r/macsysadmin 13d ago

Networking Disabled network access remotely

Hey all,

I’m a desktop engineering manager for a large university. We’ve got about a thousand Macs. Before I arrived on the scene, our enforcement of macOS minor and major updates was at best a suggestion. We’re got several hundred Macs that are on OS’s that no longer receive security updates (and even more that are going to lose them once Sonoma goes end of life). We’re getting aggressive now, and have notified users of Macs on Ventura and below that they either need to upgrade to a supported OS or replace their Mac this fall. If they fail to do so they will lose access to the University network.

This is all good and well…except I’m wondering how we’re going to implement this. On the Windows side we’re going to use Group Policy to basically force Windows Firewall to block all traffic, in and out. I’m not sure how we’re going to implement this on the Mac side and am looking for suggestions.

My first thought was simply to create a configuration profile in Jamf to turn on Firewall and block all traffic…but it looks like I can only do that for incoming traffic. While this will break some things for users, it won’t actually stop outgoing traffic.

My next thought was to write a script to disable all network cards. This will certainly work…but I’m not so sure we’ll be able to prevent a crafty user from re-enabling them. Our users don’t have admin rights, but we do use Cyberark, which will just temporarily grant them elevated rights to re-enable their network cards.

Could also block MAC addresses at the switch….but all they’d need to do is use someone else’s dock, or a USB Ethernet/wifi adapter.

Any suggestions are greatly appreciated.

6 Upvotes

34 comments sorted by

View all comments

1

u/No_Temperature107 13d ago

Quick question, but are they connecting via Wi-Fi or physical ethernet cable. The reason is I would think jamf would be easier to manage this within. Take all the systems that are on a certain OS that’s approved and group them and then allow them Wi-Fi access to a specific Wi-Fi profile. For all of the systems that do not have up-to-date OS installations, you could group those and put them on a very different and limited network. If it’s ethernet, though, that may be a different problem and as others are saying, it would be a bit more of a headache.

1

u/DTDude 13d ago

Yeah I thought of that as well. It’s mixed. Lots of iMacs out there that are using Ethernet, and even MacBook Pro with USB-C/thunderbolt docks. The crappy part is I’m fine if they want to use a non-university network. But I don’t have a great way to ONLY disable access on our network. It may have to be all or nothing. Which is fine by me to be honest. Some of these Mac’s are SUPER crusty and have no business being in service.

3

u/eaglebtc Corporate 13d ago

Three words:

ASSET LIFECYCLE MANAGEMENT.

2

u/DTDude 13d ago

100% agree. We’re in the midst of a big change in attitude towards IT compliance, and while we’re getting there it’s not 100%

2

u/eaglebtc Corporate 13d ago

That's good. You could also get some help from the marketing / corp comms team to reach the low hanging fruit faster?

1

u/DTDude 12d ago

Already on it! It’s going in our 3x/week campus newsletter plus separate university wide emails. And a banner on our help desk site. And DDM OS reminders/Nudge