How to Remediate Anti-Malware in macOS Devices?
Please follow the steps below for detail remediation instruction to resolve device non-compliance issue on MacOS devices
The Max Score for the Anti-Malware category is 30 points, and the Max Score will be subtracted using this scheme:
- If Real-Time Protection (RTP) is disabled, subtract 30 points
- Or else:
- Subtract 15 points if there is any unremediated threat detected on the machine
- Subtract 5 points if the signatures are not up-to-date within Y days
- Subtract 5 points if a scan has not been run in Z days
Note that Y and Z will be set using this algorithm:
For the Free Client:
- Use Y=8 and Z=30
For the Managed Client:
- Use the settings from the device’s My OPSWAT Central Management Policy
- If the settings are not available in the My OPSWAT Central Management Policy (either because it is not enabled, or there is an error retrieving them), use the same settings as the Free Client
How to get max score
Step 1: Install new anti-malware software https://www.opswat.com/partners/certification/certified-products (Tested on Kaspersky, McAfee, Eset).
Or make sure that Microsoft Defender is installed on your machine.
The above steps are mandatory as required by your organization. If your device does not have any of the listed software installed, please contact your administrator or IT team for assistance.
Step 2: Enable Real-Time Protection
On management console: Administrators can go to Policies > Deep Compliance > Anti-Malware > macOS section. Then look for the “Real-time protection is disabled“, check the box where it states "Attempt to enable real-time protection in approved products" to enable RTP.
On the machine that installed MetaDefender Endpoint: Make sure “Real-time protection“ in Microsoft Defender is enabled
Step 3: Check Virus & Threat protection updates to the latest version
Step 4: Start a full scan for all drives on the device. Go to Microsoft Defender > Scan Options > Select Full Scan > Scan Now
Step 5: Recheck on tray icon of MetaDefender Endpoint if needed.