To ensure your server is as secure as possible, you can enable the following security-related settings in Jamf Pro:
- Configure the Password Policy for Jamf Pro user accounts —For more information, see Jamf Pro User Accounts and Groups in the Jamf Pro Documentation.
- Enable the minimum required privileges —Enable the minimum privileges required by your organization for all user accounts and groups. For more information, see the following topics in the Jamf Pro Documentation:
- Configure the Change Management settings to log changes —Log the changes in Jamf Pro by configuring the Change Management settings (automatically enabled for Jamf Cloud instances). For more information, see Change Management in the Jamf Pro Documentation.
- Schedule log flushing at appropriate intervals —For more information, see Log Flushing in the Jamf Pro Documentation.
- Require user authentication to Self Service —For more information, see Jamf Self Service for macOS User Login Settings in the Jamf Pro Documentation.
- Require users to authenticate when enrolling via automated MDM enrollment —Require users to authenticate during computer or mobile device setup when enrolling via Apple's Automated Device Enrollment using a PreStage enrollment in Jamf Pro. For more information, see Automated Device Enrollment for Computers and Automated Device Enrollment for Mobile Devices in the Jamf Pro Documentation.
- Use multi-factor authentication —Enable multi-factor authentication (e.g., single sign-on) for Jamf Pro user authentication. For more information, see Single Sign-On (SSO) in the Jamf Pro Documentation.