Securing Apple Devices in Jamf: Security Features & Controls
By M. Crawley
A Jamf guide exploring the different security features.
Since Jamf is an MDM, especially one of its popularity, you can expect it to include a full suite of security features. In this article, we will discuss some key security features in the Jamf application that you may want to learn about.
Security Features
Passcode Policies
You can implement security features like passcode policies to enforce passcodes or passwords that meet complexity requirements on the managed Apple devices. You can choose to designate a threshold for incorrect passcode entries before the device can be locked or erased, and you may additionally set a cooldown period. This is a common practice in many other applications to prevent successful brute-force attempts.
Restrictions
Restrictions is another critical security feature in Jamf that you can use to help secure the company's Apple devices. Here are some key restriction features you can implement:
Web Content Filters: For blocking adult sites and other URLs considered to be unsafe. You may also add certain URLs to the allowlist to ensure access when needed.
Application Blacklist & Whitelist: Can be used to allow or deny the use of a specific category of application. For example, you may want to block apps like Facebook, Instagram, TikTok, etc. from use on company devices. To do this, add Social Media to the blocklisted categories. You may also restrict a specific application if you prefer not to block an entire category.
Certificate Distribution (SCEP, PKI): Use this to provide secure access to internal resources and WiFi networks. What this really means is that you can set up a digital certificate on the managed Apple device that will allow it to automatically connect to the company's WiFi or VPN network without the need for passwords; authentication is certificate-based, and this exhibits a stringent level of security between the device and the company's network.
Remote Lock & Remote Wipe: Features can be used to remotely lock the device or wipe its contents for protection of the device and its data. In a scenario where a user reports a managed device as stolen or lost, you can take these actions to protect access to company resources that may be on that device.
Common Restriction Options
Here's a list of restriction features you might implement:
| Restriction Feature | Function |
|---|---|
| Disable App Store | Prevents users from installing apps from the App Store |
| Prevent App Removal | Prevents the deletion of apps (managed or all, depending on config) |
| Disable Safari | Removes Safari browser |
| Disable Camera | Removes camera functionality |
| Disable FaceTime | Blocks access to FaceTime |
| Disable AirDrop | Prevents file sharing via AirDrop |
| Disable iMessage | Blocks use of iMessage |
| Disable Screen Recording | Prevents a user/users from using the screen recording feature |
| Disable Apple Music | Hides or disables access to Apple Music |
| Disable iCloud Services | Blocks iCloud features like backup, Drive, syncing, etc. |
| Disable Installing Configuration Profiles | Prevents users from manually installing profiles that could override Jamf's MDM |
| Enforce Explicit Content Filter | Restricts access to music, movies, and apps based on content ratings |
| Restrict Device Name Change | Prevents users from changing the device name |
| Disable Bluetooth Modification | Stops users from enabling or disabling Bluetooth |
| Disable Account Changes | Prevents editing or removing iCloud/Apple ID accounts |
| Disable Wallpaper Modification | Prevents the wallpaper from being changed |
| Restrict USB Accessories (iOS) | Prevents USB accessories from connecting to the device while locked (anti-theft measure) |
Real-World Security Scenarios
Web Content Management
A key function in security is managing user access. One such access you can restrict or allow within Jamf is web content. You may be asked to block a specific site from user access. In those situations, you can use Jamf Profiles to activate the Web Content Filter, Safelist, and Blocklist features.
Lost Device Management
You may also encounter situations where a user has lost their device. Because sensitive company data may be stored and accessed on these devices, you would need to activate a remote lock to render them useless and perform a remote wipe to remove all company data. Protecting data is one of your top priorities (always remember this).
Exploring More Security Features
There are a number of security features not mentioned above, so if you work within Jamf, make use of their documentation and exercise cautious exploration within your company's Jamf portal to familiarize yourself with security features that may be useful and applicable.


