Cyber Essentials for Kandji: Mac configuration guide
Prepare Kandji Mac fleets for Cyber Essentials with Library Items, Blueprint coverage, supported software, patching, malware controls and optional FileVault hardening.

Section 01
Cyber Essentials for Kandji: Mac configuration guide
Kandji Library Items and Blueprints can help configure Mac controls and report their coverage. Separate scheme requirements from optional hardening such as FileVault. An exception Blueprint must still satisfy the applicable requirements; assignment to a Blueprint does not by itself prove effective controls.
Section 02
1. Assignment scope via Blueprints
Use Automated Device Enrolment where appropriate and verify the ownership/enrolment restrictions actually applied. Account for every in-scope Mac, including developer, executive, BYOD and offline devices. A single production Blueprint is an organisational choice; there is no 95% scheme coverage threshold or 2-3% inventory tolerance.
Reconcile the asset register, computer records and identity activity. Users and devices have different counts; record multiple-device users and shared equipment instead of expecting equality. Alternative management methods can be used if actual compliance is evidenced.
Section 03
2. Library Items - configuration and hardening
Swipe across the table to view all columns.
| Area | What to verify |
|---|---|
| Credentials and locking | Appropriate authentication, quality and guess protection; actual locking controls |
| Firewall | Required firewall protection with only necessary approved inbound access |
| Software Update / Managed OS | Supported software, automatic updates where possible and installed required fixes |
| Malware protection | Qualifying anti-malware or actual application allowlisting controls |
| FileVault | Optional local encryption policy, key escrow and recovery where adopted |
Use the applicable credential-quality route and compromise-triggered changes without enforced complexity or periodic expiry. Ten-attempt wipe, stealth mode and zero-second lock grace are local hardening choices, not universal Cyber Essentials requirements. Configure only supported settings and confirm their effect on the actual OS. Gatekeeper provenance checking is not by itself an organisational application allowlist.
Section 04
3. Patching with Managed OS
Well-evidenced Managed OS enforcement can be one of the strongest pieces of update evidence for a suitable fleet, as a practical judgement rather than an automatic pass. Review the supported Managed OS capabilities for your OS and device eligibility. Plan notifications, installation and restarts to meet release-based deadlines. A seven-day local enforcement window is illustrative. A business-reason exception does not waive the requirement: remediate or satisfy the scheme's actual removal/exclusion conditions.
Verify each model and release against current Apple support and vulnerability fixes, not a fixed macOS 14 or N-1 threshold.
Section 05
4. Malware protection
XProtect is malware detection, not an application allowlist. Verify the complete anti-malware requirements, including malicious-file and website protection, or implement qualifying application allowlisting. If using Kandji or another EDR product, check the actual licensed capability, configuration and coverage. Appropriate permissions and a healthy agent are supporting evidence rather than a guarantee.
Section 06
5. User access control
Keep standard daily work separate from administrative tasks. Use unique accounts and remove unnecessary access. Kandji Passport, Platform SSO and administrative-password management depend on the actual product/configuration; verify their authentication and recovery flows rather than assuming they impose MFA everywhere.
Section 07
Scheme baseline and local hardening
NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.
Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.
For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.
Section 08
6. Evidence assessors can review
Prepare all scoped computer records and Blueprint/Library Item assignments, relevant configuration screenshots, supported-version evidence, update installation records and the chosen malware-route coverage. Where FileVault is local policy, include its status and recovery evidence. A zero-threat report is not proof of every required control or a promise that the estate is malware-free.
Section 09
7. Common failure points
- Developer Blueprints disabling required protections: document need and verify another qualifying control; documentation alone is not a waiver.
- Managed OS notifications without effective installation: investigate offline devices and missed deadlines.
- Unsupported Mac models/releases: upgrade or replace, or use a valid exclusion meeting the scheme conditions.
- BYOD using app protection alone: Mac device controls still need evidence; MAM is not a general fallback exemption, and FileVault itself is not a universal scheme minimum.
Section 10
What Fig Group checks
The readiness check supports preparation. Share computer records and assignment evidence when requested. Exact import functionality and first-time pass rates need service/cohort records; 99% encryption coverage or a Blueprint percentage does not establish certification.
Start Cyber Essentials - from £299.99 + VAT | Pricing | CE Plus booking
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials for Mac / macOS: configuration guide
Prepare Mac and macOS controls for Cyber Essentials with or without MDM: firewall, supported software, patching, malware protection and optional FileVault hardening.
Read articleTechnical Guides
Cyber Essentials for Jamf Pro: Mac configuration guide
Prepare Jamf Pro Mac configuration and evidence for Cyber Essentials: scope coverage, firewall, supported software, malware protection and optional FileVault hardening.
Read articleTechnical Guides
Cyber Essentials for Microsoft Azure: configuration guide
Prepare Azure Cyber Essentials controls and evidence: Entra ID authentication, shared responsibility, firewall rules, supported VMs and optional Secure Score hardening.
Read article

