> ## Documentation Index
> Fetch the complete documentation index at: https://silmaril.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Verify protection

> Check the app, connection, and live activity before expanding a rollout.

export const macosRelease = {
  "version": "0.3.22",
  "build": "1077",
  "guardianEnabled": false,
  "minimumOS": "macOS 14 or later",
  "dmgUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled.dmg",
  "pkgUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled.pkg",
  "mdmZipUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled-MDM.zip",
  "mdmChecksumUrl": "https://downloads.silmaril.dev/macos/releases/0.3.22/1077/Silmaril-0.3.22-1077-guardian-disabled-MDM.zip.sha256",
  "mdmSHA256": "86efaf60414339c97c5fcaac86d98b215f44010798f58e83ea3850b1243fd92a"
};

<a id="setup" />

A successful PKG install, an assigned configuration profile, a Managed label, or a saved direct-install connection does not by itself mean protection is active. New local defaults begin in Shadow mode unless organization policy requires another mode.

## Check the endpoint

<Steps>
  <Step title="Confirm identity">
    Open Settings and check the installed release.

    **Expected result**<br />
    Settings shows Stable {macosRelease.version}, build {macosRelease.build}, and Guardian Disabled.

    **If this differs**<br />
    Contact support before replacing an incompatible installed variant. Jamf and Iru treat {macosRelease.build} as a minimum build so an install check can accept a newer build. Verification of this Stable release still expects the version and build named here.
  </Step>

  <Step title="Confirm policy and connection">
    For MDM deployments, inspect the connection and each setting your profile forces in Settings.

    Direct installs store the typed API key in the user's login Keychain. Connection fields are not Managed unless a profile is also installed. On MDM Macs, the profile supplies the URL and key.

    **Expected result**<br />
    MDM Macs show Managed for the API URL, API key, and every other setting you intended to force. There is no Applying, Restart required, or Needs attention state. When the first-run connection screen is displayed, it reports Firewall connection verified.

    **If this differs**<br />
    Resolve pending or failed states with [troubleshooting](/docs/macos/troubleshooting). Correct invalid profile values using the [settings reference](/docs/macos/settings). They do not silently fall back to local values. For Restart required, fully quit and reopen the affected agent and start a new session.
  </Step>

  <Step title="Confirm the baseline stayed in place">
    Compare the pilot Mac's assignments and configuration profiles before and after the Silmaril rollout. These are administrator checks in your MDM.

    They are separate from live Protection activity.

    **Expected result**<br />
    The pilot Mac still has the baseline controls that were present before Silmaril, and it also has the Silmaril profile. A Mac outside the Silmaril tag, group, or label keeps that baseline and has no new Silmaril assignment.

    **If this differs**<br />
    Stop the rollout. Restore any missing baseline profile, and remove a Silmaril assignment from any Mac that was outside the intended scope.
  </Step>

  <Step title="Confirm live protection">
    Prepare supported agents and start a new agent session.

    **Expected result**<br />
    A new session produces current activity in Protection.

    **If this differs**<br />
    The endpoint is not confirmed protected. Recheck identity and connection, resolve any Restart required state, and start another new session. Package status, profile assignment, and a Managed label can all be true while this activity is still absent.
  </Step>
</Steps>
