Malware Prevention via Jamf Protect Integration

Use Malware Prevention on macOS to detect, block, and quarantine malicious processes. Malware Prevention uses the Jamf Protect threat database, an extensive repository of signatures and certificate information associated with known macOS malware or problematic developer reputations, to monitor processes at the time of their launch. When a threat is identified, Jamf Protect automatically blocks the process and quarantines the associated application.

A prompt about the blocked process is displayed to end users, such as: "This software has been identified as a malicious or potentially unwanted program. It has been blocked, moved to quarantine, and reported to your IT administrator." You can view the status of your Jamf Protect configuration on a device from its device dashboard. Start securing your computers with Jamf Protect by enabling it in Blueprints.

Deploying Jamf Protect to Enable Malware Prevention on Target Computers

  • To use this feature, you need to be on the Jamf Fundamentals plan. To view or edit your plan, click on your account name, and then navigate to Account > Plan section.

  • Target computers must be macOS 10.15 or later.

  1. Log in to Jamf Now.
  2. Click Blueprints.
  3. Click on the Blueprint you want to edit.
  4. Click Security.
  5. Select the Enable Malware Prevention with Jamf Protect checkbox.
  6. Click Save Changes.
Malware Prevention is installed on all Mac computers associated with the selected Blueprint.

Uninstalling Jamf Protect

To uninstall Malware Prevention from devices, deselect the Enable Malware Prevention with Jamf Protect checkbox in the appropriate Blueprint. This removes the Jamf Protect profile and the Jamf Protect agent from all Mac computers associated with the Blueprint.