Apple Device Security Basics for Admins
Apple Device Security Basics for Admins
Security
FOR BEGINNERS
A well-planned cyberattack or an accidental malware download can
mean the difference between a productive day and all work grinding
to a halt. As hackers get more sophisticated, organizations concerned
about their bottom line and the security of their users’ data, like
customers, employees or students, must stay on top of security.
Apple security concerns, like all IT security concerns, are quite real and pose a critical
threat to organizational resources and stakeholder safety.
Apple makes incredibly secure operating systems; there’s no doubt that its focus
on the security and privacy protections baked into its hardware and software has
played a significant role in its rise in popularity and mass adoption within enterprises,
education institutions and other industry organizations. And as Apple continues to
be the platform of choice for personal and professional hardware, it has become a
more attractive target for attackers. This means that administrators must respond
quickly to security incidents as they arise and not wait until an issue occurs. Instead,
MacAdmins and security teams (and the stakeholders they support) are better served
proactively guarding against them before threats can evolve into something far worse
by leveraging solutions tailored or purpose-built for Apple to protect against Apple-
centric threats effectively.
This guide is for administrators and managers who want to get serious about the
organizational security of their Apple devices and offers basic information for
newcomers or even a simple refresher for Apple management veterans.
1 4
Security systems already Securing data at rest and in
built in to macOS, iOS, transit, on device and
iPadOS and tvOS in network at all times
Enrolled devices:
Enrolling and deploying Compliance monitoring:
2 5
devices with secure, Monitoring devices to
centralized management determine health status
3 6
Protecting your physical
and patching:
Staying up to date with
devices and safeguarding
operating system, app and
your users from threats
software patches
BUILDING BLOCK ONE: pple operating systems are based on UNIX underpinnings which creates a rich
A
computing foundation from a mature, well-researched platform with deep development
Security
Notarization
Gatekeeper
XProtect
Apple devices are the most-secure out-of-
Malware Removal Tool (MRT)
the-box hardware options on the market,
Transparency, Consent and Control (TCC)
and purpose-built management and security
Rapid Security Responses
solutions extend the power of Apple.
Lockdown mode
Physical device security in the form of locking and lost device tracking
with the Find My service
Ability to implement and configure security controls through configuration options via
mobile device management (MDM)
Secure enrollment modes are built in to Apple devices, such as Automated Device Enrollment
and User-initiated enrollment for company- and/or personally-owned devices to meet all
ownership model needs (like BYOD, CYOD and COPE) without risky enrollment URLs or
suspicious email invitations
Seamless integration with Apple Business Manager or Apple School Manager to aid in
centrally managing all institutional hardware, including enabling Supervision of devices over-
the-air and secure hand-off to your MDM solution for device management functions, like
managed app deployment, secure device provisioning and zero-touch onboarding workflows
Find My Find My
App Sandboxing
Securely Enrolled With Automated Device Enrollment, you can inform Apple of all devices your organization
owns, as well as other ownership models discussed below, and assign them to be managed
Devices and
by your organization’s MDM. Then, when an enrolled device in this program powers on, it will:
Deployments
Enable Supervision, which is integral for allowing tighter
security controls
Allow administrators to apply configuration profiles and harden settings
This is where your organization’s MDM and flexible device ownership models meet to form the solution of multiple device ownership models, such as:
Bring Your Own Device (BYOD) Choose Your Own Device (CYOD) Company-Owned Personally
Enabled (COPE)
Arguably the most common model, This a variation on BYOD above, except
allowing users to use their personally that often, the organization or institution The COPE model is a growing trend
owned devices to access business owns the devices used in this model and among larger organizations, especially
resources. By requiring that users are to be used in carrying out job-related those that have gone fully remote or
manually enroll their devices in the functions or in the pursuit of learning (in with hybrid work environments. Here,
organization’s MDM before gaining the case of education.) By instituting a organizations purchase and own the
access to work resources, the dual-fold program of employee choice, stakeholders equipment, while enrolling and managing
benefit is that users can rest assured that can choose which Apple device meets it fully within the organization’s MDM.
