Skip to content

The 24 Jamf Pro security checks Black Cat runs

Black Cat SSPM evaluates 24 security policies against your Jamf Pro configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.

encryption

highComputer FileVault Disabled

Enforce FileVault disk encryption on all managed Macs

mediumComputer FileVault Recovery Key Invalid

Re-escrow a valid FileVault personal recovery key for the affected Mac

lowLocal Account FileVault Disabled

Enable a local account for FileVault unlock on the affected Mac

governance

infoConfiguration Profile Scoped To All Computers

Review configuration profiles scoped to all computers for blast radius

lowPolicy Disabled

Review disabled policies that may leave a security gap

lowPolicy Scoped To All Computers

Review script-running policies scoped to all computers for blast radius

hardening

highComputer SIP Disabled

Re-enable System Integrity Protection on Macs reporting SIP disabled

highComputer Gatekeeper Disabled

Re-enable Gatekeeper to block unsigned applications

mediumComputer Firewall Disabled

Enable the application firewall via a Security configuration profile

mediumComputer Remote Desktop Enabled

Review Macs with Apple Remote Desktop / Screen Sharing enabled

lowComputer Recovery Lock Missing

Set a Recovery Lock on Apple silicon Macs to protect recoveryOS

mediumComputer Secure Boot Reduced

Restore full Secure Boot security on Macs reporting reduced or no security

mediumConfiguration Profile User Removable

Make security configuration profiles non-removable by end users

mediumAPI Integration Long Token Lifetime

Reduce the access token lifetime for API integrations issuing long-lived tokens

lifecycle

mediumComputer Stale Check-in

Investigate or retire Macs that have not checked in for 30+ days

lowComputer Activation Lock Enabled

Review Macs with Activation Lock enabled to avoid wipe/reuse lockout

infoAPI Integration Disabled

Review disabled API integrations that may be stale

management

mediumMobile Device Unsupervised

Bring unsupervised mobile devices under supervision for full management

highMobile Device Unmanaged

Re-establish MDM management on mobile devices reporting unmanaged

patching

mediumComputer OS Outdated

Update Macs running macOS below the supported major version floor

mediumMobile Device OS Outdated

Update mobile devices running an OS below the supported major version floor

privilege

mediumLocal Admin Account On Managed Mac

Review standing local administrator accounts on managed Macs

mediumPolicy Ongoing Self Service Script

Review user-triggered Self Service policies that run scripts

mediumAPI Role Overbroad

Review API roles granting an unusually large number of privileges

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial