Add Security & Privacy Profile
Having covered the difference between a profile targeting the whole device or the specific user, you'll now create a device profile to manage Security and Privacy features within macOS. In this specific example, you'll configure the software update delay and Gatekeeper settings.
1. Add a macOS Device Profile
In the Workspace ONE UEM console:
- Select Devices
- Select Profiles & Resources
- Select Profiles
- Select Add
- Select Add Profile
2. Select Profile Platform
3. Select the Profile Context
Click Device Profile.
4. Profile General Settings
- Select General if it is not already selected.
macOS Security Privacyfor the profile name.
- Select Auto for the Assignment Type.
- Scroll down to view the Smart Groups field, and click in the search box. This will pop-up the list of created Smart Groups. Enter
All Devicesand select the All Devices ([email protected]) group.
5. Configure Security and Privacy Payload
Securityin the Profile search bar.
- Select Security & Privacy.
- Click Configure.
6. Review Security and Privacy Payload Settings
- Select the Delay Updates check box
- Set the delay to 90 days
- Select Mac App Store and Identified developers
- Check the box for Do not allow user to override Gatekeeper setting
- Click SAVE AND PUBLISH
Note: The delay starts from the day the update is released. For example, if Apple publishes an update and the device is offline for the first 30 days the update is released, a 90-day update delay period would end 60 days later (even though technically the device has only known about the update for 60 days).
8. Review Security and Privacy Settings
Return to the enrolled macOS device:
- Click the Apple logo
- Click System Preferences
- Click Security & Privacy
9. Review Gatekeeper Settings
- Click General
- Click the lock to make changes
- Enter the user's password on the device. If this is a VMworld provided device, enter
VMware1!as the administrator password
- Click Unlock
- Note you're still unable to make changes to the Gatekeeper settings as these are controlled by Workspace ONE UEM.