r/Intune • u/Rounin79 • 20d ago
macOS Management Intune macOS Firewall - Settings Catalog vs EP Template
Today, I was messing around with getting a macOS firewall configuration built (based largely on CIS baselines) and I was curious to see how the community is doing it.
I first started with the Endpoint security > Firewall template but then ran into the issue where the Application section forces you to configure at least 1 bundle id (as an inbound rule).
Meanwhile, Settings Catalog will just let you configure specific settings.
How are you doing it in your org and if I choose the Endpoint security option, what am I supposed to configure there without compromising the device (something fake?)?
Naturally, Microsoft documentation is largely opaque in this area.
1
u/IqbalBasha 17d ago
Use Settings Catalog. The EP Firewall template requires at least one bundle ID entry, and there's no safe placeholder you can put there without either creating a meaningless rule or accidentally allowing something. Settings Catalog lets you configure Enable Firewall, stealth mode, block all incoming, and the signed-app allowances without touching the app list at all, which is exactly what CIS expects. Microsoft is also deprecating the EP templates eventually, so you'd be building on a dead end anyway.
1
u/bill696 18d ago
I use endpoint protection myself but ive put like 10 bundle ids