---
title: Hands-On Onboarding for MDE (macOS)
description: Comprehensive guide for macOS Local MDE onboarding.
---

[Skip to content](https://knowledge.sittadel.com/manual-macos-local-script-mde-onboarding#main-content)

[![Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent copy](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png?width=55&height=55&name=Sittadel-Logo-Icon-Slim-Large-Square-Green-Transparent%20copy.png)](https://sittadel.com/)

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)

Open main navigation

Close main navigation

- [About Sittadel](https://sittadel.com/about/)
- [Capabilities](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
  
  Show submenu for Capabilities

    - [Microsoft Security Architecture](https://sittadel.com/capabilities/microsoft-office365-azure-security/)
    - [Detection & Response](https://sittadel.com/capabilities/managed-detection-and-response/)
    - [Employee Training](https://sittadel.com/capabilities/security-awareness-training/)
    - [Security Risk Advisors](https://sittadel.com/capabilities/virtual-information-security-officer/)
- [Resources](https://sittadel.com/resources/)
- [Knowledge Base](https://knowledge.sittadel.com/)
- [Get Sittadel](https://sittadel.com/start/)

[Get Sittadel](https://sittadel.com/start/)

 Find answers to your security questions.

- There are no suggestions because the search field is empty.

1. [Sittadel Knowledge Base](https://knowledge.sittadel.com/?hsLang=en)
2. [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en)
3. [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)

# Hands-On Onboarding for MDE (macOS)

## Comprehensive guide for macOS Local MDE onboarding: retrieving the MDE onboarding package from the Defender portal, installing the Agent utilizing the embedded scripts, and validating connectivity and security functionality post-implementation.

### **Gather macOS MDE Local Onboarding Package**

1. **Prior to carrying out this procedure**, we will need to **verify that the specific macOS version that is currently being utilized meets the minimum system requirements specified by Microsoft**, follow these [steps here](https://knowledge.sittadel.com/verifying-macos-specifications-for-mde-onboarding?hsLang=en).
2. Once the **macOS Specification** verification has been completed, navigate to the [Endpoint Onboarding – Microsoft Defender](https://security.microsoft.com/securitysettings/endpoints/onboarding) portal, from this page specify the **Operating System** as **macOS, Connectivity Type** as **Streamlined,** and the **Deployment Method** as **Local Script (for up to 10 devices).**  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-05-35-00-3621-PM.png?width=670&height=377&name=image-png-Aug-23-2024-05-35-00-3621-PM.png)
3. Once the proper selections have been made, locate, and select **Download Installation Package,** the **wdav.pkg** file will be stored to the **Downloads** folder on the **User** account, we will also be selecting **Download onboarding package,** the **GatewayWindowsDefenderATPOnboardingPackage.zip** file will also be stored to the **same directory**.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-05-44-49-6624-PM.png?width=647&height=65&name=image-png-Aug-23-2024-05-44-49-6624-PM.png)![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-05-45-25-8936-PM.png?width=467&height=245&name=image-png-Aug-23-2024-05-45-25-8936-PM.png)
4. We will need to **extract the contents of the package**, the **extracted** **.zip** **folder** should house a **file** named **MicrosoftDefenderATPOnboardingMacOs**.**sh.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-25-2024-03-25-32-9417-PM.png?width=670&height=49&name=image-png-Aug-25-2024-03-25-32-9417-PM.png)**
5. After the **extraction process** has been completed, we will want to relocate the **wdav.pkg** file and the **MicrosoftDefenderATPOnboardingMacOs.sh** file to a location where they can be accessed by the desired **macOS** **machines** that are wishing to **MDE** **join**, this can be done by **uploading these files to a trusted SharePoint, Outlook email, or USB.**

