Headlines refreshed Sun Oct 11, 11:45 AM ET (1 h ago) · content checked against vendor docs
⌘ macOS security
macOS, locked down.
This guide covers the two newest macOS releases as of October 2026. macOS Golden Gate 27 shipped on September 14, 2026 and runs only on Apple silicon Macs. macOS Tahoe 26 is the release before it and still gets security updates. Each tip is marked for everyday users, power users or admins, and links to Apple's own docs or the tool maker's docs. Check commands only read settings. Commands that change anything are listed separately and need you to run them on purpose.
1. Patch first: updates and Background Security Improvements
Stay on a supported macOS and install updates fast
everyone
On 2026-09-14 Apple released Golden Gate 27, Tahoe 26.7 and Sequoia 15.8 together, followed by 27.0.1, 26.7.1 and 15.8.1 on 2026-09-28. Sonoma was not part of the September release. An unpatched Mac is the easiest Mac to break into.
Go to Apple menu > System Settings > General > Software Update. Turn on Automatic Updates, then click the More Info button next to it and make sure "Install system data files and security updates" is on. Apple's security releases page lists what each update fixes.
Turn on automatic Background Security Improvements
everyone
Starting with macOS 26.1, Background Security Improvements (BSI) deliver small security fixes between full updates, for parts such as Safari, WebKit and other system libraries. A Safari fix can take effect as soon as you relaunch Safari; the rest applies at the next restart.
Go to System Settings > Privacy & Security > Background Security Improvements and turn on Automatically Install. In rare cases of compatibility problems, Apple may remove a BSI and ship the fix in a later update.
Fleet: move update enforcement to declarative management
admin
Apple says legacy software update management no longer functions in all 27.0 operating systems. That includes software update commands and queries, recommended cadence settings, and restrictions such as deferrals and Background Security Improvements.
Use your MDM's declarative software update configuration to set target versions and enforcement deadlines. Use it to decide whether BSIs install automatically and whether users may remove them.
Know about silent background security data updates
power user
XProtect signatures, Gatekeeper configuration data and other security-configuration updates install in the background, separately from macOS updates. If you turn that option off, your Mac falls behind without telling you.
In Tahoe and later, leave "Install system data files and security updates" on under Software Update > Automatic Updates > More Info. To see what has installed, hold Option, choose Apple menu > System Information, then Software > Installations.
On Apple silicon the drive is always encrypted, but FileVault adds the step that keeps anyone from decrypting your data without your login password.
Go to System Settings > Privacy & Security > FileVault and turn it on. Choose to let your iCloud account unlock the disk, or create a recovery key and keep it somewhere safe that is not with the Mac.
Admins need a way to recover a locked managed Mac that doesn't depend on the user writing down a key. On macOS 26.4 and later, FileVault turns on during Setup Assistant by default, so escrow is what you control.
Use your MDM's FileVault settings to escrow the personal recovery key and stop users from turning FileVault off. Use fdesetup to confirm a key exists and to rotate it if it is exposed.
Check — read-only
sudo fdesetup haspersonalrecoverykey; sudo fdesetup list
Apple silicon Macs check every boot stage against Apple's signatures. Full Security only allows booting the latest signed macOS that was available at install time. Reduced Security allows older macOS versions and kernel extensions.
Only lower this if you truly need third-party kernel extensions. To check or change it, shut down, press and hold the power button until Startup Options appears, choose Options, then Utilities > Startup Security Utility, and leave Full Security selected.
System Integrity Protection (SIP) limits what even the root user can change in protected parts of macOS, such as /System, /usr, /bin and /sbin. Software that gets your admin password still can't overwrite those files.
Don't turn SIP off. If a tool tells you to disable SIP, don't use that tool.
Turn on Find My Mac so Activation Lock protects it
everyone
With Activation Lock, your Apple Account password is needed before anyone can turn off Find My, erase the Mac, or reactivate and use it.
Go to System Settings > [your name] > iCloud, click See All, then Find My Mac, and turn it on. Activation Lock needs two-factor authentication and, on Apple silicon, Full Security. Turn off Find My before you sell or give away the Mac.
