Global Security & Compliance policies

Table of Contents

These are the Global Security & Compliance policies in Campus Jamf that run when the Jamf client checks-in:


Policy

Purpose

Frequency

Exceptions Group

GLOBAL - Nessus agent install/link/status

Installs the ISO required Nessus Agent if not installed, returns status if already installed.

Once every day, if Enrollment > 1 day
 

GLOBAL - Exceptions - Nessus Agent

GLOBAL - Nudge Install Only

Installs Nudge for prompting the user to install MacOS updates

Ongoing, if (Enrollment > 3 days and Nudge is Not Installed)

GLOBAL - Exceptions - Nudge

GLOBAL - Schedule Nudge - run nudge binary

Sets up a LaunchDaemon to ensure Nudge runs regularly

Ongoing, if Nudge is Installed

GLOBAL - Exceptions - Nudge

GLOBAL - UTexas Acceptable Use Policy Banner

Installs a banner to display the UT Austin acceptable use policy, required by the ISO

Once per computer

GLOBAL - Exceptions - UTexas Acceptable Use Policy Banner

GLOBAL - UTexas Shared Packet Firewall install

Installs the standard configuration for the macOS PF packet firewall

Once per computer, if Enrollment > 1 day

GLOBAL - Exceptions - UTexas Packet Firewall

GLOBAL - Microsoft Defender - Install Package

Installs Microsoft Defender, if the site has run a policy to cache the installer and the config profiles are in place

Once per computer, if Defender is Cached

GLOBAL - Exceptions - Microsoft Defender

GLOBAL - Microsoft Defender - Stage Installation

Runs Jamf Recon to ensure the Defender config profiles are in place.

Ongoing

GLOBAL - Exceptions - Microsoft Defender

GLOBAL - Block UTGuest WifiBlocks utguest wifi networkOn Network ChangeGLOBAL - Exceptions - UTGuest Wireless Network Blocked



Exceptions:


Each GLOBAL - Exceptions - FUNCTION group includes a SITE - Exceptions - FUNCTION group in your site which will exclude computers based on the value of EA "Exception-FUNCTION"


Example:

ENGR - Exceptions - Nudge

uses Extension Attribute: Exception-Nudge


To exclude a device from the Nudge global policies, set the value of Exception-Nudge to "Yes"

Leave Exception-Nudge blank or set to "No" to not be excluded


Since the exception group is in your Site you can edit it to add other criteria if needed.


Screen Saver


Using the standard Global configuration profiles, Screen Saver settings are controlled by EA "Screen Saver".  It can have a value of 15m, 30m, 60m, 120m, or Unconfigured
Using "Unconfigured" means the screen saver can be turned off or set to any timeout on each computer.

To be excluded from ALL Screen Saver configuration settings, set Extension Attribute "Exception-Screen Saver" to "Yes" or edit SITE - Exceptions - Screen Saver if needed.


------------------------------


The following policy runs at Check-In, but does not have an exceptions group.  It is for creating 'inventory.plist' on each Mac in /Library/Application Support/utexas, storing  information from Jamf such
as Site, Asset Tag, Assigned User, Department Code to be used by policies with scripts, including Provisioning, Nessus, Code42 and more.


Policy

Frequency

Exceptions Group

GLOBAL - EA-inventory-plist

Once every day

(none)