Watchtower Docs
ReferenceCheck catalog

macOS (Intune-managed)

All 115 macOS (Intune-managed) checks - what each one checks, why, and the access used to evaluate it.

115 checks. Column "Access used" lists the application permissions and collected data sources this check's evaluation reads; "None" means Watchtower reads no tenant data for it.

CheckSeverityWhat it checksWhy it mattersAccess used
Audit Game Center Settings
wt.macos.accounts.game-center-audit
LOWAudits whether Game Center is enabled on managed macOS devices and whether users have linked a personal Apple ID for gaming activity.Game Center uses the user's Apple ID to track gaming activity, achievements, and leaderboards. On a corporate device, this ties personal Apple ID usage into the device in ways that may complicate separation of personal and corporate data, and adds an Apple network service that has no business purpose on a managed workstation.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Guest Account Is Disabled
wt.macos.accounts.guest-account-disabled
HIGHChecks that the macOS Guest account is disabled, preventing unauthenticated users from logging in and accessing the machine without credentials.The Guest account allows anyone with physical access to log into the computer without a password. While it provides a sandboxed session, it still allows access to network resources, browsers, and potentially locally cached data. Disabling it closes a no-credential login path that circumvents all user-based access controls.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Guest Access to Shared Folders Is Disabled
wt.macos.accounts.guest-shared-folders-disabled
HIGHChecks that unauthenticated guest access to macOS shared folders is disabled, ensuring that file sharing services require authentication before granting access to local directories.Allowing guest access to shared folders permits anyone on the same network to browse and read shared directories without credentials. On a corporate network, this can expose project files, documents, and other data to any connected device, including those belonging to visitors, contractors, or attackers on the same network segment.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Users' Accounts Do Not Have a Password Hint
wt.macos.accounts.no-password-hint
LOWChecks that macOS user accounts do not have a password hint configured, preventing the login window from displaying clues that could aid an attacker in guessing the password.Password hints are displayed to anyone at the login screen after a configurable number of failed attempts. A hint that is too specific reveals the password directly; even a vague hint reduces the guessing space. With physical access, an attacker can trigger the hint display without any authentication.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit Touch ID
wt.macos.accounts.touch-id-audit
LOWAudits whether Touch ID is configured on managed macOS devices with supported hardware, verifying that biometric authentication is available as an authentication method.Touch ID enables strong, convenient local authentication that is significantly more phishing-resistant than passwords alone. Devices where Touch ID is not enrolled rely entirely on the login password, which is more susceptible to shoulder surfing and brute-force attacks. Organisations should confirm Touch ID is enrolled on supported hardware.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Audit Wallet & Apple Pay Settings
wt.macos.accounts.wallet-audit
LOWAudits whether Wallet and Apple Pay are configured on managed macOS devices, reviewing whether personal payment methods are linked to a corporate device.Apple Pay on a corporate device links personal financial credentials to company hardware. While this does not create a direct security vulnerability, it introduces personal data onto a managed asset, complicates device disposition and remote wipe decisions, and may create compliance concerns in regulated industries.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure External Intelligence Extensions Is Disabled
wt.macos.ai.external-intelligence-disabled
HIGHChecks that external intelligence extensions - third-party AI service integrations - are disabled on managed macOS devices, preventing system-level AI features from routing content to external providers.External intelligence extensions allow third-party AI services to access system context, selected text, and document content to provide inline suggestions. Enabling these extensions sends potentially sensitive corporate content to external AI providers whose data handling, retention, and training practices are outside organisational control.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Mail Summarization Is Disabled
wt.macos.ai.mail-summarization-disabled
LOWChecks that the Apple Intelligence mail summarisation feature is disabled on managed macOS devices, preventing automated AI processing of email content in the native Mail app.Mail summarisation feeds email content - including potentially confidential corporate communications - into Apple Intelligence models for automated processing. Even if processing is on-device, it exposes email data to AI inference workloads that may not align with data handling policies, and the feature may use Apple servers for enhanced capability.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Notes Summarization Is Disabled
wt.macos.ai.notes-summarization-disabled
LOWChecks that the Apple Intelligence notes summarisation feature is disabled on managed macOS devices, preventing AI processing of note content stored in the native Notes app.Notes may contain meeting minutes, project plans, credentials, and other sensitive corporate information. Summarisation passes this content through AI processing which may involve external model infrastructure. Disabling the feature prevents unintended data processing of corporate note content beyond its intended storage context.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Writing Tools Is Disabled
wt.macos.ai.writing-tools-disabled
LOWChecks that Apple Intelligence Writing Tools are disabled on managed macOS devices, preventing the system-wide AI rewriting and summarisation service from processing selected text.Writing Tools is a system-wide service that can rewrite, summarise, or generate text from selected content in any application. Enabling it on a corporate device allows AI processing of any selected text - including confidential documents, internal communications, and legal content - potentially through Apple Intelligence infrastructure outside organisational governance.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Improve Assistive Voice Features Is Disabled
wt.macos.analytics.assistive-voice-disabled
LOWChecks that the option to improve assistive voice features by sharing audio samples with Apple is disabled on managed macOS devices.When enabled, macOS may transmit audio recordings from accessibility voice features - including voice control commands - to Apple for model improvement. On a corporate device, this could capture sensitive spoken content, meeting audio, or dictated confidential material, sending it to Apple outside organisational data governance controls.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Share iCloud Analytics Is Disabled
wt.macos.analytics.icloud-analytics-disabled
LOWChecks that sharing iCloud analytics data with Apple is disabled on managed macOS devices, preventing iCloud usage statistics and diagnostic information from being transmitted to Apple.iCloud analytics data can reveal which iCloud services are actively used, synchronisation patterns, and usage frequency. On a corporate device, this telemetry discloses information about the organisation's cloud service consumption to Apple, which may conflict with data minimisation requirements under applicable privacy regulations.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Share Mac Analytics Is Disabled
wt.macos.analytics.mac-analytics-disabled
LOWChecks that macOS analytics data sharing with Apple is disabled on managed devices, preventing diagnostic reports, crash logs, and usage statistics from being automatically transmitted to Apple.Mac analytics data includes crash reports, application usage telemetry, and system diagnostic information. Crash reports can contain stack traces and memory fragments with data from the crashing application - potentially including corporate document contents, authentication tokens, or internal application state. Transmitting this to Apple is unnecessary data disclosure.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Share with App Developers Is Disabled
wt.macos.analytics.share-with-developers-disabled
LOWChecks that the option to share crash data and diagnostic reports with third-party app developers is disabled on managed macOS devices.When enabled, macOS forwards crash reports for third-party applications to the app's developer. Crash reports may include memory snapshots, log file fragments, and application state that could contain corporate data processed by the crashed application. This sends potentially sensitive information to external parties without explicit IT review.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Improve Siri & Dictation Is Disabled
wt.macos.analytics.siri-dictation-disabled
