1.152 APPL-26-005110

Information

The macOS system must enforce enrollment in Mobile Device Management (MDM).

GROUP ID: V-277179
RULE ID: SV-277179r1148989

Users must enroll their Mac in MDM software.

User Approved MDM (UAMDM) enrollment or enrollment via Apple Business Manager (ABM)/Apple School Manager (ASM) is required to manage certain security settings. Currently, these include:

- Allowed Kernel Extensions.
- Allowed Approved System Extensions.
- Privacy Preferences Policy Control Payload.
- ExtensibleSingleSignOn.
- FDEFileVault.
- Activation Lock Bypass.
- Access to Bootstrap Tokens.
- Scheduling Software Updates.
- Query list and delete local users.

Solution

Configure the macOS system by ensuring that the system is enrolled via UAMDM.

See Also

https://workbench.cisecurity.org/benchmarks/26538