명령줄 도구를 사용 mdatp 해 엔드포인트용 Microsoft Defender를 구성하고, 스캔을 실행하며, 탐지된 위협을 관리하고, macOS 기기에서 제품 상태를 점검하세요. 진단 정보 수집, 명령 자동 완성 활성화, 격리 파일 관리, Defender for Endpoint 삭제도 가능합니다.
제품 요구사항 및 배포 방법에 대해서는 macOS의 엔드포인트용 Microsoft Defender 및 macOS의 엔드포인트용 Microsoft Defender 전제 조건을 참조하십시오.
진단 정보 수집
문제를 재현할 수 있는 경우 로깅 수준을 높이고, 일정 시간 동안 시스템을 실행한 다음, 로깅 수준을 기본값으로 복원합니다.
로그 레벨을 다음과 같이 설정하세요
debug:mdatp log level set --level debugLog level configured successfully문제를 재현하세요.
Defender for Endpoint 진단 로그가 포함된
.zip아카이브를 생성하세요. 명령어는 성공 후 아카이브 경로를 표시합니다:팁
기본적으로 진단 로그는 에
/Library/Application Support/Microsoft/Defender/wdavdiag/저장됩니다. 다른 디렉터리를 사용하려면 명령어에 추가--path [directory]하고 목적지로 대체[directory]하세요.sudo mdatp diagnostic createDiagnostic file created: "/Library/Application Support/Microsoft/Defender/wdavdiag/932e68a8-8f2e-4ad0-a7f2-65eb97c0de01.zip"로그 레벨을 기본값으로 복원하세요:
infomdatp log level set --level infoLog level configured successfully
설치 로그 검토
설치 실패 시 설치 프로그램은 일반적인 실패만 보고할 수 있습니다. 자세한 정보는 .에서 /Library/Logs/Microsoft/mdatp/install.log확인할 수 있습니다. Microsoft 지원 케이스를 열 때 이 파일을 포함하세요.
더 많은 문제 해결 지침은 macOS에서 엔드포인트용 Microsoft Defender 설치 문제 문제 해결을 참고하세요.
명령줄에서 구성
출력 포맷 구성
명령줄 도구는 테이블 및 JSON 출력을 지원합니다. 명령어와 함께 다음 전역 옵션 중 하나를 사용하세요:
--output json--output table
지원되는 명령
다음 표는 일반적인 시나리오에 대한 명령어를 나열합니다. 설치된 제품 버전에서 지원하는 전체 명령어 목록을 보려면 터미널에서 실행 mdatp help 하세요.
| 그룹 | 시나리오 | 명령 |
|---|---|---|
| 구성 | 수동 모드 켜거나 끄기 | mdatp config passive-mode --value [enabled/disabled] |
| 구성 | 실시간 보호 기능을 켜거나 끄세요 | mdatp config real-time-protection --value [enabled/disabled] |
| 구성 | 행동 모니터링을 켜거나 끄세요 | mdatp config behavior-monitoring --value [enabled/disabled] |
| 구성 | 클라우드 보호 기능을 켜거나 끄세요 | mdatp config cloud --value [enabled/disabled] |
| 구성 | 클라우드 진단을 켜거나 끄세요 | mdatp config cloud-diagnostic --value [enabled/disabled] |
| 구성 | 자동 샘플 제출 켜기/끄기 | mdatp config cloud-automatic-sample-submission --value [enabled/disabled] |
| 구성 | 잠재적으로 원치 않는 애플리케이션 보호 차단, 감사 또는 비활성화 | mdatp threat policy set --type potentially_unwanted_application --action [block\|audit\|off] |
| 구성 | 프로세스에 대한 안티바이러스 제외 항목을 추가하거나 제거하기 | mdatp exclusion process [add\|remove] --path [path-to-process] |
| 구성 | 파일에 대한 백신 제외 항목을 추가하거나 제거하기 | mdatp exclusion file [add/remove] --path [path-to-file] |
| 구성 | 디렉터리에 대한 백신 제외 항목을 추가하거나 제거하세요 | mdatp exclusion folder [add/remove] --path [path-to-directory] |
| 구성 | 파일 확장자에 대한 백신 제외 항목을 추가하거나 제거하세요 | mdatp exclusion extension [add/remove] --name [extension] |
| 구성 | 모든 바이러스 백신 제외 나열 | mdatp exclusion list |
| 구성 | 주문형 검사에 대한 병렬 처리 수준 구성 | mdatp config maximum-on-demand-scan-threads --value [numerical-value-between-1-and-64] |
| 구성 | 보안 정보 업데이트 후 스캔을 켜거나 끄세요 | mdatp config scan-after-definition-update --value [enabled/disabled] |
| 구성 | 주문형 스캔을 위해 아카이브 스캔을 켜거나 끄세요 | mdatp config scan-archives --value [enabled/disabled] |
| 구성 | 파일 해시 계산을 켜거나 끄기 | mdatp config enable-file-hash-computation --value [enabled/disabled] |
| 보호 | 경로 검사 | mdatp scan custom --path [path] [--ignore-exclusions] |
| 보호 | 빠른 검사 실행 | mdatp scan quick |
| 보호 | 전체 검사 실행 | mdatp scan full |
| 보호 | 진행 중인 주문형 검사 취소 | mdatp scan cancel |
| 보호 | 보안 인텔리전스 업데이트 요청 | mdatp definitions update |
| 구성 | 허용된 목록에 위협 이름 추가 | mdatp threat allowed add --name [threat-name] |
| 구성 | 허용된 목록에서 위협 이름 제거 | mdatp threat allowed remove --name [threat-name] |
| 구성 | 허용되는 모든 위협 이름 나열 | mdatp threat allowed list |
| 보호 기록 | 전체 보호 기록 인쇄 | mdatp threat list |
| 보호 기록 | 위협 세부 정보 가져오기 | mdatp threat get --id [threat-id] |
| 격리 관리 | 격리된 모든 파일 나열 | mdatp threat quarantine list |
| 격리 관리 | 격리에서 모든 파일 제거 | mdatp threat quarantine remove-all |
| 격리 관리 | 격리에 대한 위협으로 검색된 파일 추가 | mdatp threat quarantine add --id [threat-id] |
| 격리 관리 | 격리에서 위협으로 검색된 파일 제거 | mdatp threat quarantine remove --id [threat-id] |
| 격리 관리 | 격리에서 파일을 복원하세요. Defender for Endpoint의 101.23092.0012 이전 버전에서 사용할 수 있습니다. |
mdatp threat quarantine restore --id [threat-id] --path [destination-folder] |
| 격리 관리 | 위협 ID를 사용해 격리에서 파일을 복원하세요. 엔드포인트용 Defender 버전 101.23092.0012 이상에서 사용할 수 있습니다. |
mdatp threat quarantine restore threat-id --id [threat-id] --destination-path [destination-folder] |
| 격리 관리 | 격리에서 파일을 원래 경로를 사용해 복원하세요. 엔드포인트용 Defender 버전 101.23092.0012 이상에서 사용할 수 있습니다. |
mdatp threat quarantine restore threat-path --path [threat-original-path] --destination-path [destination-folder] |
| 네트워크 보호 구성 | 네트워크 보호 집행 수준을 설정하세요 | mdatp config network-protection enforcement-level --value [block\|audit\|disabled] |
| 네트워크 보호 관리 | 네트워크 보호가 성공적으로 시작되었는지 확인하세요 | mdatp health --field network_protection_status |
| 디바이스 제어 관리 | 장치 제어가 활성화되어 있는지와 기본 강제 수준을 확인하세요 | mdatp device-control policy preferences list |
| 디바이스 제어 관리 | 활성 장치 제어 규칙 보기 | mdatp device-control policy rules list |
| 디바이스 제어 관리 | 장치 제어 정책에서 참조하는 그룹을 확인하세요 | mdatp device-control policy groups list |
| 구성 | 데이터 손실 방지 기능을 켜거나 끄기 | mdatp config data_loss_prevention --value [enabled/disabled] |
| 진단 | 로그 수준 변경 | mdatp log level set --level [error\|warning\|info\|debug] |
| 진단 | 진단 로그 생성 | mdatp diagnostic create --path [directory] |
| 상태 정보 | 제품 상태 확인 | mdatp health |
| 상태 | 특정 제품 속성을 확인하세요. 예를 들어 healthy, licensed, engine_version |
mdatp health --field [attribute] |
| Edr | 장치 태그를 설정하세요.
GROUP만 지원됩니다. |
mdatp edr tag set --name GROUP --value [name] |
| Edr | 장치에서 그룹 태그를 제거하세요 | mdatp edr tag remove --tag-name [name] |
| Edr | 그룹 ID 추가하기 | mdatp edr group-ids --group-id [group] |
명령줄 자동완성 활성화
Bash에서 자동 완성을 활성화하려면 Defender for Endpoint 완료 스크립트를 Bash 프로필에 추가한 후 터미널 세션을 재시작하세요:
echo "source /Applications/Microsoft\ Defender.app/Contents/Resources/Tools/mdatp_completion.bash" >> ~/.bash_profile
Z 셸(zsh)에서 자동완성을 활성화하려면 다음 단계를 따르세요:
디바이스에서 자동 완성이 사용하도록 설정되어 있는지 확인합니다.
cat ~/.zshrc | grep autoload명령어가 출력이 나오지 않는다면, zsh 프로필에서 자동 완성을 활성화하세요:
echo "autoload -Uz compinit && compinit" >> ~/.zshrc완료 디렉터리를 만들고 Defender for Endpoint 완성 스크립트를 연결하세요:
sudo mkdir -p /usr/local/share/zsh/site-functions sudo ln -svf "/Applications/Microsoft Defender.app/Contents/Resources/Tools/mdatp_completion.zsh" /usr/local/share/zsh/site-functions/_mdatp
클라이언트 격리 디렉터리 관리
Defender for Endpoint는 격리된 파일을 /Library/Application Support/Microsoft/Defender/quarantine/에 저장합니다. 파일 이름은 위협 추적 ID를 사용합니다. 현재 추적 ID를 보려면 mdatp threat list를 실행하세요. 파일을 직접 수정하지 말고 격리된 파일을 관리하는 명령어를 사용 mdatp threat quarantine 하세요.
Defender for Endpoint 설치 해제
Defender for Endpoint를 제거하기 전에 기기를 오프보드하고 해당 기기를 관리하는 정책을 제거하거나 업데이트하세요. 선택적 디바이스 사용 중지 태그, 변조 방지 요구 사항, 오프보딩 패키지 및 시스템 확장 정책 정리에 대해서는 Mac 디바이스 오프보딩을 참조하세요.
앱을 대화형으로 또는 명령줄에서 제거할 수 있습니다. Jamf Pro로 기기를 관리한다면, 애플리케이션을 제거하기 전에 오프보딩 프로필을 배포하세요. 중앙에서 관리하는 삭제 기능은 현재 Microsoft Intune에서 제공되지 않습니다.
대화형으로 제거
Finder에서 Applications를 열고 Ctrl → Microsoft Defender를 클릭한 후 휴지통으로 이동을 선택하세요.
명령줄에서 제거
터미널에서 sudo '/Library/Application Support/Microsoft/Defender/uninstall/uninstall' 실행하세요.
제거하기 전에 Jamf Pro에서 오프보딩하기
Jamf Pro는 Defender for Endpoint에 포함되지 않은 별도의 서드파티 제품이며, Defender for Endpoint 구독에도 포함되어 있지 않습니다. Jamf Pro를 사용하려면 별도의 Jamf Pro 구독이 필요합니다. 제품 및 구독 정보는 Jamf Pro를 참조하세요. 귀하의 조직에서 Jamf Pro를 사용하지 않는다면, 이 글에서 제공하는 다른 구성 방법을 사용해 보세요.
애플리케이션을 제거하기 전에 Jamf Pro를 통해 장치를 오프보드하려면, Jamf 지침을 따라 설정 프로필을 업로드하세요. Defender for Endpoint 오프보딩 프로필을 수정하지 않고 업로드한 다음, Preference Domain을 com.microsoft.wdav.atp.offboarding로 설정합니다.
참고 사항
Defender for Endpoint 삭제에 문제가 있고 보고서에 Microsoft Defender Endpoint Security Extension 항목이 포함되어 있다면, 다음 단계를 따라 하세요:
Microsoft Defender 앱을 다시 설치합니다.
Microsoft Defender.app휴지통으로 끌어옵니다.
터미널에서 다음 명령을 실행합니다.
sudo '/Library/Application Support/Microsoft/Defender/uninstall/install_helper' execute --path '/Library/Application Support/Microsoft/Defender/uninstall/uninstall' --args --post-uninstall-hook디바이스를 다시 시작합니다.
Microsoft Defender 포털 사용
Microsoft Defender 포털을 이용해 탐지 결과를 검토하고 장치에 대응 조치를 취하세요. 자세한 내용은 다음 리소스를 참조하세요.