Skip to content

Jamf Pro access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Jamf Pro, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Jamf Pro connector needs.

Checks (3)

severity: medium Local Admin Account On Managed Mac fix difficulty: medium #

Review standing local administrator accounts on managed Macs

  1. Confirm the local admin account is required (vs a managed-by-Jamf privilege-elevation workflow)
  2. Demote unnecessary local admins to standard users
  3. Consider Jamf Pro's Privilege Elevation / LAPS for just-in-time admin

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: medium Policy Ongoing Self Service Script fix difficulty: medium #

Review user-triggered Self Service policies that run scripts

  1. Confirm the script the policy runs is safe for end-user invocation
  2. Restrict the policy scope or remove Self Service availability if not needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: medium API Role Overbroad fix difficulty: medium #

Review API roles granting an unusually large number of privileges

  1. Open Settings > API Roles and Clients and review the role's privileges
  2. Remove privileges not required by the integration (least privilege)

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

More Jamf Pro checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial