Configuring a Safelist and Blocklist Profile for Computers

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
  1. In Jamf School, navigate to Profiles > Overview in the sidebar.
  2. Click + Create Profile.
  3. Select the macOS operating system.
  4. Select the Device Enrollment enrollment type.
  5. Enter a name in the Profile name field and configure the additional settings as needed, including the time filter.
  6. Click Finish.
  7. In the list of payloads on the left side of the pane, locate the macOS payload category and click the Safelist and Blocklist payload.
  8. Click Configure.
  9. To add an application the safelist, do one of the following:
    • In the Bundle IDs of allowed applications section, click + Add Bundle ID, and then enter the bundle ID for the application.

      Example:

      com.apple.safari

    • (For macOS 10.14 or earlier only) In the Paths to allowed applications section, click + Add Path, and then enter the path to the application.

      Example:

      /System/Volumes/Preboot/Cryptexes/App/System/Applications/Safari.app

  10. (For macOS 10.14 or earlier only) To add an application to the blocklist, click + Add Path in the Paths to disallowed applications section, and then enter the path to the application.
    Example:

    /System/Volumes/Preboot/Cryptexes/App/System/Applications/Safari.app

    Note:

    Adding an application to the blocklist does not remove it from computers. If a user tries to open an application that is on the blocklist, a message displays indicating that the application cannot be opened.

  11. In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
  12. Configure the scope of the profile by clicking the + icon and adding device groups to the profile scope using the pop-up menu. For more information, see Device Groups.
  13. Click the Settings icon on the right side of the page, and do one of the following:
    • To install the profile on devices automatically, click Change to automatic installation for all groups.

    • To allow users to install the profile themselves, click Change to on-demand installation for all groups. The profile will be available for users to install in the Jamf Teacher or Jamf School Student apps.

  14. Click Save.