they will obtain the tools necessary to their needs best. Each device is enrolled, Like CYOD, the tools necessary for
access the data and services required assigned to a stakeholder and managed stakeholders to perform their job tasks
for them to perform their job functions; by the organization’s MDM. The apps, are installed and managed according to
organizations rest easier knowing that configuration profiles, device settings and the device and the company’s security
enrolled devices are provided the security software are provisioned according posture. But similar to BYOD, the
necessary security software and settings to a baseline of the organization’s security organization allows and even encourages
to keep business data secured while in posture and taking into account the users to utilize the devices for personal
use, at rest and in transit. assignee’s job requirements. use alongside professional usage. This
ensures that company data stays secure
within managed apps and configuration
profiles. While this can open up the issue
of personal, private data being accessible
to companies via COPE devices, it’s
important to consider the privacy of the
data and provide the right amount of
management and privacy to these devices
through means of Acceptable Use Policies
(AUPs) and data managment.
Once enrolled, personally owned devices are manageable through the MDM, with administrators permitted to
install managed apps, deploy configuration profiles and modify certain settings using a set of configurations
allowing organizations to set device-specific requirements as well as associate management actions or
requirements with the user, not the entire device. Apple designs the limitation to allow organizations to take the
steps necessary to secure how their data is accessed, interacts with apps, is stored on device and transmitted
over networks without impacting the personal apps, data and private information on the device. Organizations
can customize the visibility of managed devices by associating a personal Apple ID with personal data and a
Managed Apple ID with company data.
Securing Devices If we look back at some of the largest, most complex and even deadliest data
breaches in recent history, we’ll find a common thread. Attacks such as Stuxnet
disabled Iran’s nuclear enrichment program by infecting a contractor’s laptop
Keeping devices, data and users safe performing updates to the SCADA equipment. LinkedIn was targeted by a
developer that exploited its API to effectively scrape PII from 700 million users
from threats
before selling the data dump online. Aadhaar—home to the largest ID database,
including PII and financial data, for more than 1.1 billion Indian citizens—was
“Hackers only need to get it right once; stolen and sold by threat actors after gaining entry through an unprotected
website linked to the database. In these and similar cases, attacks were made
we need to get it right every time.”
possible by targeting and compromising just one device.
— Chris Triolo, HP
REAL-WORLD SCENARIOS Simply put: Devices get lost and stolen. Accidents
and moments of inattention happen. Yet, planning —
with the assumption that it is only a matter of when,
A remote employee is prepping legal documents for an ongoing liability not if, someone will lose track of a device — is a
case being argued in court and is working from a nearby coffee shop. They vital key toward ensuring that the proper mitigation
leave the company-owned Mac laptop unattended briefly while refilling their strategies are in place to minimize risk before
coffee at the precise moment a thief swoops in and steals the laptop. With the devices become lost or stolen.
device unlocked, the attacker has unfettered access to sensitive and possibly
confidential company information that could negatively impact current legal Additional consideration points for user and data
proceedings and the company’s reputation. security are that many devices — especially those
serving students and patients or shared device
In a second example, a student using their personally owned iPhone to access environments serving multiple users — require
school-related resources via the educational portal misplaces their device while safeguards against misuse, the accidental discovery
changing classes. Another user finds the phone and proceeds to access the of another’s data or the access and viewing of risky
student’s account details, gaining access to sensitive PII, like their address, and inappropriate content.
phone number or student ID. An unauthorized user can utilize PII information Depending on your organization’s unique needs,
like this for identity theft or to commit crimes while impersonating the victim. hardening settings for security while configuring
The device may even be further compromised with malware and returned to devices so that they’re aligned with organizational
the victim, placing their safety and well-being at risk from remote tracking and and compliance requirements could be a
stalking by threat actors. considerable undertaking that is time and labor-
intensive, especially as device counts grow.
