Safelisting Kernel Extensions in Jamf School

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
  1. In Jamf School, navigate to Profiles > Overview in the sidebar.
  2. Create a new macOS profile and scope the profile to devices that are enrolled using User Approved Enrollment. For information, see Device Profiles.
  3. Using the Kernel Extension Loading payload, click Configure.
  4. Enter all Team IDs and/or Bundle IDs you want to safelist. A kernel extension can be safelisted by specifying one of the following:
    • The Team Identifier that signed the kernel extension. For example: EG7KH642X6

    • The Team Identifier and Bundle Identifier of a specific kernel extension, separated with a comma. For example: EG7KH642X6 and com.vmware.kext.vmnet,com.vmware.kext.vmci

    • Only the Bundle Identifier of a specific, un-signed kernel extension as shown in the image below.