Deploying a macOS compliance policy
Now that we have looked at Apple devices, we can look at making sure our corporate-managed macOS device is compliant.
One important thing to note with macOS is that unlike our other policies (except iOS), if you configure the PIN setting within a macOS compliance policy, it will enforce the setting on the device rather than just reporting on it.
Getting started
As with the other recipes, we will start by looking at the settings available to us.
Compliance settings
Now, let us run through the settings available for macOS devices.
Device Health
We will start with the single setting available under Device Health:
- Require system integrity protection: This stops protected files and folders from being changed by malicious software and was introduced in El Capitan. More information can be found here: https://support.apple.com/en-gb/HT204899.
Device Properties
Now, we will look at the settings for Device Properties...