Require passwords on all devices Require passwords on all devices Require passwords on all Apple TVs
Enable Find My Mac through System Enable Find My Mac through System
Configure restrictions:
Preferences>iCloud Preferences>iCloud From the main menu, go to
Depend on individual users to be able to
Depend on individual users to be able to sign Settings>General>Restrictions
sign into iCloud or remember their password into iCloud or remember their password Select Restrictions to turn it on
(prerequisite to enabling FindMy)
Track all inventory by device serial numbers or When asked, make a four-digit passcode
Report to Apple if a device was lost or asset tags
Enter the four digits again to confirm,
stolen while enabling the ability to initiate
Report to Apple if a device was lost or stolen then select OK
wipe/erase while enabling the ability to initiate wipe/erase
Remember the passcode
Track all inventory by Mac serial numbers or
Enable parental controls on an individual
asset tags Repeat for all Apple TVs
device, creating different accounts for
Enable parental controls on the device to each device
To restrict Airplay for Apple TV:
block inappropriate content and malicious
Keep iOS-based devices up to date
websites (using Safari browser)
From the main menu, go to Settings >
with all system and app updates to
Select AirPlay
Keep Macs up to date with all system and minimize vulnerabilities
app updates to minimize vulnerabilities
Turn AirPlay on or off
Configure and harden device settings to
Configure and harden device settings to minimize misconfigurations that could leave Choose from:
On a best-of-breed MDM solution, like Jamf Pro, the same management tasks performed above to secure or restrict
devices goes like this:
Set all restrictions and security features from the first use
Implement parental controls and block access to risky or
or enable them automatically with Supervision and trusted inappropriate apps, applying granular restrictions based on
configuration profiles and policies certain criteria or to all devices at once
Lock or wipe any lost or misused device remotely,
Deploy managed applications necessary for users to remain
regardless of its physical location — and regardless of productive at home, in the office, at school or anywhere else.
whether the device has an iCloud account signed in or not Pre-approve apps to be hosted within the Self Service app,
(no Apple ID required) empowering users to access the software they need exactly
when they need it
Enable multiple users to securely share devices by wiping
a device between uses and allowing users to use their
Integrate endpoint security solutions with your MDM to ensure
credentials and settings that are connected to the user — that devices are constantly monitored and protected against
not the device security threats while sharing rich telemetry data with the
MDM to enable policy-based management for automating
Configure managed Apple IDs to be assigned to the
incident response
device for business tasks while allowing the user to access
personal apps, data and settings stored in iCloud with their
Manage each facet of device management tasks centrally to
consumer Apple ID ensure devices, users and data remain secure against cyber
threats while upholding user privacy
Maintain inventory of all devices, including the ability to
group them by any category — not just serial number or
asset tag — to glean any data necessary, such as user
Not only does this experience streamline work for IT administrators
assignments, OS version or apps installed to name a few
and staff, but it also supports the end users. It provides the experience
Perform management tasks that issue commands to a people love and have come to expect from Apple without sacrificing
single device or in bulk, such as deploying security updates, organizational, industry compliance and security requirements or user
upgrading to a new OS version or administratively clearing privacy in favor of tighter security controls.
forgotten passcodes on locked devices
Below is a summary of the three states of data at any given time on a device:
BUILDING BLOCK FOUR:
Data at rest: stored locally Data in motion: transferred Data in use: neither kept
REAL-WORLD SCENARIOS
A new hire in the HR department at your organization receives their new Mac and quickly
completes the setup process to begin working. One of their job functions requires creating an
emergency contact tree using spreadsheet software, including each employee’s name, job title,
company email address, personal address, personal contact number and specifying whether they
are a primary or alternate contact. This information is to be backed up locally to the computer,
including the personal contact information for members of the management and C-suite teams,
and a duplicate copy must be made available to authorized stakeholders to access from a cloud
repository securely.
In the scenario above, the portions in bold indicate a specific example of each data
state. First, “using spreadsheet software” is an example of data in use, indicating that
data must remain secure while it’s being worked with within the app. This requires
the software’s integrity to be checked and verified to ensure that a threat actor
or malicious code has not compromised its internal security. Second, “backed up
locally” is an example of data at rest, indicating the criticality of enabling encryption
to prevent data from being accessed and read by unauthorized individuals. Third,
“securely access from a cloud repository” is an example of data in motion, as in
data sent and received across a network connection. The network connections
used for communication must be encrypted end-to-end, ensuring that only the two
connections at either end can successfully decrypt the message and protect this data
from unauthorized receipt or eavesdropping attacks.
