Automating Security Responses with Your Threat Prevention Policy

Jamf Protect Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Jamf Protect's endpoint and network protection capabilities allow you to set up automated threat prevention policies based on the detected event type.

You can configure these automated threat prevention policies in the Jamf Security Cloud portal by navigating to Policies > Security > Threat prevention policy. Automated threat prevention policies allow you to control the actions that Jamf Security Cloud will take in the event of certain threats. These actions include blocking traffic, whereby Jamf Security Cloud would automatically block traffic associated with a particular security event at the Secure Mobile Gateway level to protect the device from being impacted.

You can also configure notifications to be sent when a particular threat category is detected. To do this, click the Alerts column for the required threat category, then select the notifications you require in the pop-up box. You can choose to send notifications to administrators, users, or both, and also specify whether notifications are sent only once for each instance of a threat, or every time it is detected.

If you were to encounter an infrastructure threat, such as an Adversary-in-the-Middle (formerly Man-in-the-Middle) attack or a Risky Hotspot on your iOS or iPadOS device, do the following:

  1. In the Jamf Security Cloud, click Policies and navigate to Security > Threat prevention policy.
  2. In the Network section, in the Auto response field for the required Threat category, select the Secure checkbox to enable failsafe encryption to automatically protect mobile traffic against the Adversary-in-the-Middle or Risky hotspots potential threats for iOS or iPadOS devices.
    Note:

    Jamf Security Cloud's Signal UEM functionality allows you to apply Conditional Access policies in a compatible UEM when a threat is detected. For more information, see Configuring Signal UEM Using Jamf Security Cloud.