Skip to main content

Threatlocker Deployment - MAC

Summary

Triggers the Threatlocker Deployment [MAC] automation on macintosh machines where deployment is enabled.

Details

Name: Threatlocker Deployment - MAC
Description: Triggers the auto-deployment script for Threatlocker on Macintosh machines where deployment is enabled.

Recommended Agent Policies: It is advised to configure this compound policy within the following default agent policies:

  • Mac Server [Default]
  • Mac [Default]

Dependencies

Compound Condition Creation

Compound conditions can be configured within an Agent Policy. This document provides an example using the default Mac [Default] policy for demonstration purposes.

Navigate to Administration > Policies > Agent Policies.
Navigate

Search for Mac and select the default Mac [Default] policy.
DefaultMac

This will navigate you to the policy's landing page, which is the Conditions section.

Note that conditions may vary across different policies and environments. The provided screenshot is for demonstration purposes only.
Conditions

Navigate to the Compound Conditions section.

Note that existing compound conditions may vary across different policies and environments. The provided screenshot is for demonstration purposes only.
CompoundConditions

Click the + Add button to add a compound condition.
AddButton

Clicking the + Add button opens the compound condition creation window.
AddACompoundCondition

Conditions

Condition 1: Software

  • Click the + Add condition button.
    AddCondition

  • Select the Software option from the list that will appear after clicking the + Add condition button.
    CompoundConditionSoftware

  • Add Software Condition screen will appear on selecting the Software option:
    CompoundConditionSoftwareScreen

  • Configure the Add Software Condition as follow:

    Software Name: Threatlocker
    Trigger when: Any Software Doesn't exist

    Image1

  • Note: The Return key must be pressed after pasting the name to set the Software Name.

  • Click the Apply button to save the software condition.
    Apply

Condition 2: Custom fields

  • Click the + Add condition button.
    AddCondition

  • Select the Custom fields option from the list that will appear after clicking the + Add condition button.
    CompoundConditionCustomFields

  • Add custom fields condition screen will appear on selecting the Custom fields option:
    CompoundConditionCustomFieldsScreen

  • Click the + Add button within the upper section labeled Custom field value must meet ALL conditions.
    AddButtonCustomFields

  • A new row will be added upon clicking the + Add button.
    NewRow

  • Search and select the cPVAL Threatlocker Deployment - Exclude custom field.

  • Condition: cPVAL Threatlocker Deployment - Exclude does not equal Yes

    Image1

  • Click the + Add button within the upper section labeled Custom field value must meet ALL conditions.
    AddButtonCustomFields

  • A new row will be added upon clicking the + Add button.
    NewRow

  • Search and select the cPVAL Threatlocker Deployment custom field.

  • Condition: cPVAL Threatlocker Deployment equals Windows and Macintosh

    Image2

  • Click the Apply button to save the custom field condition.
    Image2

Automations

Navigate to Automations section.
AutomationSections

Click the + Add automation button.
AddAutomation

Automation Library will appear upon clicking the + Add Automation button. Note that existing automation library may vary across different environments. The provided screenshot is for demonstration purposes only.
AutomationLibrary

Search and select the Threatlocker Deployment [MAC] script.
Image3

Click the Apply button to add the automation.
Image3

Completed Automation Section:
Image5

Settings

Navigate to Settings section.
SettingsSection

Set the Settings section as follows:

Name: Threatlocker Deployment - MAC
Auto Reset:

  • After: True 1 hour
  • When no longer met: True

Run Every: 30 Minutes
Trigger uptime: False

Image6

Notifications

Leave the Notifications section untouched.

Completed Component

Click the Apply button at the bottom to save the compound condition.
Apply

Image7

Saving Agent Policy

Click the Save button located at the top-right corner of the screen to save the agent policy.
Save

You will be prompted to enter your MFA code. Provide the code and press the Continue button to finalize the process.
MFA