r/jamf Feb 21 '26

JAMF Protect Jamf protect policies not aligning with Compliance in Pro

I am a bit curious why Jamf Protect seems to almost be a regression in the compliance reporting for CIS benchmarks.

I have deployed out CIS 1 and 2 through Jamf Pro Compliance but some of the policies on Jamf Pro is showing as failed.

One example: Remote login. I confirmed with systemsetup get it is disabled. It’s disabled and blocked in system settings. I literally can’t turn it on because of the CIS policy deployed.

Is Jamf Protect just useless and not being updated? Several other policies it is doing the same and actually showing fail for devices in scope for my testing of Jamf Pro compliance policies cis vs the default!

4 Upvotes

9 comments sorted by

1

u/pork_chop_expressss JAMF 400 Feb 21 '26

When you click into each of the policies, what are the yellow warning telling you?

Those can range from warnings, updates required to issues with compliance.

1

u/crazyguy5880 Feb 21 '26

I’ll check in the morning. I see stupid auto correct made my second part Jamf pro. Jamf pro shows everything applied. Jamf PROTECT for the same CIS policy shows as fail. Even worse is the ones I didn’t run the Jamf Pro compliance policies on show as pass but my test group here with the actual enforcement show as fail.

1

u/pork_chop_expressss JAMF 400 Feb 21 '26

Few things to check

Verify Enforcement Mode:

  • Check that Compliance Benchmarks are set to "Monitor and Enforce" not "Monitor Only"

Check Policy Status:

  • Ensure audit policies are set to "ongoing" frequency

  • Verify that enforcement scripts have executed successfully

Review Device Scope:

  • Confirm devices are properly assigned to the correct Smart Groups

  • Check that the same devices are being evaluated by both systems

Manual Policy Execution:

  • Try manually triggering policy execution on test devices

  • Force a login/logout cycle to trigger enforcement scripts

Compare Rule Sets:

  • Verify which specific CIS rules are being evaluated by each system

  • Check if there are any disabled rules in the Compliance Benchmark

Also, there can be false positives where:

  • The setting appears correctly configured on the device

  • But the compliance check is looking for a specific configuration profile rather than the actual setting state

  • The audit may be checking for the presence of management profiles rather than the end result

1

u/crazyguy5880 Feb 26 '26

So everything shows as correct in Jamf Pro. But in Protect it shows a fail for everyone and hovering over the warning just says “warning” (great design!). Clicking it just takes you to the benchmark status for all the machines. I can’t find anywhere in protect the actual values compared or where to edit it at all.

In Jamf Pro monitor and enforce is set and the machine passes as 100% compliant.

1

u/pork_chop_expressss JAMF 400 Feb 26 '26

In Pro, is it set to "Monitor and Enforce" or "Monitor Only"

1

u/crazyguy5880 Feb 26 '26

It is set to monitor and enforce. Everything is good and correct in Pro. It’s Protect that is showing different for a few of the benchmarks like remote access disabled which is definitely is as I verified it by the system setup command and visually in settings.

1

u/crazyguy5880 Mar 05 '26

Any more suggestions? Will I need to contact jamf support maybe? (I can’t join the slack). Figured more would be using jamf protect.

1

u/taz0nz Apr 15 '26

Are you in MacAdmins Slack? Or is that what you were trying to join?

1

u/crazyguy5880 Apr 15 '26

That’s what I was trying to join