### **Deploy macOS MDE Local Onboarding Package**

1. On the desired **macOS** **Device**, we will first want to verify that both the **wdav.pkg** **file** and the **MicrosoftDefenderATPOnboardingMacOs.sh** **file** are housed on a **desired directory** on the machine.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-06-59-27-9375-PM.png?width=670&height=323&name=image-png-Aug-23-2024-06-59-27-9375-PM.png)
2. Once we have verified that **both files** are present on the device, we will first access the **wdav.pkg** file from the **directory the file is currently stored on**. Once the wizard generates you will see the **Introduction** page select **Continue** to proceed.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-03-19-2231-PM.png?width=627&height=450&name=image-png-Aug-23-2024-07-03-19-2231-PM.png)
3. On the **Licensing** page, read through the **Microsoft Application License Terms,** select **Continue** to proceed.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-03-38-7115-PM.png?width=626&height=450&name=image-png-Aug-23-2024-07-03-38-7115-PM.png)
4. A popup will be displayed asking for **consent for the licensure agreement prior to software installation**. Select **Agree** to consent and continue.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-05-00-3049-PM.png?width=631&height=230&name=image-png-Aug-23-2024-07-05-00-3049-PM.png)
5. On the **Installation Type** page, verify that you have the **proper disk space required for the software installation**. Select **Install** to continue.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-05-30-0079-PM.png?width=627&height=450&name=image-png-Aug-23-2024-07-05-30-0079-PM.png)
6. You will be prompted to provide **Administrative** **Credentials** **to** **install the software.** Provide the necessary credentials and select **Install Software** to continue.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-06-56-9314-PM.png?width=367&height=375&name=image-png-Aug-23-2024-07-06-56-9314-PM.png)
7. After **successful authentication**, the **installation process** will be carried out, when complete you will receive a window to approve the **system extensions** used by the product. Select **Open Security Preferences.**  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-08-55-6181-PM.png?width=607&height=450&name=image-png-Aug-23-2024-07-08-55-6181-PM.png)
8. To enable the **System Extensions,** select the **Lock Icon,** you will be prompted to provide **administrative credentials** to make system changes. Provide the necessary credentials to continue.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-09-22-9335-PM.png?width=625&height=550&name=image-png-Aug-23-2024-07-09-22-9335-PM.png)![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-10-05-9381-PM.png?width=624&height=550&name=image-png-Aug-23-2024-07-10-05-9381-PM.png)
9. Once **unlocked,** select **Details** to enable **System Extensions.**  
   **![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-10-31-6279-PM.png?width=628&height=550&name=image-png-Aug-23-2024-07-10-31-6279-PM.png)**
10. From the **Security & Privacy** window, select the checkboxes next to **Microsoft Defender** and select **Ok**.  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-10-58-2921-PM.png?width=625&height=550&name=image-png-Aug-23-2024-07-10-58-2921-PM.png)
11. After the enablement of the **System Extensions,** you will be prompted to grant **Microsoft Defender for Endpoint** the ability to filter **Network Traffic,** select **Allow** **to consent to the MDE agent inspecting socket traffic and reporting this information to the Defender portal.**  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-13-51-7345-PM.png?width=626&height=550&name=image-png-Aug-23-2024-07-13-51-7345-PM.png)
12. With the **authenticated session to make system changes still active,** we will proceed with **allowing** **Accessibility** for the **Microsoft Defender app**. Find the **Microsoft Defender** **application** from the list of **allowed apps**, verify that the **checkbox** next to the app is **selected**. If the **Microsoft Defender** **app** is not currently listed select the **+ icon to manually add the application through the generated Finder window.  An example will be listed under step 17 and 18 of the procedure.**  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-15-42-9454-PM.png?width=623&height=550&name=image-png-Aug-23-2024-07-15-42-9454-PM.png)
13. Next,we will proceed with **allowing** **Full Disk Access** for the **Microsoft Defender app** and the **Microsoft Defenders Endpoint Security Extension.** Find the **Microsoft Defender application** from the list of **allowed apps**, verify that the **checkbox** next to the app is **selected**. If the **Microsoft Defender app** is not currently listed select the **+ icon to manually add the application through the generated Finder window. ** **An example will be listed under step 17 and 18 of the procedure.** Additionally, the **Security Extension** should be **listed automatically** after the **explicit consent delegated in the previous steps.**  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-18-20-0368-PM.png?width=627&height=550&name=image-png-Aug-23-2024-07-18-20-0368-PM.png)
14. We will want to verify that after the **Full Disk Access** for the **Microsoft Defender app** and the **Microsoft Defenders Endpoint Security Extension** that they have been **given access to all files and folders. This should be conducted automatically after the Full Disk Access has been granted.**  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-20-45-9023-PM.png?width=626&height=550&name=image-png-Aug-23-2024-07-20-45-9023-PM.png)
15. Lastly, we will proceed with **allowing Bluetooth permissions** for the **Microsoft Defender app.** Find the **Microsoft Defender application** from the list of **allowed apps**, verify that the **checkbox** next to the app is **selected**. If the **Microsoft Defender app** is not currently listed select the **+ icon to manually add the application through the generated Finder window.  An example will be listed under step 17 and 18 of the procedure.**  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-24-03-4936-PM.png?width=622&height=550&name=image-png-Aug-23-2024-07-24-03-4936-PM.png)
16. After the **necessary security controls have been enabled** within the **Security & Privacy** section of the **System Preferences** utility will need to enable the **Microsoft Defender app** to be an **allowed** **Background Service.** This can be achieved by selecting the **Spotlight Search** utility and supplying **Login items** or **Signin items.** Locate and select the **Users & Groups system settings **option.  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-25-37-0709-PM.png?width=670&height=428&name=image-png-Aug-23-2024-07-25-37-0709-PM.png)
17. This will open the current **User Accounts** and **Groups** that are associated with the device, with the desired **Current User** selected, we will want to move from the **Password settings** to the **Login Items settings**, this can be done by selecting the **Login Items** tab. Once selected we will want to verify if the **Microsoft Defender application** is listed, **if it is** we can exit from this window, **if it is not,** we will need to select the **Lock Icon,** you will be prompted to provide **administrative credentials** to make system changes. Provide the necessary credentials to continue. Once authenticated we will select the **+ icon to add the necessary application**.  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-28-41-0406-PM.png?width=670&height=500&name=image-png-Aug-23-2024-07-28-41-0406-PM.png)
18. When selected a **Finder** session will be opened, the **Applications** section should already be selected, using the **Search Bar,** or **manually scrolling,** locate and select the **Microsoft Defender application** from the list. Once selected, hit **Add** to confirm the **service allowance.** If correctly done the **Microsoft Defender application** should now be **listed as an automatic** **Login Item.**  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-31-44-9478-PM.png?width=670&height=414&name=image-png-Aug-23-2024-07-31-44-9478-PM.png)
19. Before **finalizing the security settings for the MDE agent**, we will need to deploy the **MicrosoftDefenderATPOnboardingMacOs.sh **onboarding script to **register the agent to the desired tenant and license it**. We will begin by executing the command below to verify that the **macOS** **device is currently not onboarded through** **Intune** **or already locally onboarded for MDE.**
    
