Configuring Jamf and MDM configuration profiles

The deployment of the agent on a macOS machine requires a software management tool such as Jamf. Jamf is a centralized device management system for macOS and iOS, using the MDM technology.

To deploy the MDM configuration profile, it must be imported into the MDM server (usually Jamf) in advance, prior to the agent installation, and installed on the user computer.

The MDM configuration profile parameters are as displayed in the following table. An MDM profile with correct settings is mandatory and a prerequisite for a successful agent installation.

Table 1. MDM configuration profile parameters
Bundle ID Service
com.forcepoint.neo.agent Accessibility
com.forcepoint.neo.agent AppleEvents
com.forcepoint.neo.agent SystemPolicyAllFiles
com.forcepoint.neo.protectiond SystemPolicyAllFiles
com.forcepoint.neo.commond SystemPolicyAllFiles
com.forcepoint.neo.privilege-helper SystemPolicyAllFiles
com.forcepoint.neo.log-collector SystemPolicyAllFiles
/Library/Application Support/Websense Endpoint/EPClassifier/EndPointClassifier SystemPolicyAllFiles
Table 2. MDM configuration system extensions
Bundle ID Type Team ID (for system extensions)
com.forcepoint.neo.es SystemPolicyAllFiles  
com.forcepoint.neo.es-app SystemPolicyAllFiles  
com.forcepoint.neo.ne-app SystemPolicyAllFiles  
com.forcepoint.neo.ne SystemPolicyAllFiles  
com.forcepoint.neo.es AllowedSystemExtensions 4388XWHPGW
com.forcepoint.neo.ne AllowedSystemExtensions 4388XWHPGW
com.forcepoint.neo.ne-app VPNType - VPN,ProviderType - app-proxy 4388XWHPGW
com.forcepoint.neo.ne-app AllowedSystemExtensions 4388XWHPGW