- In Jamf Pro, click Compliance in the sidebar.
- Click Create benchmark.
- Select a benchmark template from the available templates.
For more information on benchmark templates, see Compliance Benchmarks Template Reference.
- Use the General pane to configure basic settings for the benchmark, including the display name, description, and enforcement type.Note:
The display name for a benchmark cannot be changed after you create it. The benchmark name prefixes the names of the automatically created management settings (e.g., policies, smart groups, configuration profiles), but those names can be changed after they are generated.
Best Practice:Jamf recommends beginning your compliance benchmarks implementation with a Monitor only enforcement type. For more information, see Enforcement Types.
- Click Next.
- Configure the scope of the compliance benchmark configuration.Note:
You can select one or more smart or static groups.
- Click Next.
- (Optional) Customize individual compliance rules for the configuration.You can customize the benchmark by choosing which rules to include in your deployment. All rules are selected by default, but any rule can be deselected to create a customized configuration. You can also view specific details associated with each rule. Certain rules contain organization-defined values (ODVs) that can be defined during this step. For more information, see Rule Reporting.Note:
To customize what macOS versions the benchmark configuration applies to, click Settings, and then select or deselect the available macOS versions to include or exclude them from the configuration. If you deselect a macOS version, no management settings will be created for that macOS version, and no computers with that macOS version will receive any management settings.
- Click Next.
- Review the deployment.
When reviewing the deployment, you can view the collection of management settings that will be created. For configuration profiles, extension attributes, and scripts, you can view specific contents of the setting prior to deployment.
- Click Save and deploy.
The new compliance benchmark configuration is created and deployed to the specified devices. The generation of management settings can take up to 15 minutes. The benchmark card will display "In Progress" during this process. After all settings have been generated, the card will display "Deployed".