Issue:
How to deploy Elements EPP for Computers (Mac) using Intune?
Resolution:
You could follow the instructions below in order to deploy Elements EPP for Computer (Mac) using Intune to your Mac devices.
Note: Make sure that you have added your Mac devices to the Intune Company Portal before proceeding with this deployment. You may refer to the following Microsoft page for more details.
https://learn.microsoft.com/en-us/mem/intune/user-help/enroll-your-device-in-intune-macos-cp
1. Login to Microsoft Intune admin center (https://intune.microsoft.com/#home)
2. Create a new group by following the steps below
2.1. Go to "Groups"
2.2. Click on "New Group"
2.3. Select "Security" for the Group Type
2.4. Enter the name of the group at "Group Name"
2.5. Leave other settings as default
2.6. Click on "No members selected" link
2.7. Search for your Mac devices
2.8. Put a tick to select all Mac devices
2.9. Click on "Select" button at the bottom
2.10. Click on "Create" button to proceed with new group creation
Note: You may skip creating a new group if there is an existing group for your Mac devices on Intune portal.
3. Create a new profile to allow WithSecure system extensions and etc
Note: It is recommended to create the configuration profiles within Intune rather than using a separate Preference file (*.plist).
In case of WithSecure system extensions:
3.1. Go to "Device"
3.2. Click on "Configuration profiles"
3.3. Click on "Create profile"
3.4. Select "macOS" for Platform
3.5. Select "Templates" for Profile Type
3.6. Choose "Extensions" from the list
3.7. Click on "Create" button
3.8. Enter the Name and Description
3.9. Click on "Next"
3.10. Under "Configuration settings", click on "System extensions"
3.11. Enter "V928P8X763" for "Team identifier"
3.12. Click on "Next" button
3.13. Under "Included groups", click on "Add groups"
3.14. Select your group from the list and click "Select" button
3.15. Click on "Next" button
3.16. Click on "Create" button
In case of Content Filtering:
3.1. Go to "Device"
3.2. Click on "Configuration profiles"
3.3. Click on "Create profile"
3.4. Select "macOS" for Platform
3.5. Select "Settings catalog" for Profile Type
3.6. Enter the Name and Description
3.7. Click on "Next"
3.8. Under "Configuration settings", click on "Add settings" link
3.9. Search for "Web Content Filter" from the list of category
3.10. Select the following settings and configure them as below
Filter Data Provider Bundle Identifier : com.withsecure.wsagent.wssystemextension
Plugin Bundle ID : com.withsecure.wsagent
User Defined Name : any name (for example, WithSecure Element Content Filter)
Filter Grade : firewall
Filter Data Provider Designated Requirement :
identifier "com.withsecure.wsagent.wssystemextension" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "V928P8X763"
User Name : any name (for example, WithSecure Element Content Filtering)
Filter Sockets : True
Filter Type : Plug-in
3.10. Close the "Settings picker" page by clicking on "X" button at the top right corner
3.11. Click on "Next" button
3.12. Under "Scope tags", click on "Next" button again
3.13. Under "Included groups", click on "Add groups"
3.14. Select your group from the list and click "Select" button
3.15. Click on "Next" button
3.16. Click on "Create" button
In case of Full Disk Access:
3.1. Go to "Device"
3.2. Click on "Configuration profiles"
3.3. Click on "Create profile"
3.4. Select "macOS" for Platform
3.5. Select "Templates" for Profile Type
3.6. Choose "Device restrictions" from the list
3.7. Click on "Create" button
3.8. Enter the Name and Description
3.9. Click on "Next"
3.10. Under "Configuration settings", click on "Privacy preferences"
3.11. Click on "Add" button
3.12. Enter "WithSecure Elements" for "Name" setting
3.13. Select "Bundle ID" for "Identifier Type"
3.14. Enter "com.withsecure.wsagent" for "Identifier"
3.15. Add the following information to "Code requirement"
identifier "com.withsecure.wsagent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "V928P8X763"
3.16. Select "Allow" for "Full Disk Access"
3.17. Click on "Save" button
3.18. Click on "Next" button
3.19. Under "Included groups", click on "Add groups"
3.20. Select your group from the list and click "Select" button
3.21. Click on "Next" button
3.22. Click on "Create" button
In case of User Notifications:
3.1. Go to "Device"
3.2. Click on "Configuration profiles"
3.3. Click on "Create profile"
3.4. Select "macOS" for Platform
3.5. Select "Settings catalog" for Profile Type
3.6. Enter the Name and Description
3.7. Click on "Next"
3.8. Under "Configuration settings", click on "Add settings" link
3.9. Search for "User Experience" > "Notifications" in the list of category
3.10. Click on "Select all these settings" button
3.11. Close the "Settings picker" page by clicking on "X" button at the top right corner
3.12. Click on "Edit instance"
3.13. Enter "com.withsecure.wsagent" for "Bundle Identifier"
3.14. Click on "Save" button at the bottom
3.15. Click on "Next" button
3.16. Under "Scope tags", click on "Next" button again
3.17. Under "Included groups", click on "Add groups"
3.18. Select your group from the list and click "Select" button
3.19. Click on "Next" button
3.20. Click on "Create" button
4. Deploy Elements EPP for Computers (Mac) to your Mac devices
4.1. Go to "Apps"
4.2. Select "macOS" from the list of available platforms
4.3. Click on "Add" button
4.4. Select "Line-of-business app" for App type
4.5. Click on "Select" button at the bottom
4.6. Click on "Select app package file" link
4.7. Click on "Select a field" field
4.8. Search for the installer file (*.pkg) of Elements EPP for Computer (Mac)
Note: There is a need to change the file extension of the installer from *.mpkg to *.pkg so that it would be recognized by Intune.
4.9. Click on "OK" button
4.10. Enter Name, Description and Publisher (use "WithSecure" in this case) for App Information
4.11. Select "macOS Monterey 12.0" for the Minimum operating system
4.12. For the Included apps, maintain just the below bundle IDs and remove the rest of the unnecessary items
com.withsecure.wsagent 3.0.52332
Note: 3.0.52332 indicates a build version, it is recommended to always use the latest build version
4.13. Leave other setting as default and click on "Next" button
4.14. Under Required category, click on "Add group"
4.15. Select your group from the list and click "Select" button
4.16. Click on "Next" button
4.17. Click on "Create" button
Note: It may take some time before Elements EPP for Computers (Mac) is being deployed to your mac devices silently in the background.
Article no: 000043088