    | **Command** |
    | --- |
    | **mdatp health --field org\_id** |
    
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-23-2024-07-36-14-3486-PM.png?width=670&height=67&name=image-png-Aug-23-2024-07-36-14-3486-PM.png)
20. After the execution of the command above, the code should return the value **No license found, if it does not** then **your device has been connected through Intune or has already been joined locally to the Microsoft Defender portal.**
21. After the verification command has been executed, we will proceed with leveraging the **MicrosoftDefenderATPOnboardingMacOs**.**sh** script, this can be done by relocating to the directory that the **.sh** file is housed in, once inside the directory execute the command below. **You will be prompted to supply the administrative password associated with the account.**
    
    | **Command** |
    | --- |
    | **sudo bash -x MicrosoftDefenderATPOnboardingMacOs.sh** |
    
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-24-2024-05-50-41-5495-PM.png?width=670&height=133&name=image-png-Aug-24-2024-05-50-41-5495-PM.png)
22. After the execution of the command, you will see the return values of a **.plist file** and additional directory configuration being established, **this ensures that the necessary security controls are in place for device communication with the Microsoft Defender portal being established.**
23. We will want to re-execute the **mdatp health --field org\_id** to verify that the execution of the **MicrosoftDefenderATPOnboardingMacOs.sh** script has successfully **connected the machine to the desired tenant.**  
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-24-2024-05-54-20-9448-PM.png?width=670&height=59&name=image-png-Aug-24-2024-05-54-20-9448-PM.png)
24. After the tenant connection has been verified, we will want to leverage a **connectivity test** that will verify that **all connection established by Microsoft services are executing properly**, leverage the command below.
    
    | **Command** |
    | --- |
    | **mdatp connectivity test** |
    
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-24-2024-06-13-59-0679-PM.png?width=670&height=479&name=image-png-Aug-24-2024-06-13-59-0679-PM.png)
25. Now that we have established the necessary **licensure requirements** for the **MDE** **agent**, we will now want to finalize the **security settings** for the **MDE** **agent**, we can achieve this by executing the **one-liner below to enable necessary security settings like Tamper protection, PUA blocking, etc. You will be prompted to supply the administrative password associated with the account.**
    
    | **One-Liner** |
    | --- |
    | **mdatp threat policy set --type potentially\_unwanted\_application --action block; mdatp config network-protection enforcement-level --value block; sudo mdatp config tamper-protection enforcement-level --value block** |
    
    ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-24-2024-06-17-23-9736-PM.png?width=665&height=90&name=image-png-Aug-24-2024-06-17-23-9736-PM.png)
26. After the execution of the one-liner, you will see the return values of **successful configuration** of the listed item. This finalizes the **deployment of the local MDE agent on macOS**, we will now move onto **Assessing the MDE agent on the device.**

### **Assessing a macOS MDE Local Onboarding Deployment**

1. Utilizing the macOS **Spotlight Search** functionality, provide **Terminal** within the **search field**. Locate and select the **utility** to begin.  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-24-2024-06-27-36-2420-PM.png?width=670&height=428&name=image-png-Aug-24-2024-06-27-36-2420-PM.png)
2. Once the session is initiated, supply the following command to evaluate if **real-time protection is currently active on the machine** for the **Microsoft Defender**  This should return **true**, if not **you will need to verify that the settings within the application are configured properly.**
   
   | **Command** |
   | --- |
   | **mdatp health --field real\_time\_protection\_enabled** |
   
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-24-2024-06-31-31-7054-PM.png?width=670&height=55&name=image-png-Aug-24-2024-06-31-31-7054-PM.png)
3. Once the session is initiated, supply the following command to evaluate the connectivity with the **MDE agent** and **Microsoft Defender Servers**.
   
   | **Command** |
   | --- |
   | **curl -o ~/Downloads/eicar.com.txt https://www.eicar.org/download/eicar.com.txt** |
   
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-24-2024-06-34-05-5530-PM.png?width=670&height=55&name=image-png-Aug-24-2024-06-34-05-5530-PM.png)
4. If done correctly, within a few moments an **‘EICAR\_Test\_File’ malware was prevented** alert will be generated within the [Alerts – Microsoft Defender](https://security.microsoft.com/alerts) portal. <https://security.microsoft.com/alerts>  
   ![](https://knowledge.sittadel.com/hs-fs/hubfs/image-png-Aug-24-2024-06-35-35-9018-PM.png?width=670&height=174&name=image-png-Aug-24-2024-06-35-35-9018-PM.png)

### Need Assistance?

Reach out to your Customer Success Manager to discuss how a Sittadel cybersecurity analyst can assist in managing these tasks for you. New to our services? [Inquire](https://sittadel.com/start/) about arranging a consultation to explore optimizing your Azure environment for painless management.

