os_gatekeeper_enable - Sonoma - Misconfiguration #141

Closed
opened 2026-01-19 18:29:22 +00:00 by michael · 2 comments
Owner

Originally created by @ryan-baier-nih on GitHub.

The Sonoma rule for os_gatekeeper_enable has the mobileconfig: value as true. This should be false since this rule is audited and remediated within the script and not a configuration profile.

Originally created by @ryan-baier-nih on GitHub. The Sonoma rule for os_gatekeeper_enable has the mobileconfig: value as true. This should be false since this rule is audited and remediated within the script and not a configuration profile.
Author
Owner

@ryan-baier-nih commented on GitHub:

Perfect. Thank you for the explanation.

@ryan-baier-nih commented on GitHub: Perfect. Thank you for the explanation.
Author
Owner

@robertgendler commented on GitHub:

This is actually on purpose.

When you set it with profile it locks the GUI but the command line can override it. So we decided the configuration profile is important but reading the status of the profile doesn't return the actual status of gatekeeper.

@robertgendler commented on GitHub: This is actually on purpose. When you set it with profile it locks the GUI but the command line can override it. So we decided the configuration profile is important but reading the status of the profile doesn't return the actual status of gatekeeper.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: usnistgov/macos_security#141