Requirements
When configuring applications in the Security & Privacy payload in Jamf School, you must specify the bundle ID or file path of an application as well as the code requirement to enhance the security of the payload. You can fetch an application's code requirement by executing a command similar to the following in Terminal:
codesign -display -r - /Applications/NameOfTheApp.app/
The code requirements are displayed after "designated=>".
- In Jamf School, navigate to in the sidebar.
- Click + Create Profile.
- Select the macOS operating system.
- Select the Device Enrollment enrollment type.
- Enter a name in the Profile name field and configure the additional settings as needed, including the time filter.
- Click Finish.
- In the list of payloads on the left side of the pane, locate the macOS payload category and click the Security & Privacy payload.
- Click Configure.
- Click the Privacy tab, and configure the applications allowed to access other apps or services by doing the following:
- Click Add new, and then click Select application.
- In the Application pop-up dialog, provide the application's name, identifier, type, and code requirement.
- Click Add.
- To allow the application to access the app or service, leave the Allowed checkbox selected. To deny the application access to the app or service, deselect the Allowed checkbox.
Important:For Camera and Microphones, you can only deny applications access to these services. For Listen Event and Screen Capture, you can allow only standard users to approve access to these services.
- Repeat step 9 as needed to configure more applications in the payload.
Note:Applications added to the Security & Privacy payload display at the top of the Application pop-up dialog. When configuring the applications allowed to access an app or service, you can choose an existing application by clicking its name at the top of the Application pop-up dialog.
- In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
- Configure the scope of the profile by clicking the + icon and adding device groups to the profile scope using the pop-up menu.
- Click the Settings
icon on the right side of the page, and do one of the following:To install the profile on devices automatically, click Change to automatic installation for all groups.
To allow users to install the profile themselves, click Change to on-demand installation for all groups.
The profile will be available for users to install in the Jamf Teacher or Jamf School Student apps.
- Click Save.