Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Terminal Servers
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Configuring Policies
    2. Consents
    3. PII Protection
    4. Time-Based Policy
    5. Malvertising Protection
    6. Login Guard
  • Secure Access (ZTNA)
    1. Introduction to ZTNA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Deployment via Jamf Pro

In this document
  • Step 1: Download Required Files
  • Step 2: Add the Installer Script
  • Step 3: Add the Uninstaller Script
  • Step 4: Create the Agent Installation Policy
  • Step 5: Create the CA Certificate Configuration Profile
  • Step 6: Create the DNS Proxy Extension Configuration Profile
  • Step 7: Create the Customer-Specific Configuration Profile
  • Uninstalling DefensX

This guide covers deploying the DefensX Agent to macOS devices managed by Jamf Pro. The process uses shared scripts applicable to all customers, plus separate configuration profiles for the CA certificate, DNS Proxy extension, and customer-specific deployment settings.

Tip
Steps 2–6 are customer-agnostic and only need to be set up once. To deploy to a new customer or deployment, only repeat Step 7 with the corresponding mobileconfig file. For new devices under an existing customer, simply update the Scope of the existing policies and profiles.

Step 1: Download Required Files

Log in to the DefensX backend and navigate to Policies & Groups. Under the Deployments section, locate your deployment and click the RMM button.

rmm

In the RMM dialog, click Mac MDM and download the following files:

File How to Download

DefensX-installer.sh

Click Download Installer Script

DefensX-CA.mobileconfig

Click Download DefensX-CA Certificate → As mobileconfig

DefensX-DNSProxy-Extension.mobileconfig

Click DNS Proxy Extension mobileconfig

DefensX-[deployment].mobileconfig

Click Download mobileconfig

DefensX-uninstaller.sh

Click Download Uninstaller Script

Keep all files available, they are needed in the steps below.

Step 2: Add the Installer Script

  • Log in to your Jamf Pro instance.

  • Navigate to Settings → Computer Management, search for "script", and click Scripts.

    scripts
  • Click + New in the top right.

  • On the General tab, enter DefensX Install Script as the Display Name.

  • Click the Script tab, open DefensX-installer.sh in a text editor, and paste its contents into the script field.

    jamf script content
  • Click Save.

Step 3: Add the Uninstaller Script

Follow the same steps as in Step 2 to add the uninstaller script.

  • On the General tab, enter DefensX Uninstall Script as the Display Name.

  • Click the Script tab, open DefensX-uninstaller.sh in a text editor, and paste its contents into the script field.

  • Click Save.

Step 4: Create the Agent Installation Policy

This policy attaches the installer script from Step 2 and deploys it to the target computers.

  • Navigate to Computers → Policies and click + New in the top right.

  • On the General tab, enter DefensX Agent Installation as the Display Name.

  • Select a trigger — Startup, Enrollment Complete, Recurring Check-in, or another trigger appropriate for your environment.

  • Click the Scripts tab on the left, then click Configure.

  • Click Add next to DefensX Install Script.

    jamp install script select
  • Click the Scope tab and select the computers where you want to install DefensX.

  • Click Save.

Tip
It is safe to deploy the DefensX Agent before pushing the mobileconfig profiles. The agent installs and remains inactive until the configuration profile is received.

The agent will be installed within approximately 15 minutes, based on the default Recurring Check-in interval in Jamf Pro.

Step 5: Create the CA Certificate Configuration Profile

This profile deploys the DefensX Root CA certificate to managed devices.

  • Navigate to Computers → Configuration Profiles and click Upload.

    jamf profile upload
  • Click Choose File and upload DefensX-CA.mobileconfig.

  • Click the Scope tab and select the target computers.

  • Click Save.

Step 6: Create the DNS Proxy Extension Configuration Profile

This profile grants the DefensX DNS Proxy Network Extension the permissions it needs to operate without prompting users for approval. It enables DNS policy enforcement without modifying system-level DNS settings.

  • Navigate to Computers → Configuration Profiles and click Upload.

  • Click Choose File and upload DefensX-DNSProxy-Extension.mobileconfig.

  • Click the Scope tab and select the target computers.

  • Click Save.

Note

Jamf Pro does not recognize the ProviderDesignatedRequirement and PayloadEnabled keys and will display an Unknown Keys warning on the DNS Proxy section of the profile. This is expected, do not click Remove Keys button. All keys are required for the DNS Proxy extension to function correctly.

Step 7: Create the Customer-Specific Configuration Profile

This profile delivers the unique deployment key and browser settings for a specific customer. Each DefensX deployment has its own mobileconfig file containing the relevant Deployment Key.

  • Navigate to Computers → Configuration Profiles and click Upload.

  • Click Choose File and upload the DefensX-[deployment].mobileconfig file downloaded in Step 1.

  • Click the Scope tab and select the target computers.

  • Click Save.

Uninstalling DefensX

Important
Before running the uninstall script, remove the target devices from the installation policy (Step 4) and all three configuration profiles (Steps 5, 6, and 7). If devices remain in those configurations, Jamf Pro will continue reinstalling the agent and reapplying profiles.

To create the uninstall policy:

  • Navigate to Computers → Policies and click + New in the top right.

  • On the General tab, enter DefensX Agent Uninstall as the Display Name.

  • Select the desired trigger.

  • Click the Scripts tab on the left, then click Configure.

  • Click Add next to DefensX Uninstall Script created in Step 3.

  • Click the Scope tab and select the computers to uninstall DefensX from.

  • Click Save.

The uninstall script will execute on the next scheduled trigger based on your Jamf Pro configuration.

www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013