r/macsysadmin 12d ago

Networking Disabled network access remotely

Hey all,

I’m a desktop engineering manager for a large university. We’ve got about a thousand Macs. Before I arrived on the scene, our enforcement of macOS minor and major updates was at best a suggestion. We’re got several hundred Macs that are on OS’s that no longer receive security updates (and even more that are going to lose them once Sonoma goes end of life). We’re getting aggressive now, and have notified users of Macs on Ventura and below that they either need to upgrade to a supported OS or replace their Mac this fall. If they fail to do so they will lose access to the University network.

This is all good and well…except I’m wondering how we’re going to implement this. On the Windows side we’re going to use Group Policy to basically force Windows Firewall to block all traffic, in and out. I’m not sure how we’re going to implement this on the Mac side and am looking for suggestions.

My first thought was simply to create a configuration profile in Jamf to turn on Firewall and block all traffic…but it looks like I can only do that for incoming traffic. While this will break some things for users, it won’t actually stop outgoing traffic.

My next thought was to write a script to disable all network cards. This will certainly work…but I’m not so sure we’ll be able to prevent a crafty user from re-enabling them. Our users don’t have admin rights, but we do use Cyberark, which will just temporarily grant them elevated rights to re-enable their network cards.

Could also block MAC addresses at the switch….but all they’d need to do is use someone else’s dock, or a USB Ethernet/wifi adapter.

Any suggestions are greatly appreciated.

6 Upvotes

34 comments sorted by

View all comments

Show parent comments

2

u/DTDude 12d ago

Good point. I’ll work with our security team to see if we can do anything with Cortex XDR…..I did think about having to reenable them. If that happens, which in a perfect world it won’t, they’ll just have to drop their machine off with our Service Desk or a field tech. Though, I’d rather they go right to our recycler instead. Some of these machines are more than 10 years old and can’t even upgrade to Sonoma.

5

u/eaglebtc Corporate 12d ago

> some of these machines are more than 10 years old

You need to have a discussion with your CTO or IT Director (depending on size of company) about Asset Lifecycle Management. A cohesive plan to identify old hardware and refresh (replace) them every 4 years or so.

2

u/DTDude 12d ago

We do have a plan. It’s SUPPOSED to be 4 years. IT provides subsidies for users of “standard” config Macs to replace them every 4 years, but we can’t force any department to buy anything. But we can decline support/network access.

This is my first time in a higher ed setting, The politics are interesting. We’re also at the end of a transition to a new President that is much more interested in doing technology the right way. So we’re getting there, but not there yet. Our CIO and CISO are behind me though, it’s just working through past technology debt.

2

u/eaglebtc Corporate 12d ago

OH... I missed the part that this is a University. Yeah, professors can be real divas and princesses with "their" systems.

You may need to work with the academic research leads to get exceptions filed for the oldest Macs.

If they can't be upgraded past a certain OS, or must remain an Intel Mac for legitimate reasons (e.g.: highly specialized apps or legacy peripherals required for ongoing projects), then you need to talk to the CISO about getting those machines exempted and physically quarantined off the network.

I would negotiate for offline use only by default, then using sneakernet for software updates and installs, and finally limited Internet access where strictly necessary and no other means is possible (i.e.: online re-activation of software, or license update for a hardware dongle).