Kernel extensions aren't loaded without user consent
Last Modified: 2023-05-26 04:32:42 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Kernel extensions aren't loaded without user consent
Technical Articles ID:
KB91332
Last Modified: 2023-05-26 04:32:42 Etc/GMT Environment
Data Loss Prevention (DLP) for Mac 11.x Apple macOS High Sierra 10.13.x and later Summary
To improve security on Mac systems, macOS High Sierra 10.13 introduces a new feature called Secure Kernel Extension Loading (SKEL). SKEL requires user consent to load any third-party kernel extensions that are installed after the installation of macOS High Sierra. For more information, see Technical Note TN2459. Problem
Kernel extensions of DLP aren't allowed to load without user consent.
Cause
SKEL prevents kernel extensions from loading, which directly affects product functionality.
SolutionIf the DLP kernel extensions are present on the Mac system before you upgrade to macOS High Sierra or later, user consent isn't needed.
Enrollment in MDM automatically disables SKEL with macOS 10.13.3 and earlier. In this case, end-user consent isn't needed to enable the DLP features. Starting with macOS 10.13.4, enrolling in MDM doesn't automatically disable SKEL. To load without end-user consent, the DLP kernel extensions have to be added in the Kernel Extension Policy payload. For details, see the following articles:
Below are the details for use in the Kernel Extension Policy payload:
When no MDM solution is available, it's possible to manually enable the DLP kernel extensions. See KB89728 - End-user experience when installing Endpoint Security for Mac on macOS High Sierra 10.13 and later. Affected ProductsLanguages:This article is available in the following languages: |
|