3. Stop bad code: Gatekeeper, notarization, XProtect
Only open apps from the App Store or identified, notarized developers
everyone
Gatekeeper checks that apps from outside the App Store come from an identified developer, are notarized by Apple and haven't been altered. Apple can also revoke an app it later finds to be malicious.
Go to System Settings > Privacy & Security, scroll to Security, and under "Allow apps downloaded from" choose App Store and identified developers (or App Store only). To open a blocked app, you have to try opening it, then click Open Anyway in Privacy & Security. Only do that when you know exactly where the app came from.
XProtect is macOS's built-in antivirus. It uses YARA signatures that Apple updates on its own schedule, blocks known malware when an app first launches or changes, and moves it to the Trash.
No setup is needed. Keep the background security updates option on. The xprotect command shows the installed signature version and can trigger an update.
Fleet: block or allow binaries with declarative rules (macOS 27)
admin
On supervised Macs with macOS 27, declarative device management can allow or deny apps and binaries. Rules match on CD Hash, Team ID, Signing ID, path prefix or signing state. Unsigned, ad hoc-signed and development-signed binaries are denied even when the list is empty.
Deploy the allow/deny apps and binaries configuration from your MDM. Deny mode blocks only what you list; allow mode runs only what you list plus essential system binaries. If one Mac gets both, the more restrictive mode wins. Start in deny mode, then move to allow mode once you have an inventory.
Pick up the other enterprise changes in Golden Gate
admin
Golden Gate lets Platform SSO sign in with your identity provider over OpenID at FileVault unlock, the Lock Screen and the login window, including multi-factor and QR code sign-in. It can require Touch ID or Apple Watch at login, adds a consolidated privacy consent prompt, and lets MDM restrict Siri AI and Visual Intelligence. Apps can no longer read the local TCC database directly.
Read Apple's enterprise What's New for Golden Gate. Update your MDM baselines before you approve the upgrade for the fleet.
In stealth mode the Mac doesn't answer probing requests such as ping, so it is harder to find on hotel or café Wi-Fi.
Go to System Settings > Network > Firewall > Options and turn on Enable stealth mode. Consider turning on Block all incoming connections when you are on untrusted networks.
Every sharing service that is on, such as Remote Login (SSH), Screen Sharing, File Sharing or Remote Management, opens a port someone can reach. Sharing services can connect through the firewall when turned on.
Go to System Settings > General > Sharing and turn off anything you don't need. Then list the listening ports to confirm.
Private Relay encrypts traffic leaving your device and sends it through two separate relays, so no one can use your IP address, location and browsing to build a profile of you.
Go to System Settings > [your name] > iCloud > Private Relay and turn it on (requires iCloud+). It must be turned on on each device. Per network, "Limit IP address tracking" must stay on for it to work.
Do daily work in a standard account, not an admin account
power user
Malware runs with your rights. A standard user can't add other users or change other users' settings, and has to ask for an admin password for system-wide changes. Apple also warns never to set up automatic login for an administrator.
Create a separate administrator account in System Settings > Users & Groups. Then click the info button next to your daily account and turn off Allow this user to administer this computer.
The Passwords app keeps passwords, passkeys and verification codes in one place and shows Security Recommendations for weak, reused or leaked passwords. A passkey can't be phished or leaked by a website breach.
Open the Passwords app and fix everything it lists under Security. When a site offers a passkey, accept it.
With Advanced Data Protection (ADP), most iCloud data, including backups, Photos, Notes and iCloud Drive, is end-to-end encrypted, so only your trusted devices hold the keys.
Update your devices first. Then go to System Settings > [your name] > iCloud > Advanced Data Protection > Turn On, and follow the steps to review your recovery methods. iCloud.com web access is off by default while ADP is on.
Your Apple Account controls Find My, Activation Lock and iCloud. Physical security keys stop attackers from phishing or intercepting your second factor.
