macOS fleet and MDM security
A macOS fleet and MDM security review checks how your Macs are enrolled, configured, encrypted, patched and monitored through your device management platform, and whether you can prove it. Most Mac fleets are managed. Far fewer are managed to a standard anyone has written down, and the gap shows up the first time a customer asks for proof.
Why Mac fleets drift
Macs usually arrive in a company before the security programme does. The MDM gets set up to push Wi-Fi and a few apps, and the settings that matter for security are added later, one incident or questionnaire at a time.
The result is familiar. Many users still have local admin rights. A few laptops were enrolled by hand and never picked up the FileVault profile. Nobody can say how many machines are more than one macOS release behind.
What we review on a managed Mac fleet
Enrolment
Whether every Mac comes in through Automated Device Enrollment in Apple Business Manager, so users cannot remove the management profile, and how many devices were enrolled some other way.
Configuration profiles
What is actually enforced: screen lock, firewall, Gatekeeper, sharing services, and the privacy permissions your security tools need to run.
FileVault and key escrow
Whether disks are encrypted and each recovery key is escrowed to the MDM, so a lost laptop is a device problem rather than a data problem.
Patch cadence
How quickly macOS and third-party app updates reach the fleet, and whether deadlines are enforced or only suggested.
Admin rights and app control
Who is a local administrator and why, whether elevation is time-bound, and what stops an unsigned or unwanted app from running.
EDR coverage
Whether your endpoint detection agent is installed, approved and reporting on every Mac, not just on the ones someone checked.
Evidence for SOC 2 and customer questionnaires
Yes. It produces the endpoint evidence a SOC 2 or ISO 27001 readiness effort typically asks for: encryption status, patch compliance, admin rights and EDR coverage, exported from the MDM rather than described from memory. The same exports answer much of the endpoint section of an enterprise security questionnaire. See SOC 2 and ISO 27001 readiness for the wider programme.
Identity sits next to this work. If your Macs sign in with Entra ID or Google accounts, the tenant side is covered on identity and workplace security.
What you receive
| Deliverable | What it is for |
|---|---|
| Fleet review report | Findings per control area, with the number of devices affected |
| Baseline profile set | The configuration your MDM should enforce, written for your platform |
| Rollout plan | Staged so the change most likely to annoy staff goes to a pilot group first |
| Evidence pack | Exports that show the controls are working, ready for a customer or a readiness assessor |
We do not run your MDM day to day. The plan is written so your IT lead or managed provider can carry it out. The first ten settings we usually look at are listed in securing a Mac fleet: what to set first.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
What does a macOS fleet security review cover?
A macOS fleet and MDM security review checks how your Macs are enrolled, configured, encrypted, patched and monitored through your device management platform, and whether you can prove it.
Do we have to change our MDM?
No. The review works with whatever you already run, whether that is Jamf, Microsoft Intune or another MDM. We suggest a change of platform only when the current one cannot enforce something you need.
What access do you need?
Usually a read-only account in the MDM console, plus a short call with whoever manages the Macs day to day. We do not need to touch the laptops.
Does this help with SOC 2 or customer questionnaires?
Yes. It produces the endpoint evidence a SOC 2 or ISO 27001 readiness effort typically asks for: encryption status, patch compliance, admin rights and EDR coverage, exported from the MDM rather than described from memory.
Find out where your Macs stand
Tell us roughly how many Macs you manage, which MDM you use and what prompted the question. The reply says what a review would cover. See also all security services.