LOWChecks that the option to improve Siri and Dictation by sharing audio samples with Apple is disabled on managed macOS devices.When enabled, macOS may retain and transmit audio recordings of Siri interactions and dictation sessions to Apple for human review and model training. On a corporate device, dictated content - including confidential documents, internal communications, and sensitive data - could be sent to Apple and reviewed by Apple employees, breaching confidentiality obligations.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Security Auditing Flags For User-Attributable Events Are Configured
wt.macos.audit.flags-configured
HIGHChecks that the macOS audit configuration includes the recommended flags for capturing user-attributable events, ensuring that authentication, privilege use, and file access events are recorded.Audit flags control which event categories are logged. Without the correct flags - such as lo (login/logout), ad (administrative actions), and fd (file deletion) - critical events are silently discarded. Investigators responding to an incident may find the audit log lacks the records needed to determine what actions a user or attacker performed.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure install.log Is Retained for 365 or More Days
wt.macos.audit.install-log-retained
HIGHChecks that the macOS install.log file is configured for a retention period of at least 365 days, preserving a record of software installations for compliance and incident investigations.The install.log records software package installations, updates, and removals. A retention period of at least one year ensures that software changes made during a breach dwell period are available for forensic review. Many compliance frameworks require at least 12 months of log retention for audit trail completeness.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Security Auditing Retention Is Enabled
wt.macos.audit.retention-enabled
HIGHChecks that the macOS security audit subsystem is configured with a minimum retention period, ensuring audit log files are not overwritten or deleted prematurely.Without a configured retention minimum, the audit subsystem may overwrite logs when disk space is needed, destroying evidence of past events. Incident investigations that need to review events from weeks or months ago will find the audit trail incomplete, hindering forensic analysis and potentially failing compliance audits that mandate log retention.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Security Auditing Is Enabled
wt.macos.audit.security-auditing-enabled
HIGHChecks that the macOS security audit daemon (auditd) is enabled and running, ensuring that system security events are recorded to the audit log for forensic and compliance purposes.Without security auditing enabled, there is no authoritative record of authentication events, privilege escalation, file access, and system calls on the device. This makes it impossible to reconstruct events during an incident investigation and fails to meet audit trail requirements under most compliance frameworks.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Audit Software Inventory
wt.macos.audit.software-inventory-audit
LOWAudits whether a software inventory process is in place for managed macOS devices, verifying that IT has visibility into what applications are installed.Without an up-to-date software inventory, unknown or unauthorised applications may run on managed devices. Unmanaged applications may lack security patches, violate licensing agreements, or introduce vulnerabilities that would otherwise be caught by a patch management process. Inventory is the foundation of any vulnerability management programme.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Automatic Login Is Disabled
wt.macos.auth.automatic-login-disabled
HIGHChecks that automatic login is disabled on managed macOS devices, requiring users to authenticate at the login window rather than being logged in automatically when the device boots or wakes.Automatic login bypasses the authentication requirement at the login screen, allowing anyone who powers on or restarts the device to access the desktop without credentials. This negates FileVault protection for the pre-boot unlock step and exposes the full desktop environment to physical access without any authentication barrier.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Account Lockout Duration Is Configured
wt.macos.auth.lockout-duration
HIGHChecks that a minimum account lockout duration is configured on managed macOS devices, ensuring that locked accounts cannot immediately be retried after the threshold is reached.A lockout threshold without a minimum lockout duration is ineffective - an attacker can simply wait a few seconds and continue guessing. A lockout duration of at least 15 minutes ensures that repeated brute-force attempts are impractical and alerts the user or monitoring systems that an account is under attack.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Account Lockout Threshold Is Configured
wt.macos.auth.lockout-threshold
HIGHChecks that a maximum number of failed login attempts is configured on managed macOS devices, after which the account is locked out to prevent brute-force password guessing.Without a lockout threshold, an attacker with physical or remote access can attempt an unlimited number of passwords against a local account. A threshold of five or fewer failed attempts ensures that guessing attacks are interrupted quickly, even against accounts that might have weak passwords.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure a Login Window Banner Exists
wt.macos.auth.login-banner-exists
MEDIUMChecks that a login window banner message is configured on managed macOS devices, displaying an acceptable use policy or legal notice to users before they authenticate.A login banner establishes the legal basis for monitoring and acceptable use of the device. Without a banner, enforcement of monitoring and disciplinary policies may be legally challenged on the grounds that users were not informed. Many compliance frameworks and legal jurisdictions require a notice before accessing monitored systems.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Complex Password Must Contain Alphabetic Characters Is Configured
wt.macos.auth.password-alphabetic
MEDIUMChecks that macOS password policy requires at least one alphabetic character, preventing passwords that consist entirely of digits or symbols.Requiring alphabetic characters ensures that passwords are not purely numeric, which would reduce them to a PIN-like structure with limited entropy. Mixed character types increase the search space for dictionary and brute-force attacks against local account hashes.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Password History Is Configured
wt.macos.auth.password-history
HIGHChecks that macOS password policy prevents reuse of recent passwords by maintaining a password history, ensuring users cannot cycle through a small set of known passwords when required to change.Without password history enforcement, a user can change their password and immediately change it back to the same value, negating the benefit of password rotation policies. Password history prevents reuse of the last N passwords, ensuring that rotation produces genuinely new credentials rather than recycled ones.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Password Age Is Configured
wt.macos.auth.password-max-age
HIGHChecks that a maximum password age is configured on managed macOS devices, ensuring local account passwords are changed periodically to limit the window of exposure for compromised credentials.A password that is never rotated remains valid indefinitely after a compromise. Enforcing a maximum age - typically 365 days - ensures that credentials obtained through phishing, credential dumps, or observation are eventually invalidated. This provides a backstop against long-term credential persistence by attackers.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Password Minimum Length Is Configured
wt.macos.auth.password-min-length
HIGHChecks that a minimum password length is enforced on managed macOS local accounts, ensuring passwords are long enough to resist offline brute-force and dictionary attacks.Short passwords have a limited keyspace. Even with complexity requirements, a password under 8 characters can be cracked quickly using modern GPU-accelerated tools against a stolen local account hash. A minimum of 15 characters is recommended for accounts on devices where the password hash could be extracted via FileVault key or local access.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Complex Password Must Contain Numeric Character Is Configured
wt.macos.auth.password-numeric
MEDIUMChecks that macOS password policy requires at least one numeric character, ensuring passwords contain a digit in addition to alphabetic characters.Including a numeric character requirement ensures that passwords are not composed entirely of dictionary words or common phrases, which can be efficiently cracked using word-list attacks. Mixed character types increase entropy and make credential stuffing less effective if hashes are ever exposed.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Complex Password Must Contain Special Character Is Configured
wt.macos.auth.password-special-char
