Category Filter
 
 

Last updated: August 14, 2026

Firewall

This page explains how to configure the macOS Firewall profile using Mobile Device Manager Plus to protect corporate Mac devices from unauthorized network traffic and cyber threats. It covers key firewall settings including enabling or disabling incoming connections, activating Stealth Mode, and managing access for signed apps, built-in apps, allowed apps, and blocked apps. The page also clarifies how conflicting firewall profiles are resolved and how administrators can optionally delegate certain firewall controls to end users.

Protect your organization's Macs from unwanted sources and traffic, by setting up a firewall using MDM. This creates a virtual barrier to prevent cyber criminals and hackers from discovering the devices, and sending harmful network requests. You can choose to selectively or completely block out untrusted connections from reaching Macs. This safeguards your corporate macOS devices from malware attacks and various cyber threats.

Profile Description

Profile SpecificationDescription
FirewallChoose to Enable or Disable a firewall for macOS devices. Select Enable to ensure that your corporate devices are safe within the internal network. Any external traffic cannot reach the Mac.
Incoming connectionsChoose to Enable or Disable all connections that are sent to the Mac.
Stealth ModeEnable Stealth Mode to hide the Mac from unsecure or public networks. When the device is in Stealth Mode, it cannot respond to network requests that could pose as a threat.
Signed AppsAllow or Restrict apps signed by Apple from receiving any network requests.(These are apps that have been evaluated and signed by Apple).
Built-in appsCertain apps are available on Macs by default. Allow or Restrict connections and network traffic to these Built-in apps.
Allowed appsYou can choose to allow apps which your organization considers critical to receive incoming connections. Choose apps from the dropdown. For apps that are not available on the App Repository, click on the Add App button and add the required app(s).
Blocked appsYou can choose to block certain apps from receiving incoming network connections. Choose apps from the dropdown provided.
  1. Suppose multiple profiles with Firewall payloads are configured and distributed to devices, Mobile Device Manager Plus will consider the Firewall payload which has the most restrictive set of configurations. (The most stringent firewall policy will be applied.)
  2. You can choose the User Controlled option, to permit users to either enable or disable the following firewall settings: Incoming connections, Stealth Mode, Built-in apps, Signed apps.

Frequently Asked Questions

What happens if multiple Firewall profiles are distributed to the same device?

If multiple profiles with Firewall payloads are configured and distributed to devices, Mobile Device Manager Plus applies the Firewall payload with the most restrictive set of configurations.

Can end users control any Firewall settings themselves?

Yes. You can choose the User Controlled option to permit users to enable or disable Incoming connections, Stealth Mode, Built-in apps, and Signed apps.

What does enabling Stealth Mode do?

Stealth Mode hides the Mac from unsecure or public networks. While in Stealth Mode, the device does not respond to network requests that could pose a threat.

Jump To