Enabling the Firewall and Gatekeeper

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

Enabling the macOS firewall helps prevent unwanted incoming connections from reaching managed computers, and you may want to enable it depending on the other network protections you have in place.

Enabling Gatekeeper controls where apps can be downloaded from.

Use the Security and Privacy payload to configure firewall and Gatekeeper settings for managed computers. Firewall settings are in the payload's Firewall section. Gatekeeper settings are in the payload's General section.

  1. On the Configuration Profiles page, do one of the following:
    • Click New to create a new configuration profile.

    • Select an existing configuration profile and click Edit .

  2. Click the Security and Privacy payload, and then click Firewall.
  3. In the Firewall settings change area, click Restrict.
  4. In the Firewall area, click Enable, and then configure the following additional options:
    1. Select Block all incoming connections to prevent incoming connections to nonessential apps and services.
      Note:

      Stealth Mode is automatically enabled, and cannot be disabled, when you select this option. For more information, see Firewall MDM payload settings for Apple devices in Apple Platform Deployment.

    2. Select Control incoming connections for specific apps to restrict incoming connections for specific apps. Click the Add button, and enter the app titles for which you want to allow or block connections.
      Note:

      Stealth Mode can be disabled if you select this option.

  5. Click General in the Security and Privacy payload.
  6. In the Gatekeeper section, select Mac App Store and identified developers.
  7. In the Temporarily overriding the Gatekeeper setting by control-clicking to install any app section, click Restrict.
  8. Click the Scope tab and configure the scope of the configuration profile.
  9. Click Save .