Configuration profile for Kaspersky Endpoint Security 11 for Mac
- Kaspersky Endpoint Security 11.2.0 for Mac (version 11.2.0.185)
- Kaspersky Endpoint Security 11.1.0 for Mac (version 11.1.0.210)
The guide below is only applicable to JAMF- and macOS servers. For other servers, use this guide.
Before the remote installation of Kaspersky Endpoint Security for Mac, do the following:
- For version 11.1.0, download the KES_11_profile.zip archive. Extract and apply the configuration profile KES_11_profile.mobileconfig using the JAMF remote administration tool.
- For version 11.2.0:
- Download the KES_11.2_ARM_profile.zip archive for devices with ARM architecture (M1). Extract and apply the configuration profile KES_11.2_ARM_profile.mobileconfig.
- Download the KES_11_profile.zip archive for devices with 64-bit systems. Extract and apply the configuration profile KES_11_profile.mobileconfig using the JAMF remote administration tool.
This will give the application:
- Permission to install System Extensions and Network Extensions (Network Content Filtering) that are necessary for the successful installation of the application
- Full Disk Access for the correct operation of File Threat Protection
The configuration profile does not give permission to install the root certificate that is required to intercept HTTPS traffic. This permission can only be obtained locally on the device.
The configuration profile has settings that can be performed only via User Approved Mobile Device Management (UAMDM). When you apply the configuration profile locally on the device, the following error occurs: "Profile installation failed. The profile must be a system profile. User profiles are not supported.” To avoid the error, use the remote management tool.
How to create configuration profile for Kaspersky Endpoint Security for Mac by yourself
If you want to create a configuration profile for Kaspersky Endpoint Security for Mac by yourself, set the following settings:
Privacy Preferences Policy Control
/Library/Application Support/Kaspersky Lab/KAV/Binaries/kav
Identifier Type
Path
Code Requirement
identifier kav and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "2Y8XE5CQ94"
App or Service
SystemPolicyAllFiles
Allow
Identifier
com.kaspersky.kav
Identifier Type
Bundle ID
Code Requirement
identifier "com.kaspersky.kav" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "2Y8XE5CQ94"
App or Service
SystemPolicyAllFiles
Allow
Identifier
com.kaspersky.kav.sysext
Identifier Type
Bundle ID
Code Requirement
identifier "com.kaspersky.kav.sysext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "2Y8XE5CQ94"
App or Service
SystemPolicyAllFiles
Allow
Approved Kernel Extensions
2Y8XE5CQ94
System Extensions
Allowed System Extensions
Team Identifier
2Y8XE5CQ94
Allowed System Extensions
com.kaspersky.kav.sysext
VPN
Kaspersky Filter
VPN Type
VPN
Connection Type
Custom SSL
Identifier
com.kaspersky.sysextctrld
Server
localhost
Provider Bundle Identifier
com.kaspersky.kav.sysext
User Authentication
Password
Password
Empty
Provider Type
App-proxy
Include All Networks
Unset
Exclude Local Networks
Unset
Provider Designated Requirement
identifier "com.kaspersky.kav.sysext" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists / and certificate leaf[field.1.2.840.113635.100.6.1.13] / exists */ and certificate leaf[subject.OU] = "2Y8XE5CQ94"
Enable VPN on Demand
Unset
Prohibit users from disabling on-demand VPN settings
Unset
Idle Timer
Do not disconnect
Proxy Setup
None
What to do if you experience any issues
If you experience any issues with the configuration profile, submit a request to Kaspersky Technical Support via Kaspersky CompanyAccount. Please include a detailed description of the issue. Before sending a request, read the required information in the Knowledge Base section.