# How to integrate Drata with Hexnode UEM for Mac

Drata is an automation tool for security and compliance that continuously tracks and gathers proof of a business’s security measures while optimizing operations to assure audit readiness. Drata offers various features via its 60+ advanced integrations, making centralized compliance management simple.

With Hexnode’s integration with Drata, organizations can effectively manage compliance-related info on all their Macs. Once the integration is complete, Drata can retrieve compliance-related information from Hexnode via an API connection rather than installing an agent on a device. This integration enhances the compliance assurance offered by Hexnode’s features. Drata not only extracts compliance-related data from Hexnode UEM and makes it available via the Drata portal, but it also generates reports and notifies the IT administrator in case there are any compliance-related discrepancies.

Start managing the compliance of your company’s Mac devices by learning how to integrate Hexnode with Drata & configure compliance-related policies.

Integrating Drata with Hexnode UEM
----------------------------------

### In the Hexnode UEM console,

1. Log in to your Hexnode UEM console using the admin credentials.
2. Navigate to the **Enroll** tab. Copy the Server URL, this has to be entered as the API URL in Drata during setup.
[![URL of the Hexnode server](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2023/03/Hexnode-server-API-URL.png "Hexnode server API URL")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2023/03/Hexnode-server-API-URL.png)

4. Now, navigate to **Admin > API**. [![Accessing Hexnode API settings from the Admin tab](https:2023/03/Hexnode-API-settings.png "Hexnode API settings")](https:2023/03/Hexnode-API-settings.png)
5. In the API window, copy the **API key** and save it somewhere safe. This API key is required to configure the integration in the Drata portal.
[![Hexnode API key to establish an integration](https:2023/03/Hexnode-API-Token.png "Hexnode API token")](https:2023/03/Hexnode-API-Token.png)

### In Drata portal,

1. In Drata, once you are signed in with your company’s credentials, select your company’s name from the blue sidebar present on the lower left. Select **Connections** from the menu that pops up.
[![Select the company menu to access the Connections tab](https:2023/03/Accessing-the-available-Connections-via-Company-menu-in-Drata.png "Accessing the available Connections via Company menu in Drata")](https:2023/03/Accessing-the-available-Connections-via-Company-menu-in-Drata.png)

3. The list of connections i.e., integrations will be displayed, scroll down and select Hexnode from the list of available integrations and click **Connect**.
[![Choose Hexnode from the list of available integrations](https:2023/03/Selecting-Hexnode-from-the-available-Connections.png "Selecting Hexnode from the available Connections")](https:2023/03/Selecting-Hexnode-from-the-available-Connections.png)

5. Once you click **Connect**, a dialog box will appear asking for the **API URL** and the **API Token**. Enter the URL of the server & the API key that you copied previously from the Hexnode console, here. Once you have entered the API URL & API key, click on **Save & Test Connection**. Make sure to include *https://* at the beginning of the server URL (API URL).
[![Configuring Hexnode API URL & token in Drata](https:2023/03/Configuring-Hexnode-API-in-Drata.png "Configuring Hexnode API in Drata")](https:2023/03/Configuring-Hexnode-API-in-Drata.png)

7. Now, to configure Hexnode in Drata for employee onboarding, navigate back to your company’s name on the blue sidebar. Select **Internal Security** from the menu that pops up.
[![Accessing Internal Security settings from the Company menu in Drata](https:2023/03/Configuring-Internal-Security-from-the-Company-menu-in-Drata.png "Configuring Internal Security from the Company menu in Drata")](https:2023/03/Configuring-Internal-Security-from-the-Company-menu-in-Drata.png)

9. In the Internal Security tab, enable **Automated via Hexnode MDM** and disable **Automated via Drata Agent**.
[![Turn ON Automated via Hexnode MDM option](https:2023/03/Enable-Automated-via-Hexnode-MDM-option.png "Enable Automated via Hexnode MDM option")](https:2023/03/Enable-Automated-via-Hexnode-MDM-option.png)

 Note:If both options are enabled, the Drata agent will be installed on the personnel’s Mac. The Drata agent will take precedence over any MDM. As a result, the employee compliance data is fetched by the Drata agent & not by Hexnode.

 

12. Once these steps are completed, compliance-related policies for macOS devices should be configured in Hexnode UEM.

How to configure compliance-related policies in Hexnode?
--------------------------------------------------------

The policies for Mac devices, such as FileVault, Firewall, Screensaver, Software updates, etc., should be configured in the Hexnode UEM portal & associated with the devices that need to be monitored. This enables Drata to gather compliance information related to macOS disc encryption, network security, screen settings, & macOS updates based on the policies.

So, once when the devices are enrolled and corresponding restrictions and policies are associated with them in Hexnode, Drata monitors and reports the compliance-related information. Follow the steps given below to configure policies related to Mac compliance.

