Skip to content
Technical Guides

Cyber Essentials for Kandji: Mac configuration guide

Prepare Kandji Mac fleets for Cyber Essentials with Library Items, Blueprint coverage, supported software, patching, malware controls and optional FileVault hardening.

a laptop sits on a desk

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

6 min read

Share

Section 01

Cyber Essentials for Kandji: Mac configuration guide

Kandji Library Items and Blueprints can help configure Mac controls and report their coverage. Separate scheme requirements from optional hardening such as FileVault. An exception Blueprint must still satisfy the applicable requirements; assignment to a Blueprint does not by itself prove effective controls.

Section 02

1. Assignment scope via Blueprints

Use Automated Device Enrolment where appropriate and verify the ownership/enrolment restrictions actually applied. Account for every in-scope Mac, including developer, executive, BYOD and offline devices. A single production Blueprint is an organisational choice; there is no 95% scheme coverage threshold or 2-3% inventory tolerance.

Reconcile the asset register, computer records and identity activity. Users and devices have different counts; record multiple-device users and shared equipment instead of expecting equality. Alternative management methods can be used if actual compliance is evidenced.

Section 03

2. Library Items - configuration and hardening

Swipe across the table to view all columns.

AreaWhat to verify
Credentials and lockingAppropriate authentication, quality and guess protection; actual locking controls
FirewallRequired firewall protection with only necessary approved inbound access
Software Update / Managed OSSupported software, automatic updates where possible and installed required fixes
Malware protectionQualifying anti-malware or actual application allowlisting controls
FileVaultOptional local encryption policy, key escrow and recovery where adopted

Use the applicable credential-quality route and compromise-triggered changes without enforced complexity or periodic expiry. Ten-attempt wipe, stealth mode and zero-second lock grace are local hardening choices, not universal Cyber Essentials requirements. Configure only supported settings and confirm their effect on the actual OS. Gatekeeper provenance checking is not by itself an organisational application allowlist.

Section 04

3. Patching with Managed OS

Well-evidenced Managed OS enforcement can be one of the strongest pieces of update evidence for a suitable fleet, as a practical judgement rather than an automatic pass. Review the supported Managed OS capabilities for your OS and device eligibility. Plan notifications, installation and restarts to meet release-based deadlines. A seven-day local enforcement window is illustrative. A business-reason exception does not waive the requirement: remediate or satisfy the scheme's actual removal/exclusion conditions.

Verify each model and release against current Apple support and vulnerability fixes, not a fixed macOS 14 or N-1 threshold.

Section 05

4. Malware protection

XProtect is malware detection, not an application allowlist. Verify the complete anti-malware requirements, including malicious-file and website protection, or implement qualifying application allowlisting. If using Kandji or another EDR product, check the actual licensed capability, configuration and coverage. Appropriate permissions and a healthy agent are supporting evidence rather than a guarantee.

Section 06

5. User access control

Keep standard daily work separate from administrative tasks. Use unique accounts and remove unnecessary access. Kandji Passport, Platform SSO and administrative-password management depend on the actual product/configuration; verify their authentication and recovery flows rather than assuming they impose MFA everywhere.

Section 07

Scheme baseline and local hardening

NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.

For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.

Section 08

6. Evidence assessors can review

Prepare all scoped computer records and Blueprint/Library Item assignments, relevant configuration screenshots, supported-version evidence, update installation records and the chosen malware-route coverage. Where FileVault is local policy, include its status and recovery evidence. A zero-threat report is not proof of every required control or a promise that the estate is malware-free.

Section 09

7. Common failure points

  • Developer Blueprints disabling required protections: document need and verify another qualifying control; documentation alone is not a waiver.
  • Managed OS notifications without effective installation: investigate offline devices and missed deadlines.
  • Unsupported Mac models/releases: upgrade or replace, or use a valid exclusion meeting the scheme conditions.
  • BYOD using app protection alone: Mac device controls still need evidence; MAM is not a general fallback exemption, and FileVault itself is not a universal scheme minimum.

Section 10

What Fig Group checks

The readiness check supports preparation. Share computer records and assignment evidence when requested. Exact import functionality and first-time pass rates need service/cohort records; 99% encryption coverage or a Blueprint percentage does not establish certification.

Start Cyber Essentials - from £299.99 + VAT | Pricing | CE Plus booking

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group