Apple, Security Configuration Deviation

Systems managed by Endpoint Management automatically receive default security settings. Some processes may require a modification or repealing of one or more settings.

Filing a Baseline Deviation Request

Apple systems managed by Jamf Pro receive a default set of settings (or "baseline") that aligns with the Center for Internet Security (CIS) Level 1 benchmarks. This is in compliance with the campus security policies IT10-Client Computer Security Standard and IT11-Mobile Device Security Standard. While this baseline holds for many common use cases, there may be situations where a baseline setting prevents necessary business processes from occurring.

If a baseline setting prevents or greatly hinders a needed business process, consider whether an alternate process can achieve the same goal. A baseline setting should not be disabled without considering the negative security impact to the system. If no other option seems viable, file a Baseline Deviation Request.

High Risk Data

You will need to indicate whether High Risk data is stored or processed on the system(s).

Extra caution should be taken with such systems. If possible, consider using a different system for the deviation.

Benchmark Setting

In order to process the Baseline Deviation Request, the setting to be modified or disabled must be specified. See below for a list of settings.

Indicate the configuration name—not number—along with the requested value change, if applicable. For some settings, a modified value allows for a measure of security without disabling the setting entirely.

Business Need and Compensating Controls

To aid in advisement and record-keeping, a reason for the request is required. Please indicate the business process requiring the setting to be disabled or modified, and why any alternatives are unfeasible.

Also indicate any settings, policies or environmental factors would compensate for the decreased security from the deviation.

Example:

Business Need: Remote management of this application requires disabling this control. This application is required to process applications.
Compensating Controls: Campus firewall rules block access to the affected service from the internet. Access to the application is restricted to device local admins.

After Filing

Filed requests will be reviewed by Technology Services' Security Engineering. Based upon the information provided and current security context, you will receive an advisement.

Possible advisements:

    • No reservations — Security Engineering has no concerns with this deviation. It will immediately continue on to Endpoint Services for processing.
    • Some reservations — Security Engineering has some concerns with this deviation. You will receive suggestions for compensating controls to harden the system.
    • Against — Security Engineering has major concerns with this deviation. You will receive suggestions for alternatives to the baseline deviation.

For advisements of "Some reservations" or "Against," you will have the option to rescind or continue the request. If you choose to continue the request, it will be sent on to Endpoint Services for processing.



Keywords:
mdm jamf mac macos setting baseline cis benchmark config 
Doc ID:
162651
Owned by:
Michael P. in UI College of Veterinary Medicine
Created:
2026-07-15
Updated:
2026-07-24
Sites:
University of Illinois College of Veterinary Medicine