### FileVault

- Navigate to **Policies > New Policy > New Blank Policy**. Click **Select**.
- Provide a suitable policy name that includes the term **“FileVault”** so that Drata can detect the policy.
- Navigate to **macOS > Security > FileVault** and click **Configure**.
- Ensure that the **“Enable FileVault”** and **“Show Personal Recovery Key to user”** boxes are checked and configure the remaining fields as per requirement. For more information and step-by-step explanations, please refer to our document on [FileVault](https://www.hexnode.com/mobile-device-management/help/how-to-manage-filevault-with-hexnode-mdm/).
[![FileVault policy configuration in Hexnode portal](https:2023/03/FileVault-policy-configuration.png "FileVault policy configuration")](https:2023/03/FileVault-policy-configuration.png)

- Navigate to **Policy Targets > Add devices** and select the devices to which the FileVault policy must be associated.
- Click **Save**.

### Firewall

- Navigate to **Policies > New Policy > New Blank Policy**. Click **Select**.
- Provide a suitable policy name that includes the term **“Firewall”** so that Drata can detect the policy.
- Navigate to **macOS > Security > Firewall** and click **Configure**.
- Ensure that the **“Enable Firewall”** and **“Allow incoming connections”** options are checked and configure the remaining fields as per requirement. For more information and step-by-step explanations, please refer to our document on [Firewall for Mac](https://www.hexnode.com/mobile-device-management/help/how-to-configure-firewall-for-mac-with-hexnode-mdm/).
[![Firewall policy configuration in Hexnode portal](https:2023/03/Firewall-policy-configuration.png "Firewall policy configuration")](https:2023/03/Firewall-policy-configuration.png)

- Navigate to **Policy Targets > Add devices** and select the devices to which the Firewall policy must be associated.
- Click **Save**.

### Screensaver

- Navigate to **Policies > New Policy > New Blank Policy**. Click **Select**.
- Provide a suitable policy name that includes the term **“Screensaver”** so that Drata can detect the policy.
- Navigate to **macOS > Configurations > Screensaver** and click **Configure**.
- Ensure that the **“Enable Screensaver”** and **“Require Password to unlock screen”** options are checked.
- It is recommended to set both **“Login window screensaver idle time”** & **“Screensaver idle time”** as 1 min. Also, it is recommended to set **“Set delay for password prompt”** as **“immediately”**. For more information and step-by-step explanations, please refer to our document on configuring the [Screensaver policy for Mac](https://www.hexnode.com/mobile-device-management/help/how-to-configure-screensaver-for-macos-devices-using-hexnode-mdm/).
[![Screensaver policy configuration in Hexnode portal](https:2023/03/Screensaver-policy-configuration.png "Screensaver policy configuration")](https:2023/03/Screensaver-policy-configuration.png)

- Navigate to **Policy Targets > Add devices** and select the devices to which the Screensaver policy must be associated.
- Click **Save**.

### Software Update

- Navigate to **Policies > New Policy > New Blank Policy**. Click **Select**.
- Provide a suitable policy name that includes the term **“Software Update”** so that Drata can detect the policy.
- Navigate to **macOS > Security > OS Updates** and click **Configure**.
- It is recommended to set **“Choose your OS update settings”** as **“Install”**. For more information and step-by-step explanations, please refer to our document on [scheduling OS updates on Mac](https://www.hexnode.com/mobile-device-management/help/how-to-schedule-macos-updates-using-hexnode-mdm/).
[![Software Update policy configuration in Hexnode portal](https:2023/03/Software-Update-policy-configuration.png "Software Update policy configuration")](https:2023/03/Software-Update-policy-configuration.png)

- Navigate to **Policy Targets > Add devices** and select the devices to which the Schedule OS updates policy must be associated.
- Click **Save**.

### Gate Keeper

- Navigate to **Policies > New Policy > New Blank Policy**. Click **Select**.
- Provide a suitable policy name that includes the term **“Gate Keeper”** so that Drata can detect the policy.
- Navigate to **macOS > Advanced Restrictions** and click **Configure**.
- The following options are recommended to be configured under Advanced Restrictions.
- Check all the options under **“Device Functionality and Personalization”**.
- Check all the options under **“Security & Privacy”** excluding the **“Activation Lock”** option.
- In the **“App installation From”** dropdown, select **“Mac App Store and Identified Developers”**.
[![Advanced Restrictions policy configuration in Hexnode portal](https:2023/03/Advanced-Restrictions-policy-configuration.png "Advanced Restrictions policy configuration")](https:2023/03/Advanced-Restrictions-policy-configuration.png)

- Uncheck all the options under **“App Store”**. For more information and step-by-step explanations, please refer to our document on [Advanced restrictions](https://www.hexnode.com/mobile-device-management/help/macos-mdm-restrictions/#advanced-mac-restrictions) for Mac.
[![Configuring App Store options in Advanced Restrictions for Mac](https:2023/03/App-Store-options-in-Advanced-Restrictions-policy-configuration.png "App Store options in Advanced Restrictions policy configuration")](https:2023/03/App-Store-options-in-Advanced-Restrictions-policy-configuration.png)

- Navigate to **Policy Targets > Add devices** and select the devices to which the Gate Keeper policy must be associated.
- Click **Save**.

The integration is now complete and Drata will fetch essential data regarding macOS devices enrolled in Hexnode UEM based on the configured policies.