Skip to main content

โš™๏ธ๐Ÿ๐Ÿ’ปCP - Device Security - Restrictions

A Mac out of the box is a consumer device that happens to be at work. This is the profile that decides it is a work device that happens to be a Mac.

โš™๏ธType Configuration profile๐ŸPlatform macOS๐Ÿ’ปTarget Devices
reference-build ยท macos-device-security-restrictionsGolden Master reference
License tier
Business Premium (Intune)
Control plane
Intune Settings Catalog, com.apple.applicationaccess
Scope
macOS, all managed Macs
Reversibility
clean-revert

What this policy is about ๐Ÿโ€‹

macOS assumes it belongs to a person. Everything about the default configuration follows from that: iCloud is signed in, Desktop and Documents sync to it, AirDrop is on, Find My is on, and Continuity hands your work to a phone on the same Apple ID. For a personal Mac that is a genuinely good product. For a company Mac it means company data has a second, parallel home that nobody at the company can see.

This is the largest profile in the macOS baseline and the one with the widest reach. It does two things: it disables the System Settings panes that let a user undo the rest of the configuration, and it switches off the consumer services that move data outside the tenant.

๐Ÿค” The Apple ID is the whole point

Most of these settings orbit one thing: a personal Apple ID signed into a work machine. Block the sync surfaces and the Apple ID stops being a data route, even if the user keeps it signed in for the App Store.

Why this matters ๐Ÿ•ต๏ธโ€‹

The failure here is silent, which is what makes it worth doing properly. Nobody notices iCloud Desktop and Documents sync. It is on, it works, it is convenient, and it means the contents of a consultant's desktop have been in a personal iCloud account for two years. There is no alert for that. There is no log you can pull. There is a discovery, usually during offboarding, usually by accident.

The second half is about the baseline surviving. Disabling the Startup Disk pane stops a user booting to another volume; disabling the Apple ID pane stops them attaching a personal account after enrolment; disabling Time Machine stops company data being backed up to an unencrypted drive in a desk. Each one on its own is small. Together they are the difference between a configuration you set and a configuration that stays set.

And the ordinary consumer noise goes away: Game Center, personalised advertising, Apple's various sharing features. Nobody misses them on a work laptop, and every one of them is a surface you no longer have to think about. ๐Ÿ™‚

๐Ÿ› ๏ธ Configurationโ€‹

Where: Intune admin center โ†’ Devices โ†’ Configuration โ†’ Create โ†’ macOS โ†’ Settings catalog โ†’ System Preferences and Restrictions.

Disabled System Settings panesโ€‹

Set Disabled Preference Panes to this list:

com.apple.AirDrop-Handoff-Settings.extension
com.apple.Family-Settings.extension
com.apple.Game-Center-Settings.extension
com.apple.Siri-Settings.extension
com.apple.Startup-Disk-Settings.extension
com.apple.Time-Machine-Settings.extension
com.apple.WalletSettingsExtension
com.apple.systempreferences.AppleIDSettings

Restrictionsโ€‹

Grouped by what they actually protect. All values are False unless noted.

GroupSettings
iCloud dataCloud Address Book, Cloud Bookmarks, Cloud Calendar, Cloud Desktop And Documents, Cloud Document Sync, Cloud Freeform, Cloud Keychain Sync, Cloud Mail, Cloud Notes, Cloud Photo Library, Cloud Reminders, Cloud Private Relay
Sharing and continuityAirDrop, Activity Continuation, Auto Unlock, Password Sharing, Password Proximity Requests, iTunes File Sharing, Air Play Incoming Requests (Disabled)
Device changesAccount Modification, Local User Creation, Device Name Modification, Startup Disk Modification, Erase Content And Settings
Service modificationBluetooth Sharing Modification, File Sharing Modification, Internet Sharing Modification, Printer Sharing Modification
Find MyFind My Device, Find My Friends
Consumer noiseGame Center, Adding Game Center Friends, Multiplayer Gaming, Apple Personalized Advertising, Assistant (Siri)
SafariSafari Allow Autofill
Assignment, includeAll devices, macOS filter

Allow Local User Creation and Allow Account Modification both go to False. These are the two that keep the machine's account list matching what you think it is. Without them a user adds a second local account, and now there is a login on company hardware that appears in no directory you manage. On macOS, where the primary user is usually a local administrator anyway, MDM-enforced restrictions like these are one of the few things that genuinely hold.

Cloud Desktop And Documents is the one that matters most. It is the single setting standing between a work Mac and every file on the desktop living in a personal iCloud account. If you deploy nothing else from this profile, deploy that.

Siri is the setting users will notice. Blocking Assistant is a defensible data-boundary decision, since dictation and requests leave the device. It is also the change most likely to generate a complaint, and allowing it is a reasonable position for a customer who cares more about the experience than the telemetry. Decide it deliberately rather than inheriting it.

Caveats โš ๏ธโ€‹

Find My is a real trade-off, not a formality. Blocking it stops a personal Apple ID tracking a company asset, and it also removes the feature people reach for when a laptop goes missing. On a properly managed estate that is the right call, because device recovery should run through Intune and Apple Business Manager rather than through somebody's personal iPhone. Be able to explain that when it comes up, because it will.

AirDrop is genuinely useful and genuinely a data path. It is also the fastest way for a file to leave a managed Mac onto an unmanaged phone with no trace. Blocked here. Expect one conversation about it per customer.

Time Machine off does not mean no backup. It means no backup to a drive you do not control. Company data belongs in OneDrive or SharePoint, which is where the rest of the baseline puts it. Make sure that is actually true before removing the alternative.

Applies to the whole Mac, including the primary user. Unlike Windows, where user-scope and device-scope settings can be aimed at different populations, these restrictions land on the device. There is no "everyone except the director" without a second profile and a second group.

Test against the customer's actual workflow. This profile touches more surfaces than any other in the macOS set. A design agency that lives in AirDrop and a bookkeeping firm that has never used it deserve different conversations, and the discovery should happen in a pilot rather than on rollout day.

Clean-revert. Remove the profile and every restriction lifts with it, because macOS carries the payload with the profile. No inverse policies anywhere in the macOS baseline.

๐Ÿ‘ฅ Assignment scopeโ€‹

Baseline for every managed Mac, assigned to all devices with a macOS platform filter.

This is the profile most likely to need a customer-specific variant rather than an exception group: a second profile with a narrower restriction set, assigned to a documented group, is cleaner than punching holes in this one. If two customers need genuinely different answers on AirDrop, that is two profiles, not one profile with an exclusion.

Worth verifying at tenant takeover: how many Macs currently have a personal Apple ID signed in, and whether iCloud Desktop and Documents is already syncing. This policy stops it continuing; it does not retrieve what already left.


A work Mac with a personal Apple ID attached has two owners. This profile settles which one is in charge. ๐Ÿ