And while this third data state may sound a lot like legacy VPN services, the
component that separates it from legacy VPN is the wording “authorized
stakeholders,” since Zero Trust Network Access (ZTNA) provides encryption for
data in motion, ZTNA also integrates with your identity provider (IdP) ensuring only
users and devices that have both authenticated successfully and are provisioned
the necessary access permissions are granted access to the requested resources
behind additional layers of protection, upholding the principle of least privilege.
Also, unlike legacy VPN services which often grant access to the entire network
once authenticated, ZTNA’s implementation of securing connections utilizes micro-
tunnels to establish a unique tunnel for each protected app or service. This provides
greater security by enforcing the principle of least privilege while employing health
checks to ensure that devices meet minimum requirements — in conjunction
with user authentication requirements — each time a request is made and before
granting access.
Take for example some common security incidents that are effectively mitigated by enabling full device or volume encryption:
macOS already has built in volume encryption in FileVault. To manually enable
You don’t have to add any additional software to encrypt a
folder, disk or volume on a Mac.
FileVault on macOS:
Newer Macs, like those powered by Apple Silicon, rely on
the secure enclave. A dedicated hardware component that Navigate to System Settings > Privacy & Security > FileVault
handles the creation and storage of encryption keys while
Select the button “Turn On…” to enable volume encryption
also performing algorithmic calculations.
Repeat for all devices
Intel-based Macs rely on a similar dedicated hardware
component named the T2 security chip to perform similar
functionality to the secure enclave. To enable FileVault across your organization’s devices, leverage your
FileVault is FIPS 140-2 certified. That means Apple’s MDM solution to automate, deploy and enforce encryption. You can
encryption system is certified by and meets the highest deploy a configuration profile or policy that will enable FileVault. IT
standards for federal government encryption. can retrieve recovery keys if staff need to decrypt the volume down
the road.
You can enable FileVault manually or remotely: personal
users can choose the option on one device, or IT can
automate and enforce enablement (using Jamf Pro) across Create a configuration profile through a simple selection of
hundreds or even thousands of devices with one policy. options within Jamf Pro
Grant users access to encrypt/decrypt volumes simply by Deploy granularly to as many devices as you’d like or to all
authenticating to macOS or entering their passcode on macOS-based devices
iOS and iPadOS devices. Users of supported devices can
There is no step three
leverage Apple’s TouchID or FaceID technologies to add a
layer of security to data protection through biometrics using
either their fingerprint or facial recognition patterns. With Jamf Pro, you can also configure recovery key redirection —
even if the user turns on FileVault themselves. IT will then have
the key saved within its management solution for easy retrieval by
device record.
Encrypting iOS and iPadOS devices is even easier. iOS-based devices have built in encryption
enabled as soon as a passcode is set. You can do this individually, or you can require it from
Jamf Pro, as well as setting the parameters for passcode strength, such as minimum length and
complexity requirements.
Data in transit
Encrypting network connections from end-to-end
Conventional best practices dictated the use of a VPN to protect data as it moves from one device
to another service. This method heralds back decades, being developed at a time when VPNs
were used to bridge two disparate networks securely over an untrusted network, like the Internet.
And while this security control still remains in active use by many personal and enterprise users,
changes in the computing landscape over the last few years, stemming from the adoption of Apple
at work, the explosive growth of mobile devices for personal and business use and organizations
migrating to fully remote and hybrid work environments has revealed the limits of VPN technology
to effectively protect devices, users and data across the modern threat landscape.
These changes have all combined to revolutionize the way we work — and play — on computers
and mobile devices. So, why are you still relying on legacy processes for your security strategy to
keep data in motion safe?
The answer short answer is Zero Trust Network Access, or ZTNA for short. The long answer is
that this solution was developed from the very real-world need to keep various types of devices,
local and distributed users and teams. Also, data accessed over untrusted networks and relying on
cloud-based services to extend infrastructure while eroding the organization’s network perimeter.
All this while securing them against existing and novel security threats employed by threat actors,
with a notable increase in threats targeting macOS and mobile devices in general.
