You must create two Jamf Pro policies that runs the compliance script uploaded from the Jamf Compliance Editor (in this example called Sonoma_cis_lvl1_compliance.sh). The first policy audits baseline rules within the benchmark.
- In Jamf Pro, click Computers in the sidebar.
- Click Policies in the sidebar.
- Click New .
- In the General tab, perform the following:
- In the Display Name field, enter Sonoma_CIS Level 1_Audit.
- Select Enabled.
- In Trigger, select Recurring Check-in.
- In Execution Frequency, select Once every day.
- In the Scripts tab, perform the following:
- Click Configure.
- Find Ventura_cis_lvl1_compliance.sh and click Add.
- In Parameter 4, enter --check.
- In the Maintenance tab, click Configure and select Update Inventory.
- Click the Scope tab and select Computers running macOS Sonoma as the selected deployment target.
- Click Save .