Big Sur - Disable Bluetooth When no Approved Device is Connected

Information

The macOS system _MUST_ be configured to disable Bluetooth unless there is an approved device connected.

[IMPORTANT]
====
Information System Security Officers (ISSOs) may make the risk-based decision not to disable Bluetooth, so as to maintain necessary functionality, but they are advised to first fully weigh the potential risks posed to their organization.
====

Solution

This is implemented by a Configuration Profile.

mobileconfig profile info:

com.apple.ManagedClient.preferences:
com.apple.MCXBluetooth:
DisableBluetooth
True

See Also

https://github.com/usnistgov/macos_security