Check: APPL-15-005110
Apple macOS 15 (Sequoia) STIG:
APPL-15-005110
(in versions v1 r3 through v1 r1)
Title
The macOS system must enforce enrollment in Mobile Device Management (MDM). (Cat II impact)
Discussion
Users must enroll their Mac in MDM software. User Approved MDM (UAMDM) enrollment or enrollment via Apple Business Manager (ABM)/Apple School Manager (ASM) is required to manage certain security settings. Currently, these include: * Allowed Kernel Extensions. * Allowed Approved System Extensions. * Privacy Preferences Policy Control Payload. * ExtensibleSingleSignOn. * FDEFileVault. * Activation Lock Bypass. * Access to Bootstrap Tokens. * Scheduling Software Updates. * Query list and delete local users.
Check Content
Verify the macOS system is configured to enforce enrollment in mobile device management with the following command: /usr/bin/profiles status -type enrollment | /usr/bin/awk -F: '/MDM enrollment/ {print $2}' | /usr/bin/grep -c "Yes (User Approved)" If the result is not "1", this is a finding.
Fix Text
Configure the macOS system by ensuring that the system is enrolled via UAMDM.
Additional Identifiers
Rule ID: SV-268569r1034647_rule
Vulnerability ID: V-268569
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |