Deploy Device Protection with ManageEngine
Use ManageEngine Endpoint Central to deploy Aikido Device Protection across your managed macOS fleet with the required permissions in place.
Installation
What you'll need
Before starting, make sure you have the following from the Aikido Device Protection dashboard:
The Aikido Device Protection
.mobileconfig(downloaded from the Aikido Device Protection dashboard)The Aikido Device Protection installer (
.pkgfile, downloaded from the dashboard)
If you're missing any of these, go back to the Aikido Device Protection dashboard, click Connect Device, and complete the pre-flight steps.
Add the Aikido Device Protection configuration profile
In Endpoint Central, go to Configurations → Mac → Custom Configuration.
Click Upload Configuration and select the
.mobileconfigfile.Give the profile a name (e.g. "Aikido Device Protection") and click Save and Publish.
Associate the profile with the target devices or device groups.
This profile allows the Aikido Device Protection system extension to load silently, enables the network content filter, and stops users from disabling background services in System Settings → Login Items.
Create the Aikido Device Protection package
In Endpoint Central, go to Software Deployment → Package Creation → Packages → Add Package → Mac.
Upload the Aikido Device Protection
.pkgfile and fill in the package details.Save the package.
Create the install deployment
In Endpoint Central, go to Software Deployment → Install/Uninstall Software.
Create a new deployment task, select Mac, and choose the Aikido Device Protection package you just created.
Set the action to Install and scope it to the same target devices or groups.
Configure the schedule and save the task.
Deploy in the right order
Deploy the configuration profile before the installer for a smoother rollout.
Verify the Aikido Device Protection configuration profile has reached all target devices. Check status under Configurations → Configuration Summary.
Only then deploy the Aikido Device Protection install task.
Reboot devices after installation
In Endpoint Central, go to Tools → Remote Shutdown.
Select the target devices from the list.
Click More Actions and choose Restart.
The agent fully activates on the next boot.
Verify the deployment
On a test device, confirm:
The system extension is activated:
systemextensionsctl list | grep aikidoExpect to see the extension marked
[activated enabled].Open System Settings → General → Login Items & Extensions and confirm the Aikido Device Protection entries cannot be toggled off.
Troubleshooting
Last updated
Was this helpful?