Deploy the Endpoint DLP configuration profile to pre-authorize DLP system extensions
on managed macOS endpoints.
| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Strata Cloud Manager)
- Prisma Access (Managed by Panorama)
- NGFW (Managed by Panorama)
|
- Check the prerequisites for the deployment you're
using
- Prisma Agent
- macOS endpoints managed by Microsoft Intune
- Endpoint DLP license
|
Endpoint DLP inspects and protects
sensitive data by deploying two system extensions alongside the
Prisma Agent: an endpoint security extension
(
com.paloaltonetworks.pangdlp.enforcer) and a network filter
extension (
com.paloaltonetworks.pangdlp.netfilterdlp). macOS
requires that system extensions be authorized by MDM before the installer runs;
without this authorization, macOS prompts users to approve each extension
manually.
The Endpoint DLP configuration profile pre-authorizes these extensions, grants full
disk access to DLP processes, and configures the DLP content filter. Deploy this
profile to your target device groups before running the Prisma Agent
installer.