Cyber Essentials for Jamf Pro: Mac configuration guide
Prepare Jamf Pro Mac configuration and evidence for Cyber Essentials: scope coverage, firewall, supported software, malware protection and optional FileVault hardening.

Section 01
Cyber Essentials for Jamf Pro: Mac configuration guide
Jamf Pro can apply Mac configuration profiles, policies and managed software updates and collect inventory evidence. The common coverage risk is a Smart Group that excludes Macs which have not checked in recently. Verify every in-scope Mac and its actual controls, rather than interpreting Jamf enrolment as automatic certification.
Section 02
1. Enrolment and scope
Automated Device Enrolment through Apple Business Manager and user-initiated enrolment serve different deployment situations. Check enrolment restrictions and ownership rather than assuming users can never skip or remove management. Reconcile All Computers with the scoped asset register and identity activity; device count need not equal user count.
The cleanest coverage approach starts with the full scoped inventory. A recent-check-in group is a health diagnostic, not the complete scope. Keep offline or stale Macs visible in a separate exception/remediation report. Reconcile regularly as local operational practice.
Section 03
2. Configuration profiles - required controls and recommendations
Swipe across the table to view all columns.
| Area | Configuration approach |
|---|---|
| Secure configuration | Remove unnecessary accounts/software, disable automatic login, apply appropriate credential quality, guess protection and locking |
| Firewall | Enable the applicable firewall protection and allow only necessary, approved inbound services |
| Updates | Enable automatic updates where possible; verify required fixes installed within the release-based deadline |
| Malware | Verify qualifying anti-malware or an application allowlisting implementation |
| Additional hardening | FileVault with recovery-key escrow, stealth mode and a ten-minute lock policy where suitable |
Use the applicable credential-quality route and compromise-triggered password changes; do not enforce complexity or regular password expiry. FileVault and stealth mode are local hardening choices, not a mandatory v3.3 bundle. Profile payloads and enforcement depend on supported macOS and Jamf versions.
Section 04
3. Patching and supported macOS
Use Jamf's supported managed-software-update tools, with Nudge or other suitable prompting where needed. Check device eligibility, installation, restarts and missed check-ins. Do not assume a major upgrade is exempt if it is the vendor's applicable vulnerability fix. Verify exact model/release support and security coverage from Apple; there is no universal N-1 rule or permanent macOS 14 minimum.
Section 05
4. Antivirus / EDR
Apple's XProtect detects malware; Gatekeeper checks signing and provenance. Neither name alone proves the complete chosen Cyber Essentials route. Check effective updates, malicious-file prevention, required malicious-website protection and user protection for the anti-malware route, or the actual approval/restriction controls for application allowlisting. Third-party EDR also needs verification against the route; agent installation alone is insufficient.
Deploy supported agents through policies and grant only necessary system-extension/Full Disk Access permissions. A health dashboard supports coverage evidence.
Section 06
5. User access control
Use a standard account for daily work and a separate administrative account for privileged tasks, granting only needed access. Jamf Connect or Platform SSO may integrate authentication, depending on its actual configuration. Touch ID for sudo alone does not establish two independent MFA factors or meet cloud-service MFA requirements.
Section 07
Scheme baseline and local hardening
NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.
Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.
For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.
Section 08
6. Evidence and common failure points
Prepare full inventory, configuration assignments, observed firewall/credential/malware state, supported-version evidence and update installation records. Encryption reports support your chosen FileVault policy; 99% coverage is not a scheme tolerance for missing required controls.
Investigate stale Macs, unsupported releases, overdue fixes and broad developer exceptions. Documented business need does not waive malware protection; check a qualifying route before relaxing Gatekeeper or other controls.
Section 09
What Fig Group checks
The readiness check supports preparation. Share Jamf inventory and configuration evidence when requested. Exact import capability and first-time pass rates need verified service and cohort records; a Jamf or FileVault percentage cannot guarantee certification.
Start Cyber Essentials - from £299.99 + VAT | All tiers | CE Plus with on-device testing
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials for Mac / macOS: configuration guide
Prepare Mac and macOS controls for Cyber Essentials with or without MDM: firewall, supported software, patching, malware protection and optional FileVault hardening.
Read articleTechnical Guides
Cyber Essentials for Kandji: Mac configuration guide
Prepare Kandji Mac fleets for Cyber Essentials with Library Items, Blueprint coverage, supported software, patching, malware controls and optional FileVault hardening.
Read articleTechnical Guides
Cyber Essentials for Microsoft Azure: configuration guide
Prepare Azure Cyber Essentials controls and evidence: Entra ID authentication, shared responsibility, firewall rules, supported VMs and optional Secure Score hardening.
Read article