MEDIUMChecks that macOS password policy requires at least one special (non-alphanumeric) character, increasing password complexity beyond what dictionary attacks can easily reach.Special characters significantly expand the keyspace for password attacks. A password meeting length, alphanumeric, and special character requirements is resistant to most dictionary and hybrid attacks. This requirement is widely mandated by compliance frameworks for local account authentication on managed workstations.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Complex Password Must Contain Uppercase and Lowercase Characters Is Configured
wt.macos.auth.password-uppercase-lowercase
MEDIUMChecks that macOS password policy requires both uppercase and lowercase characters, preventing passwords that are uniformly cased and easier to crack with dictionary-based attacks.Mixed-case requirements increase password entropy by ensuring that case variations are not predictable. Passwords that use only lowercase letters are more vulnerable to dictionary attacks and rule-based mutations used by password cracking tools such as Hashcat. Mixed-case passwords combined with length and complexity requirements significantly harden local account credentials.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure the Root Account Is Disabled
wt.macos.auth.root-account-disabled
HIGHChecks that the macOS root account is disabled, preventing direct login or sudo access as the root user on managed devices.The root account has unrestricted access to all files, processes, and system configuration. Enabling it creates an account that bypasses all file system permission controls and audit logging associated with named accounts. Attackers who gain access to the root account can modify security controls, extract credentials, and disable MDM profiles without leaving user-attributable log entries.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Secure Keyboard Entry Terminal.app Is Enabled
wt.macos.auth.secure-keyboard-entry
HIGHChecks that Secure Keyboard Entry is enabled for Terminal.app on managed macOS devices, preventing other processes from reading keystrokes entered in terminal sessions.Without Secure Keyboard Entry, other applications running on the same macOS session can intercept keystrokes typed into Terminal - including passwords, private keys, and sensitive commands - using accessibility APIs or IOHIDManager. This is exploited by keylogger malware and rogue applications that have gained local execution. Enabling Secure Keyboard Entry blocks this interception.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure the Sudo Log Is Active
wt.macos.auth.sudo-log-active
HIGHChecks that sudo activity is logged on managed macOS devices, ensuring a record exists of commands executed with elevated privileges.Sudo grants a standard user temporary root access. Without logging, there is no record of which privileged commands were executed, by whom, and at what time. Sudo logs are critical for detecting privilege abuse, investigating security incidents involving local escalation, and demonstrating compliance with least-privilege access requirements.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure the Sudo Timeout Period Is Set to Zero
wt.macos.auth.sudo-timeout-zero
HIGHChecks that the sudo credential cache timeout is set to zero on managed macOS devices, requiring password re-authentication for every sudo command rather than caching credentials for a period.By default, sudo caches the authentication credential for 5 minutes after a successful authentication. During this window, any code executing as the user - including malware - can run arbitrary sudo commands without prompting for a password. Setting the timeout to zero ensures every privileged command requires explicit authentication, eliminating the cached-credential attack window.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure a Separate Timestamp Is Used for Each User/tty Combination
wt.macos.auth.sudo-timestamp-separate
HIGHChecks that sudo is configured to maintain separate credential timestamps per terminal session, preventing a cached sudo credential in one terminal from being reused in other concurrent terminal sessions.With the default sudo timestamp type, an authenticated sudo session in one terminal window shares its cached credential with all other terminal sessions for the same user. A process or attacker who has access to any terminal belonging to that user during the cache window can exploit this shared cache to run privileged commands. Per-tty timestamps isolate the credential to its originating session.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure an Active Session Cannot Be Unlocked by a Non-Current User
wt.macos.auth.unlock-session-disabled
HIGHChecks that the active user session on a managed macOS device cannot be unlocked by a different user account, preventing admin accounts from bypassing the screen lock of another logged-in user.By default on macOS, an administrator can unlock a locked session belonging to a different user. This allows any admin-level account - including compromised admin accounts - to access another user's open session without knowing their password. Disabling this prevents lateral movement from a compromised admin account to another user's open session.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Backup Automatically is Enabled If Time Machine Is Enabled
wt.macos.backup.time-machine-auto-backup
MEDIUMChecks that automatic backup is enabled for Time Machine on managed macOS devices where Time Machine is in use, ensuring backup runs on schedule without requiring manual initiation.If Time Machine is enabled but automatic backup is not, backups only occur when a user manually initiates them. This leads to large gaps between backup points, meaning recovery after ransomware or hardware failure results in significant data loss. Automatic backup ensures backups are consistent and up to date.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Time Machine Volumes Are Encrypted If Time Machine Is Enabled
wt.macos.backup.time-machine-encrypted
HIGHChecks that Time Machine backup volumes are encrypted on managed macOS devices where Time Machine is in use, ensuring backup data is protected against access if the external drive or network share is compromised.Time Machine backups are a complete copy of the device's data. An unencrypted Time Machine disk can be connected to any Mac and browsed freely, bypassing all OS-level access controls and FileVault disk encryption. Physical access to the backup drive is equivalent to full access to all data that was ever on the device.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Power Nap Is Disabled for Intel Macs
wt.macos.energy.power-nap-disabled
LOWChecks that Power Nap is disabled on Intel-based managed macOS devices, preventing the system from performing network activity while asleep.Power Nap allows Intel Macs to wake periodically while sleeping to check email, sync iCloud, and receive software updates. This means the device maintains network connectivity and processes data while it appears to be off, making it harder to reason about the attack surface of a sleeping device and potentially exposing it to network-based threats outside expected active hours.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Sleep and Display Sleep Is Enabled on Apple Silicon Devices
wt.macos.energy.sleep-display-sleep-apple-silicon
LOWChecks that sleep and display sleep are enabled on Apple Silicon managed macOS devices, ensuring the screen locks and the system enters a low-power state after inactivity.Without sleep and display sleep configured, an unattended device remains fully powered with the screen on indefinitely. This extends the window during which a physically proximate person can interact with an unlocked session. Sleep triggers the screensaver lock, which requires re-authentication to resume.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure the OS Is Not Active When Resuming from Standby (Intel)
wt.macos.energy.standby-os-inactive-intel
LOWChecks that Intel-based managed macOS devices are configured to enter standby with the OS inactive, ensuring the system is not partially running and accessible while in a sleep state.If macOS remains partially active when resuming from standby on Intel devices, the operating system may be resumable without requiring disk encryption authentication, weakening the protection provided by FileVault for the pre-boot state. Ensuring the OS is inactive during standby strengthens the security of data at rest when the device is unattended.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Wake for Network Access Is Disabled
wt.macos.energy.wake-network-access-disabled
LOWChecks that Wake for Network Access is disabled on managed macOS devices, preventing the device from waking from sleep in response to network packets.Wake for Network Access allows an attacker on the same network to remotely wake a sleeping device by sending a magic packet. Once awake, the device is fully active and can be targeted for exploitation. Disabling this feature prevents unauthorised remote activation and reduces the attack surface of sleeping devices.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Firewall Is Enabled
wt.macos.firewall.enabled
