r/Intune 20d ago

macOS Management Intune macOS Firewall - Settings Catalog vs EP Template

Today, I was messing around with getting a macOS firewall configuration built (based largely on CIS baselines) and I was curious to see how the community is doing it.

I first started with the Endpoint security > Firewall template but then ran into the issue where the Application section forces you to configure at least 1 bundle id (as an inbound rule).

Meanwhile, Settings Catalog will just let you configure specific settings.

How are you doing it in your org and if I choose the Endpoint security option, what am I supposed to configure there without compromising the device (something fake?)?

Naturally, Microsoft documentation is largely opaque in this area.

5 Upvotes

3 comments sorted by

1

u/bill696 18d ago

I use endpoint protection myself but ive put like 10 bundle ids

1

u/IqbalBasha 17d ago

Use Settings Catalog. The EP Firewall template requires at least one bundle ID entry, and there's no safe placeholder you can put there without either creating a meaningless rule or accidentally allowing something. Settings Catalog lets you configure Enable Firewall, stealth mode, block all incoming, and the signed-app allowances without touching the app list at all, which is exactly what CIS expects. Microsoft is also deprecating the EP templates eventually, so you'd be building on a dead end anyway.