Services Methodology Why Us About Us Blog Get in Touch
← Back to Device Configuration Reviews
// 07C — macOS HARDENING

macOS Build
Review

Configuration and hardening review of macOS endpoint builds against best security practices including CIS benchmarks and NIST/NCSC macOS security guidance - covering sensitive areas including MDM profiles, FileVault, Gatekeeper, and System Integrity Protection.

CIS benchmarksNIST macOS GuidanceMDM ProfilesFileVaultGatekeeperSystem Integrity ProtectionJamfApple Business Manager
Overview

macOS fleets are frequently managed with a lighter touch than Windows estates, despite handling equally sensitive data. MDM policy scoping gaps, unmanaged local admin accounts, and inconsistent FileVault enforcement are common findings.

Our macOS build reviews assess endpoint configuration against CIS Apple macOS benchmark (Level 1 and Level 2) and NIST/NCSC macOS security guidance, covering disk encryption enforcement, Gatekeeper and System Integrity Protection status, firewall configuration, and screen lock policy.

We review both the MDM policy as configured and its actual scope and exceptions — the gap between the two is where most managed-fleet exposure lives.

Testing Methodology
01

Scope & Baseline Selection

Confirmation of macOS versions in scope, the MDM platform in use, and selection of applicable and appropriate benchmarks.

02

Configuration & Profile Extraction

Review of configuration profiles and MDM policy payloads exported from the management console, supplemented by local system state review where required.

03

Automated Benchmark Analysis

Custom script analysis of macOS across FileVault enforcement, Gatekeeper/SIP status, firewall configuration, screen lock policy, and packet filter (pf) rules.

04

Manual Review & Contextualisation

Review of MDM profile scoping and exceptions, local administrator account sprawl, unmanaged or BYOD coverage gaps, and third-party endpoint agent deployment.

05

Risk Prioritisation

Findings ranked by likelihood of enabling credential theft or data exfiltration — disabled FileVault, permissive Gatekeeper settings, and unmanaged local admin surfaced first.

06

Remediation Guidance

Custom recommendations delivered alongside a prioritised fix list.

What Makes Levantis Different

We assess the gap between MDM policy as written and policy as actually enforced across the fleet — scoping exceptions are where most exposure hides.

// In Scope

  • macOS endpoints (Intel & Apple Silicon)
  • MDM-managed fleets (Jamf, Kandji, Intune)
  • Shared / kiosk Mac devices

// Standards

  • CIS Apple macOS benchmark (L1 & L2)
  • NIST macOS Security guidance
  • NCSC End User Device guidance
  • Apple Platform Security guidance

// Typical Duration

  • Up to 2 builds: 3 days
  • 5+ builds: price on request

// Engage Us

Ready to scope an engagement? Get in touch for a no-obligation conversation.

Request Assessment

Know your macOS hardening gaps.

MDM policy on paper and MDM policy as enforced are often two different things. Get a clear picture of the difference.

Get in Touch