HIGHChecks that the macOS application firewall is enabled on managed devices, blocking unauthorised inbound network connections to applications that have not been granted firewall access.Without the application firewall enabled, any process on the device can accept inbound connections from the network. Malware or a compromised application that opens a listening port is not blocked, allowing attackers on the same network to interact with it. The macOS firewall blocks inbound connections to all applications unless explicitly allowed.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Firewall Stealth Mode Is Enabled
wt.macos.firewall.stealth-mode-enabled
HIGHChecks that macOS firewall stealth mode is enabled on managed devices, causing the system to ignore ICMP ping requests and unsolicited connection attempts rather than responding with a rejection.Without stealth mode, macOS responds to ICMP pings and TCP/UDP probes with rejection messages that confirm the device is present on the network. This information assists attackers in network enumeration and identifying live targets. Stealth mode makes the device invisible to basic port scanning.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit App Store Password Settings
wt.macos.icloud.app-store-password-audit
LOWAudits whether App Store password requirements are configured appropriately on managed macOS devices, verifying that re-authentication is required for purchases and free downloads.Without password requirements for App Store activity, any user at the device can install software or make purchases without re-authenticating. Requiring a password for App Store actions ensures intentional, attributed software installation, reducing the risk of accidental or unauthorised software being added to managed devices.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Audit iCloud Drive
wt.macos.icloud.drive-audit
LOWAudits whether iCloud Drive is enabled on managed macOS devices, reviewing whether corporate data may be synchronised to Apple's cloud storage infrastructure.iCloud Drive stores files in Apple's cloud under the user's personal Apple ID, outside the corporate data management boundary. Files stored there are accessible from unmanaged personal devices, survive MDM unenrolment, and are not subject to corporate DLP or eDiscovery controls.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure iCloud Drive Document and Desktop Sync Is Disabled
wt.macos.icloud.drive-sync-disabled
MEDIUMChecks that iCloud Drive synchronisation of Desktop and Documents folders is disabled on managed macOS devices, preventing files saved to these common locations from being automatically uploaded to Apple's cloud.When Desktop and Documents sync is enabled, any file saved to these folders - including downloads, draft documents, and temporary files containing corporate data - is automatically uploaded to iCloud and becomes accessible from any device signed in with the same Apple ID. This moves corporate data outside the managed boundary without the user's explicit awareness.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit Find My Mac
wt.macos.icloud.find-my-mac-audit
LOWAudits whether Find My Mac is configured on managed macOS devices, reviewing whether the Apple-provided device tracking feature is enabled and whether it aligns with the organisation's asset management policy.Find My Mac enables device location tracking and remote lock/wipe through Apple's infrastructure. While it provides a recovery capability for lost devices, it relies on the user's personal Apple ID rather than the corporate MDM. Organisations should confirm whether Find My Mac is needed alongside MDM-managed remote wipe, or whether it introduces complications for device reclamation.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Audit Freeform Sync to iCloud
wt.macos.icloud.freeform-sync-audit
LOWAudits whether Freeform data is synchronised to iCloud on managed macOS devices, reviewing whether whiteboard and collaboration content is stored outside the corporate data boundary.Freeform is a collaborative whiteboard application that can sync boards to iCloud. Corporate planning boards, architecture diagrams, and brainstorming content may contain sensitive project information that is then replicated to Apple's servers and accessible from any personal device signed in with the same Apple ID.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit iCloud Passwords & Keychain
wt.macos.icloud.passwords-keychain-audit
LOWAudits whether iCloud Passwords and Keychain synchronisation is enabled on managed macOS devices, reviewing whether saved credentials are replicated to Apple's cloud and accessible from personal devices.iCloud Keychain synchronises saved passwords, passkeys, and Wi-Fi credentials across all devices signed into the same Apple ID. On a corporate device, credentials saved to the system keychain - including saved network passwords and application credentials - are replicated to unmanaged personal devices, outside the corporate security boundary.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit Security Keys Used With Apple Accounts
wt.macos.icloud.security-keys-audit
LOWAudits whether hardware security keys are registered to Apple IDs associated with managed macOS devices, reviewing the state of phishing-resistant authentication for iCloud accounts on corporate hardware.Apple ID accounts on corporate devices without hardware security key protection rely on SMS or authenticator-based two-factor authentication that is vulnerable to SIM swapping and phishing. Hardware security keys provide phishing-resistant authentication for the Apple ID, protecting iCloud services and the device's activation lock from account takeover.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure a Custom Message for the Login Window Is Enabled
wt.macos.loginwindow.custom-message
HIGHChecks that a custom message is configured for the macOS login window, displaying contact information or an acceptable use notice to users before authentication.A login window custom message serves a dual purpose: it can display IT contact information to help users who are locked out, and it can display a legal notice or acceptable use statement. Without a message, users may be unaware of IT policy requirements, and the device provides no deterrence to casual unauthorised access attempts.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Login Window Displays as Name and Password Is Enabled
wt.macos.loginwindow.name-password-required
HIGHChecks that the macOS login window requires both a username and password to be entered, rather than displaying a list of user accounts where only a password needs to be typed.When the login window shows a list of accounts, an attacker only needs to guess the password for a visible account. Requiring a username entry forces the attacker to know both the account name and the password, and prevents reconnaissance of which accounts exist on the device from the login screen.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Show Password Hints Is Disabled
wt.macos.loginwindow.password-hints-disabled
HIGHChecks that password hints are not shown on the macOS login window, preventing clues about the user's password from being visible to anyone at the login screen after failed attempts.After a configurable number of failed login attempts, macOS can display the user's password hint at the login window. If the hint is specific enough, it effectively reveals the password to anyone who tries a few wrong entries. Even vague hints narrow the search space for an attacker. Disabling hints eliminates this information leakage.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Protect Mail Activity in Mail Is Enabled
wt.macos.mail.protect-activity-enabled
LOWChecks that Protect Mail Activity is enabled in the macOS Mail app, concealing the user's IP address and preventing senders from knowing when an email was opened.Email tracking pixels embedded in HTML emails allow senders to log the recipient's IP address, approximate location, and the exact time the email was opened. This tracking data enables threat actors to profile targets before phishing attacks, confirm a target is active, and correlate identity with network location. Enabling Mail Privacy Protection routes remote content through Apple's servers to obscure this information.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Bonjour Advertising Services Is Disabled
wt.macos.network.bonjour-advertising-disabled
MEDIUMChecks that Bonjour advertising services are disabled on managed macOS devices, preventing the device from broadcasting service availability information on the local network.Bonjour (mDNS) advertises services running on the device to all hosts on the local network segment, including open shares, printers, and remote access services. This information assists attackers in enumerating services on corporate devices without requiring active scanning, reducing the effort needed for lateral movement.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure HTTP Server Is Disabled
wt.macos.network.http-server-disabled
HIGHChecks that the built-in macOS HTTP server (Apache httpd) is disabled on managed devices, ensuring the device is not listening for inbound HTTP connections.macOS ships with an Apache HTTP server that can be enabled through the Web Sharing setting. If running, it opens port 80 to inbound connections on the local network, extending the attack surface of the device. An attacker who can reach this port can attempt to exploit web server vulnerabilities or serve malicious content to others on the network.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure NFS Server Is Disabled
