Securing a Mac fleet: what to set first
Start with automated enrolment, FileVault with escrowed recovery keys, enforced update deadlines and standard user accounts. Those four deal with the problems we see most often on a Mac fleet, and the other six build on them. All ten below can be enforced from any mainstream MDM, whether that is Jamf, Intune or another.
The first ten settings on a managed Mac fleet
- Automated Device Enrollment. Macs registered in Apple Business Manager enrol themselves at first start-up, and users cannot remove the management profile.
- FileVault on, recovery key escrowed to the MDM. A lost laptop stays a hardware cost, and IT can still unlock a disk when the user forgets their password.
- Enforced update deadlines. Reminders get ignored. A deadline set in the MDM is the difference between a patch released and a patch installed.
- Standard user accounts. Admin rights let malware and mistakes change the system itself. Much Mac malware steals what the user can already reach without them, which is why EDR is on this list too. Give elevation on request, time-bound and logged.
- Screen lock after a short idle time. Five to ten minutes, with the password required straight away. An unlocked laptop in a café bypasses every other control.
- Firewall on. It costs nothing on a laptop that moves between home, office and hotel networks.
- Gatekeeper enforced. Only apps from the App Store or identified developers run, and the MDM stops users overriding the check.
- EDR deployed and pre-approved. Push the agent together with its system extension and privacy permissions, so it runs on every Mac without a user clicking “Allow”.
- Sharing services off by default. Remote login, screen sharing and file sharing stay disabled unless a role needs them.
- Lost-device response tested. Activation Lock managed through the MDM, and remote lock and wipe tried on a spare machine before you need them.
Where to find a macOS security baseline
Apple documents each of these controls in its Platform Deployment guide, including FileVault escrow and software update enforcement. For a fuller baseline, the NIST macOS Security Compliance Project publishes rule sets and generates configuration profiles from them. Treat it as a menu to choose from, not a list to apply whole: some rules will break tools your staff rely on.
How to roll out Mac security settings
Change one thing at a time and send it to a pilot group first. Removing admin rights is the change people notice, so it goes last, after the elevation process works. Keep the MDM compliance report as your evidence: it is what a customer questionnaire or a SOC 2 readiness effort will ask to see.
Questions we are asked
What should we set first on a Mac fleet?
Start with automated enrolment, FileVault with escrowed recovery keys, enforced update deadlines and standard user accounts. Those four deal with the problems we see most often on a Mac fleet, and the other six build on them.
Do Macs need an EDR agent?
For most organizations, yes. The protections built into macOS block a lot of known malware, but they do not give you a record of what happened on a laptop or a way to respond remotely. That is the job of an EDR agent.
Should developers keep local admin rights?
Rarely all the time. Most developer tasks that seem to need admin rights can be handled with package managers installed per user, or with time-bound elevation that is logged and expires on its own.
How quickly should macOS updates be enforced?
A common policy is a deadline of about a week for minor and security updates, shorter when an update fixes a flaw already being exploited, and a planned window for major macOS releases once your key apps support them.
Related
Signing in to those Macs is the other half of the picture, covered on identity and workplace security. For device trust as part of a wider access model, see zero trust without buying a product.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Checking your own fleet
If you want the ten checked against what your MDM actually enforces, that is our macOS fleet and MDM security review. More pieces are indexed at writing.