macOS Big Sur elevates the most advanced desktop operating system in the world to a new level of power and beauty. Experience Mac to the fullest with a refined new design. Enjoy the biggest Safari update ever. Discover new features for Maps and Messages. Get even more transparency around your privacy.
The following models are supported:
In this article we will cover how to get old versions of macOS including Catalina, Mojave, El Capitan, Sierra, Yosemite and even old versions of Mac OS X. We explain how to get hold of the relevant.
To see which model you have, click the Apple icon in your menu bar and choose About This Mac.
Before you upgrade, we recommend that you back up your Mac. If your Mac is running OS X Mavericks 10.9 or later, you can upgrade directly to macOS Big Sur. You’ll need the following:
Go to Software Update in System Preferences to find macOS Big Sur. Click Upgrade Now and follow the onscreen instructions.
If you’re running any release from macOS 10.13 to 10.9, you can upgrade to macOS Big Sur from the App Store. If you’re running Mountain Lion 10.8, you will need to upgrade to El Capitan 10.11 first.
If you don’t have broadband access, you can upgrade your Mac at any Apple Store.
For details about your Mac model, click the Apple icon at the top left of your screen and choose About This Mac. These Mac models are compatible with macOS Big Sur:
Requires a broadband internet connection and microphone (built-in or external).
Supported by the following Mac models:
Requires a microphone (built-in or external).
Requires a broadband internet connection.
Requires a Multi-Touch trackpad, Force Touch trackpad, Magic Trackpad, or Magic Mouse.
Force Touch gestures require a Force Touch trackpad.
VoiceOver gestures require a Multi-Touch trackpad, Force Touch trackpad, or Magic Trackpad.
Requires a FaceTime or iSight camera (built-in or external) or USB video class (UVC) camera.
Audio calls require a microphone (built-in or external) and broadband internet connection.
Video calls require a built-in FaceTime camera, an iSight camera (built-in or external), or a USB video class (UVC) camera; and broadband internet connection.
High dynamic range (HDR) video playback is supported by the following Mac models:
Dolby Atmos soundtrack playback is supported by the following Mac models:
Supported by the following Mac models:
Supported by all iPad models with Apple Pencil support:
Requires an iPhone or iPad that supports iOS 12 or later.
Requires an iPhone with iOS 13 or later or an iPad with iPadOS 13 or later.
Requires an iPhone or iPad with a Lightning connector or with USB-C and iOS 8 or later.
Requires an iPhone or iPad with cellular connectivity, a Lightning connector or USB-C, and iOS 8.1 or later. Requires Personal Hotspot service through your carrier.
Requires an iPhone or iPad with a Lightning connector or with USB-C and iOS 10 or later.
Requires an Apple Watch with watchOS 3 or later or an iPhone 5 or later.
Requires an Apple Watch with watchOS 6 or later or an iPhone 6s or later with iOS 13 or later.
Requires a MacBook Pro or MacBook Air with Touch ID, an iPhone 6 or later with iOS 10 or later, or an Apple Watch with watchOS 3 or later.
Requires an iPhone with iOS 8 or later and an activated carrier plan.
Requires an iPhone with iOS 8.1 or later and an activated carrier plan.
Requires an iPhone with iOS 12 or later and a configured Home app.
AirDrop to iOS and iPadOS devices requires an iPhone or iPad with a Lightning connector or with USB-C and iOS 7 or later.
AirPlay Mirroring requires an Apple TV (2nd generation or later).
AirPlay for web video requires an Apple TV (2nd generation or later).
Peer-to-peer AirPlay requires a Mac (2012 or later) and an Apple TV (3rd generation rev A, model A1469 or later) with Apple TV software 7.0 or later.
Requires an external storage device (sold separately).
Requires an iPhone with iOS 14 and a compatible electric vehicle.
Requires an iPhone running iOS 14 or an iPad running iPadOS 14.
Allows Boot Camp installations of Windows 10 on supported Mac models.
Requires Microsoft Office 365, Exchange 2016, Exchange 2013, or Exchange Server 2010. Installing the latest Service Packs is recommended.
Supports OS X 10.7 or later and Windows 7 or later.
Available only to persons age 13 or older in the U.S. and many other countries and regions.
The improved Retouch tool is supported on the following Mac models:
Please see Compatibility between Symantec Endpoint Protection for Mac and versions of Mac OS X for specific Symantec Endpoint Protection version requirements. Note: You may see 'System Extension Blocked' when installing SEP on macOS version 10.13, or newer -- this may be resolved by authorizing Symantec kernel extensions by using the macOS Security & Privacy system preference pane.
For minor updates to Mac OS X, such as 10.14.4 to 10.14.5, the Symantec Endpoint Protection client can remain in place.
For a major update to Mac OS X on a client system (from OS X 10.13 to OS X 10.14, for example), upgrade the Symantec Endpoint Protection client to the version that is compatible with the newer operating system, and then upgrade the operating system. Otherwise, uninstall the Symantec Endpoint Protection client and cleanly reinstall the compatible version after upgrade to avoid possible corruption to logs and other Symantec Endpoint Protection components.
Although Symantec does not officially support Mac OS X Server, there are only minor differences between Mac OS X and Mac OS X Server; Symantec Endpoint Protection for Mac will function and scan for threats as expected. For guidance on best practices, please see Recommendations for installing Symantec Endpoint Protection for Macintosh on Mac OS X Server.
Installing the Symantec Endpoint Protection client for Mac covers both managed and unmanaged installations. Push deployment from the Symantec Endpoint Protection Manager (using the Client Deployment Wizard) is supported as of Symantec Endpoint Protection 12.1.5.