Simply put: Securing network connections is no longer just for employees traveling or a few special
use cases to remain productive remotely.
patches, ensure that security integrity remains intact Select “Add VPN
T
ype in the VPN server address
by checking for jailbroken or rooted devices and that Configuration”
on the device
endpoint security is both installed and configured T
ype in the VPN server
properly. S
elect it from your
address on the device
network options
If endpoints fail a health check or have been deemed
S
elect it from your
compromised, ZTNA integration with a best-of-breed Repeat for each device
network options
MDM solution, like Jamf Pro, enables policy-based
management by securely sharing telemetry data to Repeat for each device
suspend access and execute remediation workflows
to perform the necessary tasks to bring the endpoint
into compliance, verifying that any detected issue(s) are To connect multiple devices to a VPN: “How can I be sure that my
resolved. encryption is seamless?”
After you have set up a VPN provider
Forgoing implicit trust, like legacy VPNs, instead One important way of ensuring
C
reate a configuration profile in an
operating by the mantra of “never trust — always security and consistent encryption is
MDM such as Jamf for iOS
verify” each time access to any requested company to host your MDM in the cloud. With a
and/or macOS
resource is made. It is only after verification has occurred reputable product such as Jamf Cloud,
D
eploy configurations to however you can rest easy knowing that your
successfully that access to the requested resource
many devices you’d like server is secure and your data safe,
is granted.
Y
ou guessed it — there is no and that any updates or patches are
step three immediately available.
Security is enhanced by shifting from implicit trust to the explicit Zero Trust model that
requires verifying users and devices before granting access to requested resources.
Split-tunneling secures business traffic while personal traffic is routed directly to the
Internet — not back to a central network, reducing overhead and saving bandwidth,
which equals greater performance and improved privacy protection for end users.
Always-on protection means that resources are protected — even if the service is
disabled — upon requesting access, it will automatically enable to ensure traffic
remains protected every time.
A minimal footprint and cloud hosting means no expensive support contracts, complex
configurations or hardware to manage.
It also supports macOS, iOS, iPadOS, Android and Windows, which lowers the TCO
and alleviates the administrative burden on IT teams supporting multiple hardware and
software types.
In this section, we’ve discussed the basics of data encryption, the types of solutions native
to Apple devices and even explained the steps to enable this security control on macOS,
iOS and iPadOS. We’ve also discussed how modern ZTNA technology goes beyond legacy
VPN protection by continuing to secure remote network connections while including
additional layers of security to verify users and devices before granting access requests
and ensuring that data remains secure at rest (former) and in motion (latter). But what about
when data is being used, or processed by apps?
Unlock the other two data states; data in use does not have a specific security control to
mitigate this risk. Instead the solution lies in conjunction with ongoing management and
security workflows.
When apps access and process data, the data passes from the memory (RAM) to the app for
processing, then gets swapped back to memory before being saved permanently on the device’s
storage. Apps developed by known, trusted developers all contain security mechanisms to ensure
the app’s internal security remains intact. Among the many reasons for this, one such reason is to
ensure that data processed within an app is not shared with or leaked with other apps, services
or processes running on the device. This is designed to uphold the integrity of the data while the
app’s integrity is maintained.
However, apps that have become compromised through an exploit to a vulnerability had
unauthorized modifications to their internal security or are rogue apps, marketed as performing one
task really performing other clandestine tasks all place data security at risk while in use.
So, what’s the best solution, you ask? The answers below include a combination of best practices,
a defense-in-depth strategy, and processes and workflows leveraging Jamf Pro to keep data in use
as secure as possible:
A continual patch management policy that procures applications from legitimate sources, like
the Apple App Store, developer website, or from a trusted management vendor — like App
Installers with Jamf.
Deploying managed apps through your preferred MDM solution and implementing policy-
based management to keep apps up to date.
Verifying secure device settings by installing configuration profiles to minimize the possibility of
threats from misconfigurations.
Harden device settings to restrict risky behaviors that could introduce threats, like jailbreaking
iOS or iPadOS, or side-loading applications from unauthorized or insecure sources.
Implementing an ongoing user training program to keep stakeholders informed of common
threats and how certain actions, like Shadow IT, introduce risk.
Develop an Acceptable Use Policy (AUP) that all stakeholders sign to make them aware of
behavior expectations and consequences of violating company policy.
5 insight into the security controls, settings and health status, IT can better protect
devices, users and data while making sure that endpoints that are out-of-scope are
quickly remediated and brought back into compliance before threats can lead to far
worse outcomes, like data breaches.