wt.macos.network.nfs-server-disabled
HIGHChecks that the NFS server service is disabled on managed macOS devices, ensuring the device is not sharing file system volumes over the network via the NFS protocol.NFS is a legacy network file sharing protocol with weak authentication and no encryption in its older versions. If enabled on a workstation, it can expose local file system paths to any machine on the network. Attackers can mount NFS shares without authentication in many configurations, providing unrestricted access to shared directories.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Limit Ad Tracking Is Enabled
wt.macos.privacy.ad-tracking-limited
LOWChecks that ad tracking is limited on managed macOS devices, preventing advertising networks from building a persistent behavioural profile based on the device's app and web activity.Advertising tracking identifiers allow ad networks to correlate activity across applications and websites over time. On a corporate device, this builds a profile of business software usage and browsing patterns that is shared with external advertising infrastructure. Limiting tracking reduces the data shared with third parties and aligns with privacy-by-default principles.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit Full Disk Access for Applications
wt.macos.privacy.full-disk-access-audit
LOWAudits which applications have been granted Full Disk Access on managed macOS devices, reviewing whether the permissions granted are appropriate and limited to authorised tools.Full Disk Access bypasses the macOS Transparency, Consent and Control (TCC) framework, granting an application unrestricted read access to all files on the system - including protected directories, mail, messages, and user data. Applications granted this permission inadvertently or maliciously can exfiltrate any data on the device without further user prompts.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Help Apple Improve Search Is Disabled
wt.macos.privacy.improve-search-disabled
LOWChecks that the option to help Apple improve Spotlight and Siri search is disabled on managed macOS devices, preventing search queries and results from being transmitted to Apple.When enabled, Spotlight search queries - including file names, application searches, and Siri requests - are sent to Apple to improve search algorithms. On a managed device, search activity may reveal internal project names, file names, and application usage patterns. Transmitting this to Apple is unnecessary data disclosure with no business benefit.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Show Location Icon in Control Center when System Services Request Your Location Is Enabled
wt.macos.privacy.location-icon-enabled
LOWChecks that the location icon is displayed in the menu bar when system services are actively using location data on managed macOS devices, providing users with visibility into when location tracking is occurring.Without the location icon shown in the menu bar, background location access by system services is invisible to the user. Displaying the icon alerts users when their location is being accessed, enabling detection of unexpected or unauthorised location tracking by applications or system processes.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Audit Location Services Access
wt.macos.privacy.location-services-audit
LOWAudits which applications have access to Location Services on managed macOS devices, reviewing whether granted location permissions are appropriate and limited to applications with a legitimate need.Location data reveals the physical whereabouts of the device and its user. Applications with location access can track user movement patterns, which could expose sensitive information about visited facilities, client sites, and personal routines. Organisations should confirm that only required applications retain location access.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Location Services Is Enabled
wt.macos.privacy.location-services-enabled
LOWChecks that Location Services is enabled on managed macOS devices, allowing applications and system services that require location data - such as Find My and time zone detection - to function correctly.Location Services must be enabled for Find My to function, which is a key remote device recovery capability. With Location Services disabled, the device cannot be located or remotely locked if lost or stolen. Enabling the service at the system level while controlling per-application access through the Privacy preferences provides the right balance.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure On-Device Dictation Is Enforced
wt.macos.privacy.on-device-dictation
LOWChecks that on-device dictation is enforced on managed macOS devices, ensuring dictation processing occurs locally rather than being transmitted to Apple's servers for cloud-based speech recognition.Cloud-based dictation sends audio recordings to Apple's servers for transcription. On a corporate device, dictated content - including confidential communications, financial figures, and internal project details - would be transmitted to and processed by external infrastructure outside the organisation's data governance controls. On-device dictation keeps this processing local.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit AutoFill in Safari
wt.macos.safari.autofill-audit
LOWAudits which AutoFill categories are enabled in Safari on managed macOS devices, reviewing whether saved passwords, credit card details, and contact information are stored for automatic form completion.Safari AutoFill stores saved passwords and payment information locally and fills them into web forms automatically. If a managed device is compromised or accessed by an unauthorised user, AutoFill can automatically submit corporate credentials into attacker-controlled forms. The organisation should ensure AutoFill settings are reviewed and limited to approved categories.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Prevent Cross-Site Tracking Is Enabled in Safari
wt.macos.safari.cross-site-tracking-prevented
HIGHChecks that cross-site tracking prevention is enabled in Safari on managed macOS devices, blocking third-party cookies and other tracking mechanisms that correlate browsing across different websites.Cross-site trackers allow advertising networks and data brokers to profile browsing behaviour across the web. On a corporate device, this exposes visited sites - including internal portals, partner sites, and tool logins - to external tracking infrastructure. Safari's Intelligent Tracking Prevention mitigates this by isolating third-party data.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit Hide IP Address in Safari Setting
wt.macos.safari.hide-ip-audit
LOWAudits whether Safari's Hide IP Address feature is configured on managed macOS devices, reviewing whether the device's IP address is concealed from trackers and websites.Trackers use IP addresses to identify and correlate users across websites, even after cookies are cleared. Hiding the IP address from trackers prevents IP-based correlation of browsing activity. Additionally, websites cannot use the IP address to determine the organisation's network range or approximate location.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Audit History and Remove History Items in Safari
wt.macos.safari.history-audit
LOWAudits the Safari browser history retention settings on managed macOS devices, reviewing how long browsing history is kept and whether users can remove history items.Browser history containing visited URLs and timestamps represents a record of user activity. If the device is seized or compromised, browser history can reveal sensitive internal URLs, partner site access patterns, and personal browsing habits. Organisations should define a policy for appropriate history retention duration and ensure users are not prevented from clearing their own history.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Open Safe Files After Downloading Is Disabled in Safari
wt.macos.safari.safe-downloads-disabled
HIGHChecks that the Open safe files after downloading feature is disabled in Safari on managed macOS devices, preventing downloaded files from being automatically opened without user review.When enabled, Safari automatically opens files it considers 'safe' - including disk images, PDFs, and scripts - immediately after download. This bypasses the deliberate review step that would normally occur before opening an unknown file, enabling drive-by download attacks where a malicious file is executed as soon as it finishes downloading.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Show Full Website Address Is Enabled in Safari
wt.macos.safari.show-full-address
LOWChecks that Safari is configured to display the full website address in the address bar on managed macOS devices, showing the complete URL including subdomain and path rather than just the domain.Safari's default compressed address display shows only the registered domain, hiding the full URL including subdomains and path components. This makes homograph and subdomain phishing attacks harder to detect - for example, an attacker can register corporate.evil.com, and Safari would only show evil.com in the address bar, making the phishing page appear legitimate.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Show Status Bar Is Enabled in Safari
wt.macos.safari.show-status-bar
LOWChecks that the status bar is visible in Safari on managed macOS devices, displaying the destination URL of a link before it is clicked.The Safari status bar shows the full URL of a hovered link before the user clicks it. Without it, users cannot see where a link leads before navigating, making it easier for phishing pages to use deceptive link text. Enabling the status bar gives users a basic signal to validate that links lead to expected destinations.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Warn When Visiting Fraudulent Websites Is Enabled in Safari
wt.macos.safari.warn-fraudulent-websites
HIGHChecks that Safari's fraudulent website warning is enabled on managed macOS devices, alerting users when they navigate to sites identified as phishing or malware distribution points.Phishing attacks targeting corporate credentials frequently use newly registered or compromised domains. Safari's Safe Browsing integration checks visited URLs against known malicious site databases and displays a warning before the page loads. Disabling this removes a passive, low-friction protection that intercepts phishing navigation without requiring user expertise.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Require Password After Screen Saver Begins or Display Is Turned Off Is Enabled
wt.macos.screensaver.password-required
HIGHChecks that a password is required immediately when the screensaver starts or the display turns off on managed macOS devices, ensuring the session locks on inactivity.Without requiring a password on screensaver activation, anyone who moves the mouse on an unattended Mac resumes the unlocked session without authentication. This completely negates the screen lock as a security control. Requiring a password ensures that every screensaver activation results in a locked session that requires re-authentication.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure an Inactivity Interval of 15 Minutes Or Less for the Screen Saver Is Enabled
wt.macos.screensaver.timeout-15min
HIGHChecks that the screensaver activates after no more than 15 minutes of inactivity on managed macOS devices, limiting the time a session remains unlocked and visible when unattended.A long screensaver timeout leaves an unlocked session accessible for extended periods. In open office environments, public spaces, or during meetings, an unlocked Mac left on a desk can be accessed by anyone who walks by. A maximum of 15 minutes reduces the exposure window to a practical minimum that balances security with usability.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure an Administrator Password Is Required to Access System-Wide Preferences
wt.macos.security.admin-password-required
HIGHChecks that an administrator password is required to make changes to system-wide preferences on managed macOS devices, preventing standard users from modifying security settings.System-wide preferences - including network settings, security policies, and sharing services - control the device's security posture. If a standard user can change these settings without authentication, they can weaken security controls, enable unauthorised sharing services, or modify network configurations. Requiring admin authentication preserves IT control over system-level settings.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure an Anti-Virus Solution Is Installed
wt.macos.security.antivirus-installed
HIGHChecks that an anti-virus or endpoint security solution is installed and active on managed macOS devices, providing malware detection and response capability beyond the built-in XProtect.macOS malware - including ransomware, spyware, and trojanised applications - continues to increase in prevalence. While XProtect provides basic signature detection, it lacks behavioural analysis, real-time file system monitoring, and incident response capabilities provided by enterprise endpoint security solutions. An active AV agent also feeds telemetry into SIEM and EDR platforms for detection and investigation.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure FileVault Is Enabled
wt.macos.security.filevault-enabled
CRITICALChecks that FileVault full-disk encryption is enabled on managed macOS devices, ensuring that all data stored on the device is encrypted at rest and protected against physical access.Without FileVault, the contents of a Mac's internal storage can be read by booting from external media or connecting the drive to another computer. A lost or stolen Mac without disk encryption exposes all local data - including cached credentials, documents, email, and browser history - without requiring the login password. FileVault ensures the disk is unreadable without the encryption key.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Gatekeeper Is Enabled
wt.macos.security.gatekeeper-enabled
CRITICALChecks that Gatekeeper is enabled on managed macOS devices, ensuring that only code-signed software from Apple-approved sources can be executed without explicit override.Gatekeeper verifies that applications are code-signed by an Apple-registered developer and notarised by Apple before execution. Without it, users can freely run unsigned or unnotarised executables - including malware distributed as productivity tools or cracked software. Gatekeeper is the primary OS-level control against execution of unauthorised code.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit Lockdown Mode
wt.macos.security.lockdown-mode-audit
LOWAudits whether Lockdown Mode is enabled on managed macOS devices used by high-risk individuals, reviewing whether the extreme security hardening feature is appropriate and deployed where needed.Lockdown Mode is designed for individuals at high risk of sophisticated targeted attacks - such as executives, journalists, and government officials. It significantly restricts device functionality to reduce the attack surface against state-sponsored and mercenary spyware. Organisations with high-risk personnel should evaluate whether Lockdown Mode should be enabled on their devices.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure AirDrop Is Disabled When Not Actively Transferring Files
wt.macos.sharing.airdrop-disabled
HIGHChecks that AirDrop is disabled on managed macOS devices when not actively transferring files, preventing wireless file transfer to unknown nearby devices.AirDrop allows files to be wirelessly received from unknown devices when set to 'Everyone' or from contacts when signed in with an Apple ID. On a corporate device, this provides a path to receive potentially malicious files or to accidentally or deliberately transfer corporate documents to nearby unmanaged devices, bypassing DLP controls.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure AirPlay Receiver Is Disabled
wt.macos.sharing.airplay-receiver-disabled
HIGHChecks that the AirPlay receiver is disabled on managed macOS devices, preventing the device from accepting screen mirroring or audio streaming connections from other Apple devices.When enabled, the AirPlay receiver opens a listening service on the local network, extending the device's attack surface. An attacker on the same network could attempt to connect to this service or exploit vulnerabilities in the AirPlay protocol stack. The receiver also advertises the device's presence via mDNS, aiding network reconnaissance.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Bluetooth Sharing Is Disabled
wt.macos.sharing.bluetooth-sharing-disabled
HIGHChecks that Bluetooth Sharing is disabled on managed macOS devices, preventing other Bluetooth-connected devices from browsing or transferring files to the Mac.Bluetooth Sharing allows paired devices to browse the Mac's file system and transfer files without network access. This is a data exfiltration path that does not traverse network monitoring or DLP controls. A paired Bluetooth device - including a personal phone - can copy corporate files directly over Bluetooth.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Computer Name Does Not Contain PII or Protected Organizational Information
wt.macos.sharing.computer-name-no-pii
LOWChecks that the macOS computer name does not contain personally identifiable information or protected organisational information, preventing the device name from disclosing user or company details over the network.The computer name is broadcast over mDNS and visible to all devices on the same network segment. A computer name that includes the user's full name, job title, department, or company name aids attackers in targeting specific individuals during network reconnaissance, and discloses organisational information to anyone on the network.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Content Caching Is Disabled
wt.macos.sharing.content-caching-disabled
LOWChecks that Content Caching is disabled on managed macOS devices, preventing the device from acting as a caching server for Apple software downloads for other devices on the network.Content Caching turns the Mac into a local distribution point for Apple software and iCloud content. When enabled, the device maintains a cache of downloaded content and serves it to other Macs and iOS devices on the network, increasing disk usage and network activity. On a workstation, this caching role increases the device's exposure and resource consumption without a clear security benefit.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure File Sharing Is Disabled
