Create a Device Level Mac System Extension Policy

The MacOS System Extension policy lets you pre-approve specific System Extensions before they are installed. System Extensions run in the user space, rather than in the kernel space like Kernel Extensions do. System Extensions are an important way to support Mobile Device Management (MDM) because they allow extensions to load without user interaction. 

Note:

MacOS 15 Sequoia will disable the option to toggle system extensions under System Settings > General > Login Items & Extensions > Endpoint Security Extensions for end users.

Prerequisites

  • Apple Mobile Device Management (MDM) must be configured for your organization and Mac computers must be enrolled in JumpCloud MDM. See Set up Apple MDM
  • Target Mac computers must have an active network connection for this policy to take effect.

Considerations

  • The policy configuration settings are applied automatically and do not require a system restart.

Creating the Policy

To create a System Extension Policy policy for Mac computers, do the following:

Selecting the Policy Template

  1. Log in to the JumpCloud Admin portal.

Important:

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Device Management > Policy Management. The Policy Management page is displayed.
  2. On the Policy Management page, click +Add New.
  3. Select Device Policy to assign the policy to devices and device groups. On the New Device Policy page:
    • Select the macOS tab.
    • Search and select the required policy and click Configure. The Details tab of the policy is displayed.
    • On the Details tab, configure the required policy configuration settings.
    • (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
    • (Optional) In the Policy Notes field, enter details such as creation date of the policy, and information on testing and deployment of the policy.

Configuring the Policy

  • Enter your application’s Apple Team ID for the System Extension you want to preapprove. For instructions on locating your Team ID and Bundle ID, see Create a Mac Application Privacy Preferences Policy.
  • Click Add Bundle ID and enter the unique identifier for the System Extension you want to preapprove. For example, com.webfilter_cloud.se-agent.extension.
  • Select Security Extension to preapprove Endpoint Security Framework as the extension type for this app. For example, an antivirus software app can monitor system events to improve security.
  • Select Driver Extension to preapprove Hardware Driver Framework as the extension type for this app. For example, a driver for USB or Serial devices can perform installations.
  • Select Network Extension to preapprove Network Extension Framework as the extension type for this app. Examples include a content filter, DNS proxy, or VPN client and require the following fields:
    • Filter Data Provider Bundle ID - Enter the unique identifier for the Data Provider included in your System Extension. Locate this identifier by consulting the documentation for your System Extension. For example, com.webfilter_cloud.se-agent.extension.
    • Filter Data Provider Designated Requirement - Paste the code block for the Data Provider included in your System Extension. To locate the code block, see Create a Mac Application Privacy Preferences Policy.
    • Filter Grade - Click this field and choose the priority of your filter. Firewall grade traffic is reviewed before Inspector grade traffic.
  • Select Filter Packets to let the System Extension monitor inbound and outbound packet traffic.
  • Select Filter Sockets to allow the System Extension to monitor inbound and outbound socket traffic.
  • Click Filter Type and choose the type of filter you’ll use. Plugin is the most common filter type.
  • For Organization, enter your Organization name if your app requires it.
  • For Plugin Bundle ID, enter the unique identifier for the app included in your System Extension. Locate this identifier by consulting the documentation for your System Extension. For example, com.webfilter_cloud.se-agent.extension. Locate this identifier by consulting the documentation for your System Extension.

Applying the Policy

  • (Optional) Select the Policy Groups tab. Select one or more policy groups where you want to add this policy. 
  • Select the Device Groups tab. Select one or more device groups where you want to apply this policy. For device groups with multiple OS member types, the policy only applies when a user logs into a supported Mac computer that is enrolled in Apple MDM.
  • Or, select the Devices tab. Select one or more devices whom you want to add this policy to.
  • Click Create Policy. A success message is displayed indicating the completion of policy creation.

Viewing Policy Status

  1. Select the Status tab.
  2. To see the last Result Log for a device where this policy is applied, click view.

Note:
  • If any errors occur, they're listed in Exit Status. If you have an Exit Status of 0, no errors occurred when applying or enforcing this policy.
Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case