BUILDING BLOCK FIVE: As with most of the building blocks in this e-book, there are multiple paths to
monitor endpoint compliance: manual and automated methods. Depending on your
Compliance
organization’s requirements, compliance monitoring’s efficacy can be impacted by
contributing factors, such as knowledge base, device and security management
solutions used and budgetary considerations, to name a few of the most critical.
As a last consideration, the number and types of devices supported an increase in size, the
time for IT and Security to respond to issues manually will also increase exponentially. This
gives threat actors more time to expand threats in their attack chain against organizations,
simultaneously increasing the risk of a data breach.
The ability to see device inventory statuses helps administrators keep their finger on the pulse
of every Apple device in their fleet. By knowing the current status of a device, administrators
can efficiently manage devices and security by knowing which updates to send where, and
which security features to configure respectively. Creating Smart Groups, based on dynamic
criteria means that administrators can be as targeted or all-encompassing in updates as they
choose. Whether based on granular permissions, specific device types, or virtually any other
categorization method, Jamf Pro provides powerful tools to make short work of compliance-
related tasks while maintaining the flexibility to zero in (or send tasks to all devices in your fleet)
through customizable criteria. Learn more with our Inventory Management for Beginners e-book.
Audit endpoints based on Center for Internet Security (CIS) benchmarks
Stream all your compliance data to the cloud for centralized management
Access macOS unified logs and comprehensive endpoint telemetry to identify
threats quickly and efficiently
Enforce compliance using policies to automate remediation tasks and keep
endpoints in-scope
Monitor for Common Vulnerabilities and Exposures (CVE) to understand the
vulnerabilities that exist in your environment
Prevent security threats using comprehensive analytics mapped to the MITRE
&TTACK framework
Securely share telemetry data between management (Jamf Pro) and security (Jamf
Protect) solutions via API to develop advanced workflows to automatically minimize
incident response times and resolve identified issues without delay
It’s not enough to secure your devices; many regulations mandate that organizations be
able to prove that devices continue to be secure and meet compliance requirements.
This means organizations must provide documentation to corroborate compliance levels
during various points in their timeline. After all, if you can’t provide evidence the device
was compliant at a given time, then for all intents and purposes — it wasn’t compliant.
However, Jamf’s data and reporting provides organizations with the necessary tools
to obtain telemetry data from every endpoint and organize this data using critical
categorizations, like patch levels, vulnerabilities detected and timestamps that identify
actions performed during the device’s lifecycle. Plus, integration allows the secure
sharing of telemetry data with first- and third-party tools to further extend data through
centralized dashboards to include data visualizations and export to other formats for
sharing compliance reports with regulatory investigators.
Security and Knowing that identified vulnerabilities are patched is vital to the
device’s security posture. But do you know where your applications
Management
come from? And are you confident that they don’t contain malware or
other malicious code? The answer to those questions is critical to your
organization because if you can’t trust your application sources, you
risk compromising the security of your devices, as well as end-user
privacy and exposing sensitive data.
Patch reporting, policies and App
Installers to maintain apps updated Apple makes preserving security and privacy a top priority. When
while enforcing security easily. it comes to app security, they make apps as safe as possible to
download and use.
5
latest version of their hosted apps directly in the hands of Restrictions on app usage: On iOS-based devices, the
users, eliminating the possibility of introducing risk from only secure way to get apps is via the App Store. That
downloading illegitimate software from risky sources. said, jailbreaking iOS and iPadOS devices introduces
the ability to access third-party app stores that are often
used to distribute apps that have been “cracked”, or had
their internal security removed, such as paid apps that
3
are made available for free but often have been injected
Notarization signs off on security integrity: Notarizing
with malicious code by threat actors to steal data or spy
apps gives users more confidence that software signed by
on users. With an MDM, like Jamf Pro, administrators
a developer’s unique ID — and downloaded to your Mac —
can set up alerts to notify them when jailbroken devices
has been checked by Apple for malicious components and
are identified, allowing them to perform remediation
code-signing issues. When an app is notarized, you can
workflows to correct the security issue.
trust it hasn’t been tampered with or compromised.