wt.macos.sharing.file-sharing-disabled
HIGHChecks that File Sharing (AFP/SMB) is disabled on managed macOS devices, preventing the device from sharing its file system over the network.File Sharing opens AFP and SMB services on the device, making it a network file server accessible to other machines on the same network. A compromised account or guest access misconfiguration can expose all shared directories. Attackers who reach this service can use it for lateral movement, data exfiltration, or ransomware deployment.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Internet Sharing Is Disabled
wt.macos.sharing.internet-sharing-disabled
HIGHChecks that Internet Sharing is disabled on managed macOS devices, preventing the device from acting as a network access point or NAT gateway for other devices.Internet Sharing creates a Wi-Fi hotspot or shares an Ethernet connection with other devices. This creates an unmonitored network segment that bypasses corporate network security controls. Devices connecting through the shared connection are not subject to the corporate firewall, proxy, or network access control policies.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Media Sharing Is Disabled
wt.macos.sharing.media-sharing-disabled
LOWChecks that Media Sharing is disabled on managed macOS devices, preventing the device from serving its media library to other devices on the local network.Media Sharing opens a media streaming service that is discoverable by any device on the local network. While primarily used for music and video, enabling this service increases the device's network footprint, consumes resources, and may inadvertently expose media files to discovery by unexpected network participants.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Printer Sharing Is Disabled
wt.macos.sharing.printer-sharing-disabled
HIGHChecks that Printer Sharing is disabled on managed macOS devices, preventing the device from sharing locally connected printers with other network hosts.Printer Sharing opens a CUPS-based printing service on the device. Allowing arbitrary hosts to submit print jobs could expose printer resources and print queue data to unexpected parties. It also unnecessarily extends the device's listening service footprint on the corporate network.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Remote Apple Events Is Disabled
wt.macos.sharing.remote-apple-events-disabled
HIGHChecks that Remote Apple Events is disabled on managed macOS devices, preventing remote AppleScript execution from network hosts.Remote Apple Events allows scripts running on remote computers to send AppleScript commands to the device over the network. AppleScript can manipulate the UI, read data from applications, and execute shell commands. An attacker with network access who can authenticate to this service can perform arbitrary actions on the device.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Remote Login Is Disabled
wt.macos.sharing.remote-login-disabled
HIGHChecks that Remote Login (SSH) is disabled on managed macOS devices, preventing inbound SSH connections that could provide remote shell access to the device.SSH Remote Login opens port 22 for inbound connections on the corporate network. Any authenticated account - or an attacker who has compromised credentials - can log in remotely and execute arbitrary commands, access local files, or use the device as a pivot point for lateral movement. Workstations do not require inbound SSH and should have this service disabled.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Remote Management Is Disabled
wt.macos.sharing.remote-management-disabled
HIGHChecks that Remote Management (Apple Remote Desktop) is disabled on managed macOS devices, preventing remote screen control and management via the ARD protocol.Remote Management opens the ARD service, which provides full screen control, remote script execution, and file transfer to authenticated users over the network. If enabled without strict access controls, an attacker who compromises an admin account or exploits the service can take complete control of the device's interface, exfiltrate data, and deploy malware.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Screen Sharing Is Disabled
wt.macos.sharing.screen-sharing-disabled
HIGHChecks that Screen Sharing (VNC) is disabled on managed macOS devices, preventing remote viewing and control of the device's display over the network.Screen Sharing opens a VNC-compatible service that allows authenticated users to view and control the desktop remotely. If enabled, this service is accessible to any host on the local network that can authenticate. An attacker with stolen credentials can observe the user's screen, interact with applications, and access all open data without any additional foothold.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Siri Is Disabled
wt.macos.siri.disabled
HIGHChecks that Siri is disabled on managed macOS devices, preventing the voice assistant from processing queries that may involve corporate data.Siri on macOS processes natural language queries that may include context from open applications, documents, and conversations. Queries are processed using Apple's cloud services in many configurations. Disabling Siri prevents corporate information from being inadvertently included in queries sent to Apple's inference infrastructure.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Listen for Siri Is Disabled
wt.macos.siri.listen-disabled
HIGHChecks that the Hey Siri always-on voice activation feature is disabled on managed macOS devices, preventing the microphone from continuously monitoring for the wake word.Always-on microphone listening for the Siri wake word means the device's microphone is continuously active, processing ambient audio. In sensitive environments - executive offices, boardrooms, or spaces where confidential conversations occur - this passive monitoring is inappropriate. Disabling it ensures the microphone is not capturing environmental audio outside of deliberate user interaction.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Apple Mobile File Integrity Is Enabled
wt.macos.system.amfi-enabled
HIGHChecks that Apple Mobile File Integrity (AMFI) is enabled on managed macOS devices, ensuring the kernel-level code signing enforcement is active.AMFI is the macOS kernel extension responsible for enforcing code signing requirements. Without AMFI, unsigned code can execute with full trust, bypassing Gatekeeper and removing the primary OS-level barrier against unsigned malware. Disabling AMFI is a technique used by attackers and rootkits to allow unsigned kernel modifications.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure System-Wide Applications Are Not World-Writable
wt.macos.system.apps-not-world-writable
HIGHChecks that application bundles in /Applications are not world-writable on managed macOS devices, preventing any local user from modifying installed applications.World-writable application bundles allow any user on the system - including standard accounts - to modify the application's executable files or resources. This enables privilege escalation by replacing a legitimate application binary with a malicious one, which would then execute with the permissions of any higher-privileged user who runs the application.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Authenticated Root Is Enabled
wt.macos.system.authenticated-root-enabled
HIGHChecks that Authenticated Root is enabled on managed macOS devices, ensuring the macOS system volume is cryptographically sealed and mounted read-only.Authenticated Root seals the macOS system volume with a cryptographic hash that is verified at boot. Any modification to system files - by malware, a rootkit, or a compromised installation process - invalidates the seal and prevents the device from booting. Disabling Authenticated Root allows persistent system-level modifications that survive reboots.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Home Folders Are Secure
wt.macos.system.home-folders-secure
HIGHChecks that home directories on managed macOS devices have secure permissions, preventing other local users from reading or writing to each other's home folders.If home directories have overly permissive permissions (e.g. 755 or world-readable), any local user on the device can browse the contents of other users' home folders. On a shared device, this allows one compromised account to read another user's documents, SSH keys, application data, and cached credentials without privilege escalation.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure System Integrity Protection Status (SIP) Is Enabled
wt.macos.system.sip-enabled
CRITICALChecks that System Integrity Protection (SIP) is enabled on managed macOS devices, ensuring that protected system directories and processes cannot be modified even by root.SIP prevents processes running as root from modifying protected locations including /System, /usr, /bin, and /sbin, and blocks kernel extension loading without Apple approval. Without SIP, a process that achieves root access - through privilege escalation or social engineering - can modify system binaries, install persistent malware, and disable security tools with no further barrier.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure No World Writable Folders Exist in the Library Folder
