ArticlesSecuring Apple Devices in Jamf: Security Features & Controls
JamfEndpoint Security12 min read

Securing Apple Devices in Jamf: Security Features & Controls

By M. Crawley

A Jamf guide exploring the different security features.

Since Jamf is an MDM, especially one of its popularity, you can expect it to include a full suite of security features. In this article, we will discuss some key security features in the Jamf application that you may want to learn about.

Security Features

Passcode Policies

You can implement security features like passcode policies to enforce passcodes or passwords that meet complexity requirements on the managed Apple devices. You can choose to designate a threshold for incorrect passcode entries before the device can be locked or erased, and you may additionally set a cooldown period. This is a common practice in many other applications to prevent successful brute-force attempts.

Restrictions

Restrictions is another critical security feature in Jamf that you can use to help secure the company's Apple devices. Here are some key restriction features you can implement:

Web Content Filters: For blocking adult sites and other URLs considered to be unsafe. You may also add certain URLs to the allowlist to ensure access when needed.

Application Blacklist & Whitelist: Can be used to allow or deny the use of a specific category of application. For example, you may want to block apps like Facebook, Instagram, TikTok, etc. from use on company devices. To do this, add Social Media to the blocklisted categories. You may also restrict a specific application if you prefer not to block an entire category.

Certificate Distribution (SCEP, PKI): Use this to provide secure access to internal resources and WiFi networks. What this really means is that you can set up a digital certificate on the managed Apple device that will allow it to automatically connect to the company's WiFi or VPN network without the need for passwords; authentication is certificate-based, and this exhibits a stringent level of security between the device and the company's network.

Remote Lock & Remote Wipe: Features can be used to remotely lock the device or wipe its contents for protection of the device and its data. In a scenario where a user reports a managed device as stolen or lost, you can take these actions to protect access to company resources that may be on that device.

Common Restriction Options

Here's a list of restriction features you might implement:

Restriction Feature Function
Disable App Store Prevents users from installing apps from the App Store
Prevent App Removal Prevents the deletion of apps (managed or all, depending on config)
Disable Safari Removes Safari browser
Disable Camera Removes camera functionality
Disable FaceTime Blocks access to FaceTime
Disable AirDrop Prevents file sharing via AirDrop
Disable iMessage Blocks use of iMessage
Disable Screen Recording Prevents a user/users from using the screen recording feature
Disable Apple Music Hides or disables access to Apple Music
Disable iCloud Services Blocks iCloud features like backup, Drive, syncing, etc.
Disable Installing Configuration Profiles Prevents users from manually installing profiles that could override Jamf's MDM
Enforce Explicit Content Filter Restricts access to music, movies, and apps based on content ratings
Restrict Device Name Change Prevents users from changing the device name
Disable Bluetooth Modification Stops users from enabling or disabling Bluetooth
Disable Account Changes Prevents editing or removing iCloud/Apple ID accounts
Disable Wallpaper Modification Prevents the wallpaper from being changed
Restrict USB Accessories (iOS) Prevents USB accessories from connecting to the device while locked (anti-theft measure)

Real-World Security Scenarios

Web Content Management

A key function in security is managing user access. One such access you can restrict or allow within Jamf is web content. You may be asked to block a specific site from user access. In those situations, you can use Jamf Profiles to activate the Web Content Filter, Safelist, and Blocklist features.

Lost Device Management

You may also encounter situations where a user has lost their device. Because sensitive company data may be stored and accessed on these devices, you would need to activate a remote lock to render them useless and perform a remote wipe to remove all company data. Protecting data is one of your top priorities (always remember this).

Exploring More Security Features

There are a number of security features not mentioned above, so if you work within Jamf, make use of their documentation and exercise cautious exploration within your company's Jamf portal to familiarize yourself with security features that may be useful and applicable.

Related Topics

Related Reading