What is new
Addigy now applies 42 macOS security rules with Declarative Device Management. Declarative Device Management is Apple's newer way to manage a Mac. The Mac holds the setting itself and keeps it in place, instead of waiting for a configuration profile to arrive.
Three of these rules test a Mac by reading the setting that the declaration writes. They are Disable Siri, Disable Siri AI and Disable Dictation. Each one requires your MDM to manage that setting, so a configuration profile on its own does not make the rule pass.
You do not have to rebuild your benchmarks. The rules keep their names and their place in each benchmark, and no rule loses its remediation. Some rules do change compliance status, because this release corrects faults that made them report the wrong result. The next section lists them.
Rules that now use Declarative Device Management
Apple Intelligence:
Disable Apple Intelligence Image Playground
Disable Apple Intelligence Mail Smart Replies
Disable Apple Intelligence Mail Summary
Disable Apple Intelligence Natural Language Editing in Calendar and Reminders
Disable Apple Intelligence Notes Transcription
Disable Apple Intelligence Notes Transcription Summary
Disable Apple Intelligence Safari Reader Summary
Disable Apple Intelligence Visual Intelligence
Disable Apple Intelligence Writing Tools
Disable Genmoji AI Creation
Enforce On Device Dictation
SSH access:
Configure SSHD All Inactive Channel Timeout to 900
Configure SSHD ClientAliveCountMax to 0
Configure SSHD ClientAliveInterval to 900
Configure SSHD PerSourcePenalties
Configure SSHD Unused Connection Timeout to 900
Disable Password Authentication for SSH
Disable Root Login for SSH
Enforce SSH to Display Policy Banner
Limit SSHD to FIPS Compliant Connections
Set Login Grace Time to 30
Password policy:
Limit Consecutive Failed Login Attempts
Prohibit Password Reuse for a Minimum Number of Generations
Prohibit Repeating, Ascending, and Descending Character Sequences
Require Passwords Contain a Minimum of One Numeric Character
Require Passwords Contain a Minimum of One Special Character
Require Passwords to Match the Defined Custom Regular Expression
Require a Minimum Password Length
Restrict Maximum Password Lifetime
Set Account Lockout Time
Software updates:
Disable rollback of Background Security Improvements
Enforce Background Security Improvements are Automatically Installed
Enforce Critical Security Updates to be Installed
Enforce Software Update Downloads Updates Automatically
Enforce macOS Updates are Automatically Installed
External intelligence:
Disable External Intelligence Integration Sign In
Disable External Intelligence Integrations
Siri:
Disable Siri
Disable Siri AI
Other:
Access to External Storage Must Be Defined
Disable Dictation
Disable FaceTime.app
Each password policy rule above carries a number that comes from the benchmark, for example a minimum password length of 14 characters. The number differs between benchmarks.
Corrections in this release
This release corrects nine rules that reported the wrong result or did not enforce their setting. Most of these faults sit in the declaration path that this release introduces, so the current benchmark version does not show them.
Rule | What was wrong |
|---|---|
Disable Password Authentication for SSH | The rule tests two SSH settings but declared only one, so it could never pass. |
Limit SSHD to FIPS Compliant Connections | The rule declared the algorithm list for an older macOS version, so four of its seven settings could never match. |
Disable Root Login for SSH | The declared value was not valid SSH configuration syntax. macOS rejects the whole file at the first bad line, so no SSH rule in the benchmark took effect. |
Configure SSHD All Inactive Channel Timeout to 900 | The declared value was not valid SSH configuration syntax, with the same effect as the rule above. |
Configure Gatekeeper to Disallow End User Override | The rule passed only when the override was allowed, which is the opposite of what it enforces. |
Enforce Background Security Improvements are Automatically Installed | The rule turned the setting on and then expected it to be off. |
Require Passwords to Match the Defined Custom Regular Expression | macOS rejected the whole password policy because one value had the wrong format, so no password rule in the benchmark applied. |
Set Account Lockout Time | The rule changed a different password setting than the one it reported on. |
Access to External Storage Must Be Defined | The Mac reported the setting as applied and enforced nothing, because the value sat at the wrong level. |
What you must do
Test the rules in this release on a small group of Macs before you apply them widely. A Mac now applies these settings through a different part of macOS, even when the value stays the same.
Give the SSH rules and the password policy rules the most attention. If a value is wrong in either group, you can lose remote access to a Mac or lock a user out of it.
If you use SSH to reach your Macs, set up key-based access first. Disable Password Authentication for SSH removes password login once it applies.
Known limits
This release covers the macOS 27 benchmarks. Benchmarks for earlier macOS versions do not change.