. For plans that existed prior to the release of tamper prevention, tamper prevention is disabled and needs to be manually enabled.

Important:

An additional configuration profile needs to be installed on target computers running macOS 15 or later, in order to make the Jamf Protect agent a non-removable system extension. For more information see Making Jamf Protect a Non-Removable System Extension.

Requirements
  • macOS 13 or later

  • Jamf Protect 5.1.2 or later

  • Jamf Protect running as a system extension as approved through your MDM

  • System Integration Protection (SIP) enabled on the target computer

    Note:For more information on enabling SIP, see System Integrity Protection.
  1. In Jamf Protect, click Plans.
  2. Navigate to an existing plan and edit the plan, or create a new plan.
  3. Under Legacy, click Edit legacy features.
  4. Configure Tamper Prevention settings.
    1. Choose Block and report to prevent unauthorized changes to Jamf Protect's application.
    2. Choose Disable to disable all prevention of unauthorized changes considered tampering to Jamf Protect's application.
  5. Click Save.
After enabled inside a plan, Tamper Prevention deploys protections to computers the next time they connect to the Jamf Protect Cloud.