wt.macos.system.world-writable-library-folder
MEDIUMChecks that no world-writable directories exist within the /Library folder on managed macOS devices, preventing standard users from writing to shared library locations.World-writable directories in /Library allow any user to plant files in locations that are loaded by system processes, other users' applications, or launched daemons. Attackers can use world-writable Library locations to insert malicious LaunchAgents, frameworks, or plugins that execute with elevated privileges when the system or a privileged user loads them.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure No World Writable Folders Exist in the System Folder
wt.macos.system.world-writable-system-folder
HIGHChecks that no world-writable directories exist within the /System folder on managed macOS devices, protecting critical system directories from modification by standard users.World-writable directories in /System allow any local user to plant files in OS-critical locations. While SIP normally protects /System/Library, legacy or misconfigured directories may fall outside SIP's protection scope. A writable directory in a trusted system path can be used to inject malicious content that executes with system-level trust.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Set Time and Date Automatically Is Enabled
wt.macos.time.auto-set-enabled
LOWChecks that the date and time are set automatically via network time on managed macOS devices, preventing manual clock manipulation.Accurate system time is essential for certificate validation, Kerberos ticket issuance, audit log timestamp integrity, and MFA token validation. An incorrectly set clock can cause TLS certificate errors, break SSO authentication, and produce misleading timestamps in security logs that complicate incident investigations.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure the Time Service Is Enabled
wt.macos.time.service-enabled
LOWChecks that the timed time synchronisation service is enabled on managed macOS devices, ensuring the NTP-based clock synchronisation daemon is active.The timed service maintains ongoing clock accuracy by periodically synchronising with NTP servers. Without it, clock drift accumulates over time, gradually invalidating time-sensitive security mechanisms including certificate validity checks, Kerberos ticket time windows, and log correlation. Enabling the service ensures continuous clock accuracy.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Screen Saver Corners Are Secure
wt.macos.ui.hot-corners-secure
MEDIUMChecks that no hot corner on managed macOS devices is configured to disable the screensaver, preventing users from setting up a gesture that bypasses automatic screen lock.Hot corners can be assigned to disable the screensaver. A user who sets this up can trivially prevent the screensaver from activating, negating automatic screen lock policies. In shared or open-plan environments, this creates a persistent window during which an unattended device remains unlocked indefinitely.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Audit iPhone Mirroring
wt.macos.ui.iphone-mirroring-audit
LOWAudits whether iPhone Mirroring is enabled on managed macOS devices, reviewing whether linked iPhones can be controlled and mirrored from the corporate Mac.iPhone Mirroring allows an iPhone to be fully controlled from a connected Mac. When enabled, the Mac can access all iPhone content - including personal messages, apps, and stored credentials - and mirror the iPhone's screen. On a managed Mac, this creates a path for users to interact with personal devices in ways that blur the data boundary between corporate and personal environments.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Audit Menu Bar and Control Center Icons
wt.macos.ui.menu-bar-audit
LOWAudits the icons visible in the menu bar and Control Center on managed macOS devices, reviewing whether status indicators for security-relevant features such as Wi-Fi, VPN, and location services are visible.Menu bar icons provide real-time visual indicators of the device's security-relevant state - including active network connections, VPN status, microphone or camera usage, and location access. Users who cannot see these indicators may be unaware of unexpected network connections, ongoing screen recordings, or active location tracking.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Audit Universal Control Settings
wt.macos.ui.universal-control-audit
LOWAudits whether Universal Control is enabled on managed macOS devices, reviewing whether the keyboard and mouse can be shared with and used to control other nearby Apple devices.Universal Control allows a single keyboard and mouse to seamlessly control multiple Macs and iPads. While convenient, it creates a pathway for content to be dragged and dropped between a managed corporate Mac and a personal unmanaged device, potentially moving corporate files outside the managed boundary without a deliberate copy action.None - no tenant data read (not automatable via API, reported as a manual/indeterminate result)
Ensure Install Application Updates from the App Store Is Enabled
wt.macos.updates.app-store-updates-enabled
HIGHChecks that automatic installation of App Store application updates is enabled on managed macOS devices, ensuring third-party applications from the App Store are kept up to date.App Store applications installed on corporate devices may have known vulnerabilities if not kept current. Enabling automatic App Store updates ensures that security patches released by developers are applied promptly without requiring user intervention, reducing the window of exposure for vulnerable application versions.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Apple-provided Software Updates Are Installed
wt.macos.updates.current
HIGHChecks that Apple-provided software updates have been installed on managed macOS devices, ensuring the operating system and bundled components are running with current security patches.macOS security updates address vulnerabilities that are actively exploited - including kernel privilege escalation, sandbox escapes, and browser engine flaws. Devices running outdated software are exposed to attacks that Apple has already issued fixes for. Verifying that updates are applied ensures the device benefits from Apple's ongoing security improvements.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Software Update Deferment Is Less Than or Equal to 30 Days
wt.macos.updates.deferment-limited
HIGHChecks that software update deferment on managed macOS devices is configured to 30 days or fewer, ensuring security updates are not delayed beyond an acceptable window.Update deferment periods greater than 30 days extend the window during which known and potentially actively exploited vulnerabilities remain unpatched on corporate devices. Apple issues security updates addressing zero-days and critical kernel vulnerabilities - delaying these patches beyond 30 days significantly increases risk exposure.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Download New Updates When Available Is Enabled
wt.macos.updates.download-enabled
HIGHChecks that automatic download of new updates is enabled on managed macOS devices, ensuring updates are fetched in the background so they are ready to install promptly.Without automatic download, users must manually initiate the download of each update before they can install it. This introduces additional delays in applying security patches, extending the window during which known vulnerabilities remain unaddressed on the device. Background downloading removes a manual step from the patching process.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Install of macOS Updates Is Enabled
wt.macos.updates.macos-install-enabled
HIGHChecks that automatic installation of macOS operating system updates is enabled on managed devices, ensuring major security updates are applied without requiring manual user action.macOS updates deliver critical security patches for kernel vulnerabilities, TLS libraries, and system frameworks. If automatic installation is not enabled, security updates accumulate and remain uninstalled until a user manually initiates the process. Many users defer updates indefinitely, leaving known vulnerabilities active on corporate devices.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles
Ensure Install Security Responses and System Files Is Enabled
wt.macos.updates.security-responses-enabled
HIGHChecks that Rapid Security Responses and system file updates are automatically installed on managed macOS devices, ensuring out-of-band security patches can be applied without a full OS update.Apple's Rapid Security Response mechanism allows critical security patches to be delivered and applied between full macOS updates, typically within hours of discovery for actively exploited vulnerabilities. Disabling this mechanism means the device must wait for the next full update cycle before receiving patches for zero-day or critical vulnerabilities under active exploitation.DeviceManagementConfiguration.Read.All - via macosCompliancePolicies, macosConfigurationProfiles