Enable access for macOS Monterey

edit

[preview] This functionality is in technical preview and may be changed or removed in a future release. Elastic will work to fix any issues, but features in technical preview are not subject to the support SLA of official GA features.

To properly install and configure Elastic Defend manually without a Mobile Device Management (MDM) profile, there are additional permissions that must be enabled on the host before Elastic Endpoint—the installed component that performs Elastic Defend’s threat monitoring and prevention—is fully functional:

The following permissions that need to be enabled are required after you configure and install the Elastic Defend integration, which includes enrolling the Elastic Agent.

Approve the system extension for Elastic Endpoint
edit

For macOS Monterey (12.x), Elastic Endpoint will attempt to load a system extension during installation. This system extension must be loaded in order to provide insight into system events such as process events, file system events, and network events.

The following message appears during installation:

 getting started install endpoint system ext blocked
  1. Click Open Security Preferences.
  2. In the lower-left corner of the Security & Privacy pane, click the Lock button, then enter your credentials to authenticate.

     getting started fda lock button
  3. Click Allow to allow the Elastic Endpoint system extension to load.

     getting started install endpoint allow system ext
Approve network content filtering for Elastic Endpoint
edit

After successfully loading the Elastic Endpoint system extension, an additional message appears, asking to allow Elastic Endpoint to filter network content.

 getting started install endpoint filter network content
  • Click Allow to enable content filtering for the Elastic Endpoint system extension. Without this approval, Elastic Endpoint cannot receive network events and, therefore, cannot enable network-related features such as host isolation.
Enable Full Disk Access for Elastic Endpoint
edit

Elastic Endpoint requires Full Disk Access to subscribe to system events via the Elastic Defend framework and to protect your network from malware and other cybersecurity threats. To enable Full Disk Access on endpoints running macOS Catalina (10.15) and later, you must manually approve Elastic Endpoint.

The following instructions apply only to Elastic Endpoint version 8.0.0 and later. To see Full Disk Access requirements for the Endgame sensor, refer to Endgame’s documentation.

  1. Open the System Preferences application.
  2. Select Security and Privacy.

     getting started fda sec privacy pane
  3. On the Security and Privacy pane, select the Privacy tab.
  4. From the left pane, select Full Disk Access.

    Select Full Disk Access
  5. In the lower-left corner of the pane, click the Lock button, then enter your credentials to authenticate.
  6. In the Privacy tab, confirm that ElasticEndpoint AND co.elastic.systemextension are selected to properly enable Full Disk Access.

     getting started fda select endpoint ext

If the endpoint is running Elastic Endpoint version 7.17.0 or earlier:

  1. In the lower-left corner of the pane, click the Lock button, then enter your credentials to authenticate.
  2. Click the + button to view Finder.
  3. Navigate to /Library/Elastic/Endpoint, then select the elastic-endpoint file.
  4. Click Open.
  5. In the Privacy tab, confirm that elastic-endpoint AND co.elastic.systemextension are selected to properly enable Full Disk Access.

     getting started fda fda 7 16