Symantec Endpoint Encryption for FileVault and the Symantec Removable Media Access Utility are supported with use on macOS 10.15.1.
Support for using these Symantec Encryption products with macOS 10.15.1 also requires "Full Disk Access" for them to work correctly. Full Disk Access is part of Apple's security framework for macOS, and granting full disk access allows an application the ability to access otherwise protected files on an endpoint.
While individual users can allow or deny access for specific applications like Symantec Endpoint Encryption for FileVault and Removable Media Access Utility, you can bypass end-user prompts for allowing disk access by deploying an MDM device profile to users in your organization. The profile can configure security settings on endpoint systems that also have Symantec Endpoint Encryption for FileVault or Removable Media Access Utility.
This article explains how to edit the MDM profile to enable Full Disk Access on endpoint systems.
Update the MDM configuration values for Symantec Endpoint Encryption for FileVault or Removable Media Access Utility for macOS. To update MDM configuration values, use a third-party mobile device management (MDM) solution.
Refer to the following information for values to update in the MDM profile:
Attributes | Symantec Endpoint Encryption for FileVault | Removable Media Access Utility |
Payload type | com.apple.TCC.configuration-profile-policy | com.apple.TCC.configuration-profile-policy |
Services | SystemPolicyAllFiles | SystemPolicyAllFiles |
Identifier |
/Library/Application Support/Symantec Endpoint Encryption/SEEd |
com.yourcompany.RemovableMediaAccessUtility |
CodeRequirement |
anchor apple generic and identifier "com.Symantec.Encryption.SEEd" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "9PTGMPNXZ2") |
anchor apple generic and identifier "com.yourcompany.RemovableMediaAccessUtility" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "9PTGMPNXZ2") |
IdentifierType | Path | Bundle ID |
Allowed | 1 | 1 |
The attached files (SEE-for-FileVault_macOS10.15.1_MDM.rft and RME-Access-Utility_macOS10.15.1_MDM.rft) provide the MDM configuration values in a version formatted as a plist file. You can copy the plist content into the MDM file you create.
Additional Information:
For more details, see the Configuration Profile Reference for Apple developers, especially the section "Privacy Preferences Policy Control Payload."