Jamf Pro configuration hardening security checks
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
On Jamf Pro, Black Cat runs 16 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Jamf Pro connector needs.
Checks (16)
severity: high Computer SIP Disabled fix difficulty: medium #
Re-enable System Integrity Protection on Macs reporting SIP disabled
- Identify the affected Mac from the finding
- Boot to Recovery and run csrutil enable, then reboot
- Investigate why SIP was disabled (developer override, malware, MDM drift)
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: high Computer Gatekeeper Disabled fix difficulty: easy #
Re-enable Gatekeeper to block unsigned applications
- Deploy a configuration profile enforcing Gatekeeper (allow App Store and identified developers)
- Or run spctl --master-enable on the affected device
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Computer Firewall Disabled fix difficulty: easy #
Enable the application firewall via a Security configuration profile
- Deploy a Security & Privacy configuration profile with the firewall enabled
- Scope it to all managed computers
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Computer Remote Desktop Enabled fix difficulty: easy #
Review Macs with Apple Remote Desktop / Screen Sharing enabled
- Confirm remote management is intentional for the affected Mac
- Disable Remote Management in System Settings > Sharing if not required
- Restrict ARD access to specific admin accounts only
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Computer OS Outdated fix difficulty: medium #
Update Macs running macOS below the supported major version floor
- Identify the affected Mac and its current macOS version
- Deploy a software update policy or enforce a minimum OS configuration profile
- Confirm the device reports a supported macOS version after update
Satisfies: NIS2 Directive NIS2-21.e.2 DORA (SaaS Security) DORA-8.3
severity: low Computer Recovery Lock Missing fix difficulty: easy #
Set a Recovery Lock on Apple silicon Macs to protect recoveryOS
- Deploy a Set Recovery Lock command from Jamf Pro to the affected Mac
- Confirm recoveryLockEnabled is true after the command completes
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Computer Secure Boot Reduced fix difficulty: medium #
Restore full Secure Boot security on Macs reporting reduced or no security
- Boot the affected Mac to Recovery and open Startup Security Utility
- Set Secure Boot to Full Security
- Investigate why secure boot was reduced (kext install, downgrade)
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium Mobile Device Unsupervised fix difficulty: medium #
Bring unsupervised mobile devices under supervision for full management
- Re-enroll the device via Automated Device Enrollment (ADE) to gain supervision
- Confirm supervised reports true after re-enrollment
Satisfies: NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: high Mobile Device Unmanaged fix difficulty: medium #
Re-establish MDM management on mobile devices reporting unmanaged
- Investigate why the device lost management (MDM profile removed, jailbreak)
- Re-enroll the device or remove the stale record
Satisfies: NIS2 Directive NIS2-21.i.6 DORA (SaaS Security) DORA-9.13
severity: medium Mobile Device OS Outdated fix difficulty: medium #
Update mobile devices running an OS below the supported major version floor
- Identify the affected device and its current OS version
- Push an OS update command or enforce a minimum OS version
Satisfies: NIS2 Directive NIS2-21.e.2 DORA (SaaS Security) DORA-8.3
severity: medium Configuration Profile User Removable fix difficulty: easy #
Make security configuration profiles non-removable by end users
- Edit the profile in Jamf Pro and set the distribution to not allow user removal
- Re-deploy the profile to affected computers
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium API Integration Long Token Lifetime fix difficulty: easy #
Reduce the access token lifetime for API integrations issuing long-lived tokens
- Open Settings > API Roles and Clients and edit the API client
- Lower the access token lifetime to 30 minutes or less
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium SSO Not Enabled fix difficulty: medium #
Enable single sign-on for Jamf Pro so admin and end-user auth flows through the IdP
- In Jamf Pro go to Settings > Single sign-on
- Configure the SAML or OIDC identity provider metadata
- Enable single sign-on and confirm a test login succeeds
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: medium SSO Bypass Allowed fix difficulty: easy #
Disable the single sign-on bypass so local Jamf credentials cannot skip the IdP
- In Jamf Pro go to Settings > Single sign-on
- Turn off "Allow Bypass" (or the enrollment/local-login SSO bypass option)
- Re-scan to confirm sso_bypass_allowed is false
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low SSO Not Enforced For Enrollment fix difficulty: easy #
Require single sign-on during device enrollment
- In Jamf Pro go to Settings > Single sign-on
- Enable "Use for Enrollment" (SSO for enrollment)
- Re-enroll a test device to confirm the IdP prompt appears
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10
severity: low SSO Not Enforced For macOS Self Service fix difficulty: easy #
Require single sign-on for macOS Self Service authentication
- In Jamf Pro go to Settings > Single sign-on
- Enable "Use for Self Service" (SSO for macOS Self Service)
- Confirm end users are redirected to the IdP when opening Self Service
Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10