Download PDF
GlobalProtect
Enable Kernel Extensions in the GlobalProtect App for macOS Endpoints
Table of Contents
Expand All
|
Collapse All
GlobalProtect Docs
-
-
-
-
- 6.3
- 6.2
- 6.1
- 6.0
-
- 6.3
- 6.2
- 6.1
- 6.0
Enable Kernel Extensions in the GlobalProtect App for macOS Endpoints
| Where Can I Use This? | What Do I Need? |
|---|---|
|
|
Starting with macOS 10.13, Apple introduced
a software change that requires users to approve kernel extensions
before they can use them.
While users can manually enable
the kernel extension on macOS (System PreferencesSecurity & Privacy and
selecting Allow for the kernel extension),
you can use any Qualified MDM vendor to
create a policy and automatically approve the kernel extension. Apple Technical Note TN2450 describes
the process.
The following workflow has been tested using Workspace ONE.
- Create a kernel extension policy.
- Log in to Workspace ONE UEM as an administrator.Select DevicesProfiles & ResourcesProfiles, and then select AddAdd Profile from the drop-down.In the Add Profile area, click Apple macOS, and then click the Device Profile icon.In the General area, specify the name for the profile.You can also select an existing kernel extension profile (DevicesProfiles & ResourcesProfiles) in the list.Add a kernel extension and distribute the relevant policy to macOS devices.
- Select Kernel Extension Policy.Enter the Team Identifier used by the GlobalProtect app (PXPZ95SK77).Enter the Bundle ID (com.paloaltonetworks.kext.pangpd).
Click Save and Publish to save your changes.