Get at least two FIDO Certified security keys. Go to System Settings > [your name] > Sign-In & Security > Two-Factor Authentication > Security Keys and add them. If you lose all trusted devices and keys you can be locked out for good.
Lock the screen quickly and require the password right away
everyone
An unlocked, unattended Mac gets past every other control on this list.
Go to System Settings > Lock Screen and set Require password after screen saver begins or display is turned off to Immediately. Set short display-off times on battery and power adapter. Use Control-Command-Q to lock the screen.
macOS privacy controls (TCC) decide which apps can use your camera, microphone, screen recording, input monitoring, files and more. Malware tries hardest to get Accessibility and Full Disk Access.
Go to System Settings > Privacy & Security. Check Full Disk Access, Accessibility, Screen & System Audio Recording, Input Monitoring, Camera and Microphone, and remove anything you don't recognize.
Persistence is how malware survives a reboot. Login items and apps allowed to run in the background are listed in one place.
Go to System Settings > General > Login Items & Extensions. Review Open at Login and App Background Activity, and turn off anything you don't recognize. Also check Endpoint Security and Network extensions there.
Fleet: approve background items and privacy permissions by profile
admin
If you pre-approve known agents by profile, users don't get trained to click Allow on everything.
Deploy a Managed Login Items (com.apple.servicemanagement) payload with rules matched on Team ID or bundle ID, plus a Privacy Preferences Policy Control payload for each managed tool. On Golden Gate, users are notified about apps given Accessibility by PPPC and can turn that off.
Check for unknown configuration profiles and MDM enrollment
power user
A configuration profile can set up accounts, Wi-Fi, VPN and other settings, so a rogue one can redirect your traffic.
Go to System Settings > General > Device Management. Remove any profile you didn't install on purpose. On a managed Mac, ask IT before removing anything.
Check — read-only
profiles status -type enrollment; sudo profiles show -type configuration
On Mac laptops with Apple silicon, new USB and Thunderbolt devices and SD cards must be approved before they can exchange data. Don't Allow still lets a device charge, which is the safe choice at public charging stations.
Go to System Settings > Privacy & Security > Accessories and set Allow accessories to connect to Ask for new accessories or Always ask.
Use Lockdown Mode if you could be targeted by spyware
everyone
Lockdown Mode greatly reduces what an attacker can reach. It blocks most Messages attachments and link previews, some complex web technologies, configuration profiles and MDM enrollment, and on Apple silicon laptops needs the Mac unlocked plus your approval to connect an accessory.
Go to System Settings > Privacy & Security > Lockdown Mode > Turn On, then click Turn On & Restart. You can exclude trusted websites, apps or contacts, which lowers protection. Turn it on separately on each Mac.
A Mac in Lockdown Mode can't install configuration profiles or enroll in MDM or supervision. Admins should plan for that before users turn it on.
Turn Lockdown Mode on only on unmanaged Macs, or enroll the Mac first and test that your MDM workflows still work. Golden Gate MDM status reports now include Lockdown Mode status.
Build your baseline with the macOS Security Compliance Project
admin
The NIST-led mSCP turns NIST 800-53, 800-171, CIS Benchmarks and the DISA STIG into ready-made profiles, scripts and documentation. mSCP 2.0, Release 27.0 covers macOS 27, and Tahoe Guidance Revision 3.0 covers macOS 26.
Clone the repo. Generate a baseline, for example CIS Level 1, and from it get the configuration profiles plus a compliance script that has check-only and fix modes. Run the check first.
Read the Apple Platform Security guide once a year
power user
It is Apple's official explanation of secure boot, the Secure Enclave, Data Protection, XProtect, privacy controls and Background Security Improvements. Use it to answer why a control works.
Read the web version. Re-read the sections that change after each major release.
Use the Endpoint Security API instead of kernel extensions
admin
Third-party security tools should use Apple's Endpoint Security framework, not kernel extensions, which need Reduced Security. Since macOS 15 these tools can also see Gatekeeper user-override events.
When you choose EDR or allowlisting tools, require Endpoint Security system extensions, and approve them by MDM.