Installation Process

Downloading the macOS Installation Package

In the case of macOS, the dope.endpoint has one universal installation package that supports:

• Apple Intel • Apple Silicon (Native)

This page is for a device where a Mobile Device Management (MDM) profile has not been installed.To install on a device with an MDM profile installed see Installing using MDM on Mac.

Select the installer package for your device

After selecting the installation package you require, a ZIP file will be downloaded to your device. The ZIP file will be called dope_security_mac_<processor type>_<build number>.zip

Extract the ZIP file, it will contain the following three files:

  • dope.security-<build number>.pkg — The dope.endpoint installer.

  • dope.security.crt — The dope.security Root CA, required for SSL inspection.

  • agent_parameters.json — Tenant-specific data required for the installation process.

All three files must be in the same directory or the installation will FAIL.

To install the dope.endpoint, double click on the PKG file. This will launch the Installer UI.

From here select Continue. A new screen will appear:

There will be a prompt to allow the dope.security Root CA to be installed:

The final prompt is to allow the dope.security application to run. There's a prompt to open the macOS security and preferences settings:

Open the security preferences dialog box. You will see the following screen:

Some system software requires your attention before it can be used. Selecte "Details..." and toggle to allow DopeSecurityApp to run.

Finally, you will be prompted with a warning that the dope app will filter web traffic, again select to allow.

All of the prompts above will not appear on a device where a MDM profile has been installed. For more details, see Installing using MDM on Mac.

When the dope.endpoint has been successfully installed, and endpoint authentication has been enabled (See Users), you will be prompted to log in via your Microsoft 365 / Google corporate email.

Log in with the appropriate corporate email address.

If enabled, Multi Factor Authentication (MFA) will be required.

Once the user has successfully authenticated they will be displayed the following page.

This page can then be closed and the user can continue browsing. The dope.endpoint will be configured with the dope policy you have assigned them in the dope.console. If you have not assigned them a specific policy, they will automatically be assigned the Base Policy.

Where endpoint authentication has not been enabled (See Users) the user will not be prompted to authenticate and will get the Base Policy.

Unauthenticated Users

Where a user has not successfully authenticated and they attempt to access the internet they will get the following screen, selecting continue here will bring them to the M365 or Google Login Screen.

Last updated