Endpoint Protection client for Mac versions earlier than 12.1.4 must be uninstalled before you upgrade to version 14. You do not need to uninstall later versions first. See Supported upgrade paths to Symantec Endpoint Protection.
Auto-Upgrade is supported as of 14, but cannot be used to upgrade from 12.1. You must export a client package for the new version then install or deploy as you would a new installation; it is not possible to use the Upgrade Groups with Package wizard (auto-upgrade) to migrate Macintosh clients up to a later client version. However, you can usually install the new version directly over the old without uninstalling first; see the previous question.
As of version 14, you can uninstall through the menu bar once the SEP client UI is open. See Uninstalling the Symantec Endpoint Protection client for Mac for more information.
The Symantec Endpoint Protection Manager cannot host Macintosh LiveUpdate content the same way as it does for Windows clients. As of Symantec Endpoint Protection version 12.1 RU4 the Symantec Endpoint Protection Manager can be configured as a reverse proxy for downloading and caching the latest Macintosh LiveUpdate content. All Macintosh updates otherwise must otherwise occur through Symantec LiveUpdate or from an internal LiveUpdate Administrator (LUA) server. Please see Using the LiveUpdate Administrator 2.x to download updates for Symantec Endpoint Protection for Macintosh for information on how to configure LUA for this content.
Note: it is not recommended or supported for LiveUpdate Administrator and Symantec Endpoint Protection Manager to be on the same physical server. If you are looking for the standalone definitions updater, Intelligent Updater, for the Symantec Endpoint Protection (SEP) client for Mac, please refer to 'Intelligent Updater and Endpoint Protection for Macintosh'.
No, for the same reasons outlined above.
No.
Rapid Release definitions are not available for Mac security products.
Daily, usually in the morning Pacific time (west coast, USA).
Connection Status: Connected appears under Management on the Symantec QuickMenu.
Yes, see How to convert an unmanaged Symantec Endpoint Protection for Macintosh client to managed for more information.
Windows-specific policies will not apply to Macs; only those policies which contain Mac specific settings will be parsed and applied by the SEP for Mac client.
No.
Version 14 introduced Device Control for the Mac client. You can enable Device Control on managed clients only. See Allowing or blocking devices on client computers and Mac Device Control.
It is not tested or supported.
Even though the command can be sent, these features are not supported for Symantec Endpoint Protection for Mac clients.
In the latest version of Symantec Endpoint Protection, Virus and Spyware Protection and Network Threat Protection can be disabled/re-enabled by unloading/loading the SymDaemon service:
sudo launchctl unload /Library/LaunchDaemons/com.symantec.symdaemon.*plist
sudo launchctl load /Library/LaunchDaemons/com.symantec.symdaemon.*plist
# the asterisk in daemon pathnames will accommodate suffix variations - SEP 14.0+ use com.symantec.symdaemon.NFM.plist
Location Awareness was introduced for Symantec Endpoint Protection for Mac clients in version 12.1. Supported conditions for ALS and Mac clients:
- Computer IP Address
- Gateway Address
- DNS Server address
- DHCP server address
- Network connection Type
- Management Server connection
- DNS Lookup
- Wireless SSID
- DHCP connection DNS suffix
- ICMP request (ping)
It is not possible to convert a SEP for Mac client to User Mode. Onlly Computer Mode will work.
There are not many changes that the end user can make, but if you want to prevent them from disabling Auto-Protect or Network Threat Protection (intrusion prevention), make sure their group is set to Server Control and unlock the padlock icon within the appropriate policy types.
When the policy types are locked and/or the group is set to Server Control, SEP for Mac UI options will be disabled and grey. When unlocked, they will be green and changeable for an admin-level account.
The macOS Parental Controls feature, used to manage users in order to restrict applications that are launched on the system, could be used to restrict the manual launch of LiveUpdate. However, under normal circumstances, Administrator and Standard users alike should be able to launch LiveUpdate manually, whether the LiveUpdate policy is checked allowing clients to manually launch LiveUpdate or not.
No. SEP for Mac only performs file system virus/spyware scanning. There is no proxying of incoming or outgoing messages for email clients like Mail or Entourage, as there is in the optional email component of SEP for Windows. SEP for Mac AutoProtect does monitor and scan everything that is being written to the hard drive, including attachments that a user may attempt to save from an email message. However, email client inboxes and other email archives may become corrupt if SEP scans mail folders under the user profile directories. As a best practice, those directories should be excluded from SEP scans. See How to create a Security Risk Exception for a Mac client and check the documentation for your email client.
The GatherSymantecInfo tool can be used to collect SEP for Mac client data. An exported System Profiler report will often also provide a lot of information about the system in question.
There may also be /Library/Application Support/Symantec/LiveUpdate/liveupdate.conf but this location is overwritten every time LiveUpdate runs. Do not edit this file. It is a temporary record of the settings last used and combined from /etc/liveupdate.conf and the Mac OS Network settings.
For the installation, no separate log is written. Instead it is written to the system's installation log, which is most easily viewable via the Console application. With Console open, show the log list if it is not already showing. Click to expand Files, click to expand /private/var/log, and then look for install.log (see image below). After listing some environmental variables, the phrase 'Symantec Endpoint Protection Installation Log' appears at the beginning of the installation cycle.
This document can be used to enable Sylink debugging for client communication problems with the Symantec Endpoint Protection Manager.
When using System Information / System Profiler, instead of printing, however, you will want to save the file. Before saving, under View, ensure 'Full Profile' is selected.
About System Information and System Profiler