Managed Devices

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
In addition to the recommendations provided below, Jamf recommends reviewing the following resources:
Computers and Mobile Devices
Jamf recommends that you use the following suggestions to secure both computers and mobile devices:
  • Improve Automated Device Enrollment by enabling Require Authentication in the PreStage enrollment, and include an Enrollment Customization Configuration to require a Pane Type of either "Single Sign-On Authentication" or "Directory Service Authentication" depending on your environment.

  • Require VPN or Apple Private Relay for remote work.

  • Enforce Wi-Fi encryption (WPA3) when connecting to networks.

  • Enforce device locking after inactivity.

  • Require remote wipe capabilities via MDM for lost or stolen devices.

  • Apply automatic OS updates using managed software updates for security patches.

  • Enforce App Store-only installations or notarized applications.

  • Disable AirDrop or restrict to contacts only.

Computers
Jamf recommends that you use the following suggestions to secure computers:
  • Use Jamf Pro's compliance benchmarks feature to enforce compliance standards, such as CIS Level 1 and 2. For more information, see Compliance Benchmarks Configuration Guide.

  • Define the minimum required macOS version in the PreStage enrollment to be only macOS 14 or later, if possible.

  • Enable Set Recovery Lock Password in PreStage enrollments.

  • Configure passcode complexity for local user accounts by deploying the Passcode payload in a computer configuration profile. Additional settings for controlling Touch ID, iCloud settings, and more are available in the Restrictions payload.

  • Require FileVault encryption. For more information, see Enabling FileVault Disk Encryption Using a Policy in the Jamf Pro Documentation.

  • Use Gatekeeper, XProtect, and System Integrity Protection (SIP) to prevent malware.

  • Lock lost or stolen computers using a specific password.

Mobile Devices
Jamf recommends that you use the following suggestions to secure mobile devices:
  • Enable supervision in Prestage enrollments for Automated Device Enrollment to ensure access to additional security settings and remote commands, including the following:

    • Use Prevent unenrollment to prevent the end user from removing the MDM profile.

    • Use Pairing to allow or disallow the device's ability to connect to Mac computers.

    • Use the Set Activation Lock remote command to manage Activation Lock according to your organization's needs.

    • Use the Enable Lost Mode remote command for lost or stolen devices, and use the Update Device Location remote command to track their location.

  • Ensure iOS encryption is enforced by implementing strong authentication passcodes by deploying the Passcode payload in a mobile device configuration profile. Additional settings for controlling Face ID, Touch ID, iCloud settings, and more are available in the Restrictions payload.

  • Ensure the Make app managed when possible checkbox is selected when distributing apps to keep data secure.

Patch Policies and Reporting
It is important to keep your apps up to date with the latest security patches. For more information, see the Patch Policies and Patch Reporting pages in the Jamf Pro Documentation.
Scripts
Custom or prebuilt scripts are a common way to execute commands for computers, and can be run using a policy. Avoid hard-coding account credentials for Jamf Pro server administrators in scripts.