The following policy remediates rules not controlled by a configuration profile
- In Jamf Pro, click Computers in the sidebar.
- Click Policies in the sidebar.
- Click New .
- In the General tab, perform the following:
- In the Display Name field, enter Sonoma_CIS Level 1_Remediation.
- Select Enabled.
- In Trigger, select Recurring Check-in.
- In Execution Frequency, select Ongoing.
- In the Scripts tab, perform the following:
- Click Configure.
- Find Ventura_cis_lvl1_compliance.sh and click Add.
- In Parameter 4, enter --check.
- In Parameter 5, enter --fix.
- In the Maintenance tab, click Configure and select Update Inventory.
- Click the Scope tab and select Sonoma_CIS_LVL1_NotCompliant as the selected deployment target.
- Click Save .