Windows Agent Metered Network Settings - Jamf Security Cloud Portal Setup Guide

Jamf Security Cloud Portal Setup Guide

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Note:

This configuration does not apply to Jamf security services that operate across any network interface, such as Jamf Connect's Zero Trust Network Access and Jamf Protect's endpoint and network security service.

You can define which networks should be considered "metered" by Jamf for any Windows devices. In Jamf Security Cloud, navigate to Policies > Internet > Windows Metered Networks. Jamf security policies will apply to any network defined here.

Metering Rules

In the Metering Rules section, you can select the option to automatically consider any Windows device that is tethering off an iOS or iPadOS hotspot as metered.

By default, all network connections are metered. This means that custom metering rules will not apply to Windows devices. If you want all networks to be unmetered, deselect the Treat all networks as metered by default checkbox. This means that custom metering rules apply to Windows devices.

You can define all other rules under the Custom Metering Rules section.

Custom Metering Rules

The Custom Metering Rules section allows you to define exactly which networks should be monitored and managed by Jamf.

You can define a number of criteria using All, Any, and OR rules. The following can be used to define Custom Metering Rules:

  • SSID

    The visible network name of the wireless network to which you're connecting

  • BSSID

    The MAC address of the wireless network to which you're connecting

  • ICCID

    (Integrated Circuit Card Identifier) The unique serial number of a SIM card

  • Adapter Name

    The name of an internal network interface

  • Adapter Description

    The description of an internal network interface

  • Physical Address

    MAC address of the internal interface

  • Adapter IP

    The internal IP address

  • DNS IP Address

    The DNS address set on the device. In most circumstances this is defined by the network to which the user is connecting, but it can also be set manually on the device.

  • Physical Medium

    The physical type of interface that the device is connecting with. Select from the pre-defined list of options, such as WirelessWan for internal SIM cards.

Note:

Jamf recommends that you create the following rule to treat all connections through a built-in SIM as metered networks:

Physical Medium - is - NdisPhysicalMediumWirelessWan

After you have configured the rules, click Save to confirm. All settings and changes will start applying to all your deployed devices, without requiring any end-user interaction.