Appendix C - Kandji
Use Kandji to deploy Workforce AI Security components to managed macOS devices.
Kandji supports multiple deployment scenarios.
For more information about Workforce AI Security connection to external systems, see External System Connections.
Deploying AI Security Client
In this scenario, you use Kandji to deploy full endpoint protection.
To deploy the client:
-
Download
CheckPoint_Installer.zipas described in Downloads. -
Unzip the file.
-
Open a terminal and run:
./TinyGenAI.app/Contents/MacOS/EPTinyGenAI --gen-mdm-script -
Use the generated script
gen_genai_protect_installer_script.shfor the deployment. -
Log in to the Iru portal (https://www.iru.com/login).
-
Go to Library.
-
Click + Add library item.
-
Select Custom Script.
-
Paste the script content into the script editor.
-
Click Save.
-
Go to Blueprints.
-
Assign the script to the required blueprint.
-
Save the configuration.
-
Return to Library and monitor deployment status.
Deploying the Fleet Scan Script
Deploy the Agentic Endpoint Scanner fleet scan script to managed macOS devices with Kandji.
Supported platforms: macOS
Prerequisites
-
Download the macOS fleet scan script from Workforce > Deployment > Downloads.
-
Make sure you have administrative access to Kandji.
To deploy the fleet scan script:
-
Log in to the Kandji dashboard.
-
Go to Library.
-
Click + Add library item.
-
Select Custom Script > Add and configure.
-
Configure the script:
-
Enter a title (for example, Agentic Endpoint Discovery).
-
Select the blueprint for the endpoints where you want the scan script to run.
-
Set the frequency to Run daily.
-
Copy the fleet scan script content into the Audit Script box.
-
Save and deploy to your target macOS devices.
-
User & Device Sync
Connect Kandji to Workforce AI Security to synchronize Apple devices and users.
Creating an API Token
-
Log in to Kandji and go to Settings > Access > API Token.
-
Click Add API Token and enter a descriptive name.
-
Click Create Token. Copy the displayed token immediately and store it securely. The token is not shown again.
-
Make sure these permissions are enabled for the token:
Category
Permissions
Users
List users
Devices
Device details, Device list, Application list
Connecting in the Portal
-
In the Workforce AI Security portal, go to Settings > User & Device Sync.
-
Expand Kadji.
-
Enter the API URL and API Key.
-
Click Save.