Lesson 1: Introduction to Apple Platform Security - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Discover how Apple devices are designed to protect users. Understand how administrators can extend this protection to their organizations.

Video

Key points

  • Apple devices are designed to secure user data with intuitive features.

  • The Secure Enclave is a subsystem of the Apple system on a chip (SoC) that isolates security-related tasks from the rest of the system.

    • Biometric data such as Touch ID and Face ID information is protected by the Secure Enclave.

    • The Secure Enclave is included in all M- series chips, later A- series chips, and Intel-based Mac computers with the T2 security chip.

  • Encryption ensures data is not vulnerable to attackers.

    • Secure Enclave AES engines ensure storage encryption is fast and efficient.

    • Mobile devices will be encrypted when a passcode is set.

    • Mac computers can be encrypted by activating FileVault.

  • Security features such as encryption can be enforced on managed devices using configuration profiles deployed with Jamf Pro.

  • Jamf Protect can be used to create security baselines that meet common benchmarks, like those published by the Center for Internet Security (CIS®) and the National Institute of Standards and Technology (NIST).

    • Jamf Protect can also detect and quarantine known malware to protect organizations from threats.

  • Devices should be kept updated to protect them from emerging security vulnerabilities.

    • Jamf Pro and Jamf Protect can be used to manage updates and report on device compliance.

Review

To view answers, click arrow next to each question.

  1. Encryption
  2. Secure Enclave
  3. Jamf Pro can be used to enable built-in security features on devices and to ensure they stay up to date.
  4. Jamf Protect uses compliance benchmarks, like those from CIS and NIST, to create compliance baselines that ensure a consistent level of device security within an organization.

Practice

  1. In Jamf Pro, create a configuration profile that will require a passcode on devices in scope.

    1. Navigate to Devices > Configuration Profiles.

    2. Click New.

    3. In the list of payloads, click Passcode, then select Require Passcode. Configure any additional options as desired.

    4. Click Scope and add a test device as a target, then click Save.

  2. In Jamf Protect, confirm that a computer is configured to receive automatic updates.

    1. Navigate to Computers and click the name of a computer.

    2. Click Compliance Details.

    3. In the list of rules, find Download New Updates Enabled, MacOS Update Installs Enabled, and Auto Update Enabled and observe whether all three report a pass status.

Resources

Jamf Online Training Catalog

Jamf Pro Documentation

Jamf

Apple