Jamf Pro lifecycle & offboarding security checks
Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.
On Jamf Pro, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Jamf Pro connector needs.
Checks (3)
severity: medium Computer Stale Check-in fix difficulty: easy #
Investigate or retire Macs that have not checked in for 30+ days
- Filter computers by last contact time in Jamf Pro
- Contact the device owner or flag the asset for retirement
- Remove the record if the device is decommissioned
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: low Computer Activation Lock Enabled fix difficulty: medium #
Review Macs with Activation Lock enabled to avoid wipe/reuse lockout
- Confirm the organization holds the Activation Lock bypass code in Jamf Pro
- Clear Activation Lock before reassigning or wiping the device
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: info API Integration Disabled fix difficulty: easy #
Review disabled API integrations that may be stale
- Confirm the integration is intentionally disabled
- Delete the API client and its role if no longer in use
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6