Scoping the Remediation Policy for Compliance Scripts

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

The following policy remediates rules not controlled by a configuration profile

  1. In Jamf Pro, click Computers in the sidebar.
  2. Click Policies in the sidebar.
  3. Click New .
  4. In the General tab, perform the following:
    1. In the Display Name field, enter Sonoma_CIS Level 1_Remediation.
    2. Select Enabled.
    3. In Trigger, select Recurring Check-in.
    4. In Execution Frequency, select Ongoing.
  5. In the Scripts tab, perform the following:
    1. Click Configure.
    2. Find Ventura_cis_lvl1_compliance.sh and click Add.
    3. In Parameter 4, enter --check.
    4. In Parameter 5, enter --fix.
  6. In the Maintenance tab, click Configure and select Update Inventory.
  7. Click the Scope tab and select Sonoma_CIS_LVL1_NotCompliant as the selected deployment target.
  8. Click Save .
You can use the Jamf Protect Compliance Baseline Summary to monitor rules in your baseline in Jamf Protect.