Skip to content

macOS 15 Sequoia · macOS 26 Tahoe · Apple silicon

Harden every Mac, layer by layer.

A practical map of macOS security controls — from FileVault and System Integrity Protection to TCC, MDM profiles and NIST mSCP baselines — with the commands to apply and verify each one.

areas
11
guides
11
glossary terms
12
admin@mac — zsh — posture-check

$ fdesetup status

FileVault is On.

$ csrutil status

System Integrity Protection status: enabled.

$ spctl --status

assessments enabled

$ socketfilterfw --getglobalstate

Firewall is enabled. (State = 1)

$ profiles status -type enrollment

MDM enrollment: Yes (User Approved)

✓ FileVault✓ SIP✓ Gatekeeper✓ Firewall✓ MDM
Checking a Mac's security posture from the terminal

defense-in-depth

Defense in depth, the Apple way

macOS security is a stack of cooperating layers. Hardening means confirming each one is on, enforced and monitored.

  1. L1

    Hardware & boot

    The Secure Enclave, the boot ROM and Startup Security policy decide what code may run before macOS loads.

  2. L2

    Operating system

    SIP and the Signed System Volume keep the OS read-only and verifiable, even against root.

  3. L3

    Apps & data

    Gatekeeper, notarization, XProtect and TCC gate what runs and what it can touch.

  4. L4

    Policy & visibility

    MDM profiles enforce the baseline; unified logs and Endpoint Security tell you when it drifts.

/Library/Hardening

The macOS hardening map

Eleven areas, from the boot chain to the people most likely to be targeted. Each one links to guides with configuration, verification commands and pitfalls.

  1. 01

    Disk Encryption & Boot

    FileVault, recovery-key escrow, Startup Security and Activation Lock.

    FileVaultfdesetupRecovery key1 guide
  2. 02

    Platform Integrity

    System Integrity Protection, the sealed system volume and kernel extensions.

    SIPSigned System Volumekmutil1 guide
  3. 03

    App Execution Control

    Gatekeeper, code signing, notarization, XProtect and binary allowlisting.

    GatekeeperNotarizationXProtect1 guide
  4. 04

    Network & Firewall

    Application Firewall, stealth mode, pf rules, sharing services and encrypted DNS.

    socketfilterfwpfStealth mode1 guide
  5. 05

    Accounts & Privileges

    Standard users by default, scoped sudo, password policy and screen lock.

    sudoersStandard userpam_tid1 guide
  6. 06

    Privacy & TCC

    Transparency, Consent and Control: Full Disk Access, screen recording and PPPC profiles.

    TCCPPPCFull Disk Access1 guide
  7. 07

    Updates & Patching

    softwareupdate, automatic security responses and DDM update enforcement.

    softwareupdateDDMBackground Security Improvements1 guide
  8. 08

    MDM & Configuration Profiles

    Automated enrollment, supervision, .mobileconfig payloads and declarative management.

    .mobileconfigADESupervision1 guide
  9. 09

    Logging & Detection

    Unified Logging predicates, the Endpoint Security framework and EDR deployment.

    Unified LogEndpoint Securityeslogger1 guide
  10. 10

    Benchmarks & Compliance

    NIST mSCP baselines, CIS macOS Benchmarks, tailoring and continuous compliance.

    NIST mSCPCIS BenchmarkBaselines1 guide
  11. 11

    Lockdown & High-Risk Users

    Lockdown Mode, Advanced Data Protection and security keys for targeted people.

    Lockdown ModeADPSecurity keys1 guide
  12. macOS security glossary

    Short, accurate definitions of the Apple platform security terms used across the guides.

~/guides

Latest guides

View all guides
08 · MDM & Configuration Profiles

MDM and Configuration Profiles for Mac Hardening

How MDM, Automated Device Enrollment, supervision, configuration profiles and Declarative Device Management fit together to enforce a macOS security baseline.

Read guide
03 · App Execution Control

Gatekeeper, XProtect and Notarization on macOS

How Gatekeeper, quarantine, code signing, notarization and XProtect decide what runs on a Mac, how to verify them, and how to manage them with MDM and Santa.

Read guide
11 · Lockdown & High-Risk Users

Lockdown Mode on macOS: Protecting High-Risk Users

What Lockdown Mode restricts on macOS, how to enable it, how it affects MDM, and the companion controls high-risk users need, from ADP to security keys.

Read guide

How the guides are written

01

Verify, don't assume

Every control comes with the command that proves its current state, so you can audit a Mac instead of trusting a checkbox.

02

Enforce at scale

Where a setting can be managed, we show the configuration profile or MDM approach alongside the local command.

03

Mapped to benchmarks

Controls are explained in the context of the CIS macOS Benchmarks and the NIST macOS Security Compliance Project.