Deploying the macOS Agent via Intune

Table of contents


Introduction

This article will assist you in setting up and deploying the macOS Field Effect MDR agent using Intune


Requirements

For this procedure, you’ll need to: 


For more on downloading installers, see The Downloads Page


The table below describes each Intune profile you will need to create - and what they are used for. It also provides the location within the macOS installer bundle (available on the Downloads Page).


Profile NameProfile TypeDescriptionInstaller Bundle Location
Field Effect MDR LicensePreferenceThis profile contains the actual license.co file.\macos\intune\covalence_license.plist
MDR System ExtensionExtensionsThis profile is specifically responsible for the extension.\mdm\macos\generic\covalence_sysext.mobileconfig
MDR Full Disk AccessCustomThis profile allows Field Effect MDR full access for monitoring. \mdm\macos\generic\convalence_ttc.mobileconfig


Create the Intune Profiles

Begin by navigating to Home > macOS > Configuration profiles. From this page, click + create profile and create the profiles outlined in the table above.


 

Create Profile: Field Effect MDR License

Follow the steps below to create a preference profile named “Field Effect MDR License” and add the contents of the macOS installer bundle's licensing plist file (macos/intune/covalence_license.plist) to it.

  1. In Intune, go to Devices, and under Manage Devices, select Configuration.
  2. Under Configuration profiles, select Create Profile.
  3. On the Policies tab, select Create > New Policy.
  4. Under Platform, select macOS.
  5. Under Profile type, select Templates.
  6. Select Preference File, and select Create.
  7. On the Basics tab, Name the profile and enter a Description. Then select Next.
  8. On the Configuration settings tab, select device for the Deployment Channel.
  9. For the bundle name, enter “com.fieldeffect.covalence”.
  10. For the Configuration profile file, upload the "mdm/intune/covalence_license.plist" file.
  11. On the Assignments tab, assign the profile to a group where the macOS devices or users are located.
  12. Review the configuration profile. Select Create.



Create Profile: MDR System Extension

Follow the steps below to create an extensions profile named “Field Effect System Extension” and add the contents of the macOs installer bundle's mobilconfig file (macos/generic/covalence_sysext.mobileconfig) to it.

  1. In Intune, go to Devices, and under Manage Devices, select Configuration.
  2. Under Configuration profiles, select Create Profile.
  3. On the Policies tab, select Create > New Policy.
  4. Under Platform, select macOS.
  5. Under Profile type, select Settings catalog.
  6. Select Create.
  7. On the Basics tab, Name the profile and enter a Description. Then select Next.
  8. On the Configuration settings tab, select + Add settings.
  9. Under Template name, select Extensions.
  10. In the Settings picker, expand the System Configuration category, and then select System Extensions > Allowed System Extensions:
  11. Close the Settings picker, and then select + Edit instance.
  12. Configure the following entries in the Allowed system extensions section, and then select Next. 
  13. Expand the table and input the following: 
    1. Allowed System Extensions: com.fieldeffect.covalence.esext
    2. Team identifier: KSBE8M6M6F

  14. On the Assignments tab, assign the profile to a group where the macOS devices or users are located.
  15. Review the configuration profile. Select Create.


Create Profile: MDR Full Disk Access

Use the steps below to create a custom profile named “Field Effect Full Disk Access” and add the contents of the macOS installer bundle's mobilconfig file (macos/generic/covalence_tcc.mobileconfig) to it.

  1. In Intune, go to Devices, and under Manage Devices, select Configuration.
  2. Under Configuration profiles, select Create Profile.
  3. On the Policies tab, select Create > New Policy.
  4. Under Platform, select macOS.
  5. Under Profile type, select Templates.
  6. Select Custom, and select Create.
  7. On the Basics tab, Name the profile and enter a Description. Then select Next.
  8. On the Configuration settings tab, select device for the Deployment Channel.
  9. For the Configuration profile file, upload the "mdm/generic/covalence_tcc.mobileconfig" file.
  10. On the Assignments tab, assign the profile to a group where the macOS devices or users are located.
  11. Review the configuration profile. Select Create.


Full Disk Access granted through Apple MDM Configuration Profile is not reflected in System Settings > Privacy & Security > Full Disk Access. It does not show items that have that access granted via an MDM deployed Configuration Profile. 



 

Deploying Agents to Endpoints

Navigate to Home > Apps and add the MDR macOS .pkg as a macOS Line-of-Business (LOB) app.



Upload the provided .pkg installer (accessible via the Field Effect MDR Portal) to Intune as the app package file.


Use the settings outlined in the image below for your Field Effect MDR Intune app. After configuring the settings of your MDR Intune App, click Next.



You’ll be taken to the assignments page, where you can assign which groups, users, and devices will receive updates via Intune. After making your assignments, click Next.



Review the configuration for your app, and when ready, click Create. This will create the app in Intune and begin deploying the agent to your assigned group, users, and devices.




Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article