- [UserOps](https://knowledge.sittadel.com/userops?hsLang=en#main-content)

    - [Access & Permissions](https://knowledge.sittadel.com/userops?hsLang=en#access-permissions)
    - [Account](https://knowledge.sittadel.com/userops?hsLang=en#account)
    - [Devices](https://knowledge.sittadel.com/userops?hsLang=en#devices)
    - [Document Sharing](https://knowledge.sittadel.com/userops?hsLang=en#document-sharing)
    - [Email](https://knowledge.sittadel.com/userops?hsLang=en#email)
    - [Requests](https://knowledge.sittadel.com/userops?hsLang=en#requests)
    - [Troubleshoot](https://knowledge.sittadel.com/userops?hsLang=en#troubleshoot)
- [TechOps](https://knowledge.sittadel.com/techops?hsLang=en#main-content)

    - [Tenant Foundations](https://knowledge.sittadel.com/techops?hsLang=en#tenant-foundations)
    - [Collaboration Security](https://knowledge.sittadel.com/techops?hsLang=en#collaboration-security)
    - [Email Security](https://knowledge.sittadel.com/techops?hsLang=en#email-security)
    - [Device Security](https://knowledge.sittadel.com/techops?hsLang=en#device-security)
    - [Identity Security](https://knowledge.sittadel.com/techops?hsLang=en#identity-security)
- [SecOps](https://knowledge.sittadel.com/secops?hsLang=en#main-content)

    - [Email SOC](https://knowledge.sittadel.com/secops?hsLang=en#email-soc)
    - [Identity SOC](https://knowledge.sittadel.com/secops?hsLang=en#identity-soc)
    - [Tenant SOC](https://knowledge.sittadel.com/secops?hsLang=en#tenant-soc)
    - [Device SOC](https://knowledge.sittadel.com/secops?hsLang=en#device-soc)
- [Deploy Intune](https://knowledge.sittadel.com/deploy-intune?hsLang=en)
- [Deploy MDE](https://knowledge.sittadel.com/deploy-mde?hsLang=en#main-content)

    - [Overview](https://knowledge.sittadel.com/deploy-mde?hsLang=en#overview)
    - [Intune Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#intune-deployment)
    - [Hands-On Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#hands-on-deployment)
    - [Azure Arc Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#azure-arc-deployment)
    - [RMM Tool Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#rmm-tool-deployment)
    - [MECM/SCCM Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#mecm-sccm-deployment)
    - [GPO Deployment](https://knowledge.sittadel.com/deploy-mde?hsLang=en#gpo-deployment)
- [Deploy Services](https://knowledge.sittadel.com/deploy-services?hsLang=en#main-content)

    - [Cloud Enclave](https://knowledge.sittadel.com/deploy-services?hsLang=en#cloud-enclave)
- [Azure Portals](https://knowledge.sittadel.com/azure-portals?hsLang=en#main-content)

    - [Entra ID](https://knowledge.sittadel.com/azure-portals?hsLang=en#entra-id)
    - [Intune](https://knowledge.sittadel.com/azure-portals?hsLang=en#intune)
    - [Defender](https://knowledge.sittadel.com/azure-portals?hsLang=en#defender)
    - [Purview](https://knowledge.sittadel.com/azure-portals?hsLang=en#purview)
    - [SharePoint Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#sharepoint-admin-center)
    - [Teams Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#teams-admin-center)
    - [Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#admin-center)
    - [Exchange Admin Center](https://knowledge.sittadel.com/azure-portals?hsLang=en#exchange-admin-center)

[![](https://knowledge.sittadel.com/hs-fs/hubfs/Sittadel_LogoH_Color_BlackText.png?width=186&height=55&name=Sittadel_LogoH_Color_BlackText.png)](https://Sittadel.com)

Security for Humans.

Copyright © 2026, Sittadel

<https://www.linkedin.com/company/sittadel> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true> <https://outlook.office365.com/book/StartSittadelcom@sittadel.com/?ismsaljsauthenabled=true>