CB Defense: How to Generate "Code Requirement" For Granting Sensor Full Disk Access (pre-Big Sur)
search cancel

CB Defense: How to Generate "Code Requirement" For Granting Sensor Full Disk Access (pre-Big Sur)

book

Article ID: 291753

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense)

Issue/Introduction

Generate the identifier string for the "Code Requirement" portion of the Privacy Preferences payload to grant Full Disk Access (FDA) to Sensor through Jamf policy

Environment

  • CB Defense PSC Sensor: 3.2.1.10 - 3.4.x.x
  • Apple macOS: 10.14.5 - 10.15.x (pre-Big Sur)
  • Jamf Pro: 10.9 and higher

Resolution

  1. Open Terminal on the machine running the Sensor
  2. Run this command to generate the identifier string
    codesign -dr - /Applications/Confer.app/Contents/MacOS/CbDefense
  3. Copy the output in its entirety into the Code Requirement section of the Privacy Preferences payload

Additional Information

  • The identifier string listed in the CB Defense: How to Enable Full Disk Access for Sensor on macOS 10.14.5 and Higher KB applies to all 3.2.x.x thru 3.4.x.x sensors at the time of this writing
  • Sometimes errors can occur as a result of copying and pasting the identifier string from a Web Browser, so manual generation of the identifier string is a good troubleshooting step
  • Jamf documentation on granting FDA can be found here
  • Carbon Black recommends granting the Sensor Full Disk Access