Security-Focused Computer Configuration Profiles

Jamf Trusted Access Solution Guide for Business

Solution
Application
Content Type
Technical Documentation
Solution Guide
Utilities & Services
ft:locale
en-US

As part of your Trusted Access implementation, Jamf recommends that you deploy configuration profiles that include the following security-focused areas:

  • FileVault Disk EncryptionEnsures the data stored on computer hard disks remains secure
  • Firewall and Gatekeeper EnforcementHelps protect managed computers from unwanted network or internet communication
  • Passcode EnforcementRequires end users to use a secure password to log in to the computer

In many environments, best practices for payload management include creating unique configuration profiles to achieve separate goals. This approach reduces complexity in terms of configuring the scope of profiles and identifying issues when troubleshooting.

Creating separate configuration profiles for different purposes allows for easier testing and scoping, and makes future changes easier because you can adjust individual, focused configuration profiles. For example, you may want to create one configuration profile for enabling FileVault and another one for passcode enforcement.

For more information on optimizing payload planning and management, see Plan your configuration profiles for Apple devices in Apple Platform Deployment.

Note:

You can distribute computer configuration profiles during Automated Device Enrollment. This allows you to install configuration profiles before end users complete the Setup Assistant. For example, you can distribute a configuration profile that enforces a passcode policy that end users must comply with during the Setup Assistant. For more information, see Creating a PreStage Enrollment to Deploy the Automated Device Enrollment Experience to Computers.