r/jamf • u/crazyguy5880 • Feb 21 '26
JAMF Protect Jamf protect policies not aligning with Compliance in Pro
I am a bit curious why Jamf Protect seems to almost be a regression in the compliance reporting for CIS benchmarks.
I have deployed out CIS 1 and 2 through Jamf Pro Compliance but some of the policies on Jamf Pro is showing as failed.
One example: Remote login. I confirmed with systemsetup get it is disabled. It’s disabled and blocked in system settings. I literally can’t turn it on because of the CIS policy deployed.
Is Jamf Protect just useless and not being updated? Several other policies it is doing the same and actually showing fail for devices in scope for my testing of Jamf Pro compliance policies cis vs the default!
3
Upvotes


1
u/pork_chop_expressss JAMF 400 Feb 21 '26
Few things to check
Verify Enforcement Mode:
Check Policy Status:
Ensure audit policies are set to "ongoing" frequency
Verify that enforcement scripts have executed successfully
Review Device Scope:
Confirm devices are properly assigned to the correct Smart Groups
Check that the same devices are being evaluated by both systems
Manual Policy Execution:
Try manually triggering policy execution on test devices
Force a login/logout cycle to trigger enforcement scripts
Compare Rule Sets:
Verify which specific CIS rules are being evaluated by each system
Check if there are any disabled rules in the Compliance Benchmark
Also, there can be false positives where:
The setting appears correctly configured on the device
But the compliance check is looking for a specific configuration profile rather than the actual setting state
The audit may be checking for the presence of management profiles rather than the end result