Jamf Pro access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Jamf Pro, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Jamf Pro connector needs.
Checks (3)
severity: medium Local Admin Account On Managed Mac fix difficulty: medium #
Review standing local administrator accounts on managed Macs
- Confirm the local admin account is required (vs a managed-by-Jamf privilege-elevation workflow)
- Demote unnecessary local admins to standard users
- Consider Jamf Pro's Privilege Elevation / LAPS for just-in-time admin
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: medium Policy Ongoing Self Service Script fix difficulty: medium #
Review user-triggered Self Service policies that run scripts
- Confirm the script the policy runs is safe for end-user invocation
- Restrict the policy scope or remove Self Service availability if not needed
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: medium API Role Overbroad fix difficulty: medium #
Review API roles granting an unusually large number of privileges
- Open Settings > API Roles and Clients and review the role's privileges
- Remove privileges not required by the integration (least privilege)
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3