Monitor Only

Compliance Benchmarks Configuration Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Note:

Jamf recommends beginning your compliance benchmarks implementation with a Monitor only enforcement type. After you have established baseline measurements, you can change the benchmark to a Monitor and enforce enforcement type to enforce compliance standards. For more information, see Editing the Scope and Enforcement Type of a Benchmark.

You can create a compliance benchmark specifically for reporting purposes. When configuring a new benchmark, selecting the Monitor only enforcement type enables you to assess your security posture without making automatic changes to device configurations. With this enforcement type, you can see how devices measure against selected security standards without enforcing any modifications to bring devices into compliance.

With the Monitor only enforcement type, you are provided with valuable insights through the compliance benchmarks rule report, where you can view the overall compliance status of your fleet and view specific rules to see which devices meet or fail to meet particular security requirements. This approach is particularly useful during the initial assessment phase of a security program, allowing you to understand your current security posture before implementing enforced changes.

The benchmark can be scoped to specific computers or computer groups, enabling targeted compliance assessment across different segments of the organization. This flexibility allows you to phase your compliance initiatives and establish baseline metrics for different departments or user groups before moving to an enforcement model.