Preparing Jamf Protect Cloud Action and Plan Settings for Testing - Jamf Protect Evaluation Guide

Jamf Protect Evaluation Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

To test Jamf Protect Cloud's macOS Security capabilities, you need verify settings for these key features:

  • Action configurations

    Action configurations control the storage and collection of data from enrolled computers. You can define where alerts from computers are sent, such as the Jamf Protect Cloud or your SIEM/HTTPS endpoint.

  • Plans

    Plans contain comprehensive security settings that are deployed to computers as configuration profiles. Plans allow you to control how Jamf Protect agent runs on the Mac computers.

For testing purposes, you can choose to use the default action configuration and plan included with new Jamf Protect Cloud portals as a starting point, and then edit the following settings that are required for testing.

  • In the default action configuration, go to the Jamf Protect Cloud section and make sure all alert types are collected.

    This will ensure all threat detection tests are sent to the Jamf Protect Cloud as and display on the Alerts page.

  • In the default plan, configure these settings:
    1. Make sure the default action configuration is chosen from the Action Configuration pop-up menu.
    2. Set Advanced Threat Controls to Block and Report.
    3. Make sure Tamper Prevention is set to Block and Report.
    4. Make sure Endpoint Threat Prevention is set to Bock and Report.
    5. Choose an analytic set that includes all Jamf-managed analytics from the Analytic Sets pop-up menu.