On macOS, users (or administrators with an MDM) may select from two
Gatekeeper options:
Confining macOS users to the Mac App Store for their apps allows adminstrators to
control app security device-wide while minimizing the risk of introducing threats —
malicious or otherwise — from suspicious, risky and/or compromised apps. However,
if requiring third-party apps that are only available from the developer’s website,
the second option permits obtaining apps from both the App Store and identified
developers that are vetted by Apple and create software packages signed with their
respective developer ID for greater security.
For macOS, configure allowing the Mac App Store and identified developers selection,
especially if you create your own applications or repackage apps for deployment. Also,
apply for a developer ID from Apple and sign internally-developed applications by the
organization so Gatekeeper will trust them. Lastly, by using Jamf Pro as your MDM solution,
the Self Service app catalog can be deployed to all devices, whereby IT pre-approves apps,
settings, configurations and much more to end users, allowing them to access and install the
tools and services they need, when they need them, without requiring a help desk ticket,
modification of permissions or an Apple ID.
Navigate to: System Settings > Privacy & Security > Security
et up and deploy a configuration profile with your Gatekeeper settings to all your
S
devices.
That’s it!
Organizations must implement a patch management strategy to test for Let’s review some of the options available to administrators managing
and incorporate bug fixes as quickly as possible to keep their hardware, patches manually and via MDM:
data and users protected. Testing is an often overlooked necessity when
Options for managing patches manually:
deploying patches, especially when bugs present themselves in the form
Educate users to perform updates themselves as soon as they receive
of security vulnerabilities that need to be addressed as quickly as possible.
update notifications on their devices.
By performing both as soon as possible, IT reduces the impact of security
Collect all devices when a new patch is released a new patch and
threats spreading while introducing greater issues — stemming from patches
manually deploy.
that fix one thing but inadvertently break other, more critical functions — to
Remediate devices missing patches as part of your ongoing compliance
a minimum.
monitoring processes.
Throughout this e-book, the trend of how long administrative tasks performed
by IT will take to complete is directly correlated to the number of devices Options for managing patches via MDM (i.e. Jamf Pro):
managed. When managing patches, this rule continues to be the case except
for one variable: the number of patches required to deploy could range from
Updates and patch notifications are automatically received by Jamf, along
few to many, exponentially increasing the administrative tasks by an unknown with tools for deploying patches to all of your organization’s devices, so
quantity per device. you can update on your timetable — not someone else’s.
Jamf’s Self Service app catalog makes it easy to empower users to
update anytime a new patch is available by notifying users that they need
to update before continuing to use an affected app.
Eliminate the reliance on end users while alleviating the burden on IT by
automating patch distribution. Send out patches as policies to all devices,
or target them with dynamic Smart Groups to ensure that devices are up
to date.
To learn more about the app lifecycle and automating and deploying apps, check out our white paper.
V
ideo camera surveillance There’s an app for that! Jamf Trust protects against user-initiated risks, like
S
ecurity guards that patrol the grounds the above phishing attack example, by notifying users in the form of Apple
Push Notifications when Jamf detects a threat on their device — like if that
S
moke and carbon monoxide detectors
malicious link that was clicked on previously delivered malicious code in the
F
ire extinguisher form of malware currently recording keystrokes on the device.
H
omeowner’s or renter’s insurance
The solution has determined a threat exists and has informed the user (and
the administrator, as well). Helping the user to be mindful of the danger and
to look out for those like it in the future while IT can respond to the incident
and remediate it quickly, utilizing a combination of Jamf Pro and Jamf
Protect to quarantine the device from the network, clean out the infection,
patch any vulnerabilities present and restore the device to its baseline.
Lastly, use the lessons learned to inform future security awareness training
for stakeholders.
Organizations have the choice to get ahead of many possible attacks or data thefts by implementing the strongest possible
security protections through Apple — and Jamf can make this easier, faster and far more secure and efficient than manual
security protocols.
When it comes to cybersecurity, no one likes surprises and certainly doesn’t want to find themselves scrambling in response
to an attack if they can help it. Get the best security options for your organization by taking Jamf product solutions for
a free trial run, or start by contacting a Jamf representative today to discuss what a customized, comprehensive Apple
management and security solution looks like for your organization’s unique needs.
Try Jamf
[Link]
© 2023 Jamf, LLC. All rights reserved.