Back to blog
macOSPublished on July 24, 20268 min read

macOS firewall via Intune: stealth mode, Gatekeeper

Enable the macOS application firewall, stealth mode and Gatekeeper via Intune to block incoming connections and allow only trusted, notarised applications.

macOS ships an application firewall that is often off by default, which leaves each Mac more exposed than people assume. Unlike the Windows firewall, which filters by port, the macOS one thinks in terms of applications: it decides which apps may accept incoming connections. Combined with stealth mode and Gatekeeper, it forms a hardening baseline that is simple to deploy through Intune and consistent with what you already enforce on Windows.

On a mixed fleet, leaving Macs without a firewall creates an asymmetry that is hard to justify at audit: your Windows machines are locked down, your Macs are not. Turning these three protections on centrally corrects that imbalance and delivers a uniform level of network security, whatever the platform.

Three complementary protections

  • The application firewall: blocks incoming connections to unauthorised applications.
  • Stealth mode: the Mac does not answer network probes like ping, becoming invisible on public networks.
  • Gatekeeper: only allows applications signed and notarised by Apple to run, blocking unidentified software.

None of these settings gets in the user's way day to day: legitimate App Store or signed apps keep working, while unsolicited connections and dubious software are pushed aside. Stealth mode in particular defeats the casual port scans attackers run to map a network, since the Mac simply never answers the probe.

Gatekeeper deserves special attention because it acts upstream, at the moment an application tries to run for the first time. Apple's notarisation checks that the software has been scanned and contains no known malicious component. By allowing only App Store and identified-developer apps, you shut the door on most software downloaded at random from the internet, without blocking legitimate, properly signed business tools.

Application firewall, stealth mode and Gatekeeper: a sound baseline for macOS.

Deploy through Intune

These protections are configured in a macOS configuration profile, settings catalog or template, assigned to your Apple devices. The settings are few, but locating them correctly in the console takes a little practice the first time.

  1. 1Enable the macOS application firewall.
  2. 2Enable stealth mode so the Mac does not answer network probes.
  3. 3Prevent users from turning the firewall off.
  4. 4Configure Gatekeeper to allow only App Store and identified-developer apps.
  5. 5Verify the state in the Intune reports and through a compliance policy.

The thing to watch is line-of-business apps that need to accept incoming connections, such as sharing or local-network collaboration tools. The macOS application firewall then asks for permission; you can pre-approve it in the policy to avoid prompts on the user side and the help-desk tickets that come with them.

What the firewall does not do

The macOS application firewall filters inbound traffic only: it does not restrict outbound connections. A malicious app already installed could therefore reach out without being blocked by this mechanism. That is why it works alongside Gatekeeper, which stops unidentified software from running in the first place.

Keep this limit in mind when talking to an auditor: the application firewall protects against unsolicited connections, but controlling outbound traffic falls to other controls, such as network filtering or endpoint detection and response. Being honest about the scope of each measure inspires more confidence than overstating what a single building block can do.

Common mistakes to avoid

Hardening macOS is simple, but a few pitfalls come up regularly and are worth anticipating.

  • Enabling the firewall without preventing its deactivation, letting the user turn it off in one click.
  • Forgetting stealth mode, and leaving Macs answering network probes on public Wi-Fi.
  • Loosening Gatekeeper to install an unsigned tool, then forgetting to restore the setting.
  • Believing the application firewall controls outbound traffic, and neglecting the other layers of defence.

Consistency with the rest of the fleet

Turning the firewall on across macOS as well as Windows delivers a uniform level of network protection across the fleet, which ISO 27001 and NIS2 auditors appreciate. Preventing users from disabling it turns good intent into a control that is actually enforced and verifiable, with evidence in the Intune reports.

Consistency also makes your policies easier to maintain. When the same baseline principles apply to every device, whatever its operating system, there are fewer special cases to remember and fewer gaps for an attacker to find. A Mac left as an exception is exactly the kind of overlooked asset that turns up in an incident report, so folding it into the same hardening standard as the rest of the fleet is both a security and an operational win.

An active, non-disableable firewall, provable at audit.

How AuPoint hardens macOS

Finding the right macOS setting identifiers and preventing their deactivation without breaking legitimate use takes time in the native console. AuPoint is a SaaS that makes Intune security and compliance easy, with no PowerShell. It offers a ready-made macOS hardening policy, firewall, stealth mode and Gatekeeper, with an impact preview before applying and one-click reversibility.

Frequently asked questions

Does the macOS firewall block browsing or email?

No. The application firewall filters only incoming connections to your applications. All browsing, email and outbound exchanges stay perfectly functional, since those are connections initiated by the Mac itself, not unsolicited traffic arriving from the network.

Does Gatekeeper prevent installing our in-house software?

Software signed by an identified developer or notarised by Apple installs normally. For an unsigned in-house tool, you need an exception or, better, to have it signed. The recommended setting allows the App Store and identified developers, which covers the vast majority of needs.

Does stealth mode get in the way of network troubleshooting?

Stealth mode stops the Mac from answering ping, which can surprise you during diagnostics. It is not a real obstacle: management tools and most services work normally, and invisibility to probes remains a clear security gain on public networks. If you genuinely need to ping a Mac for a test, you can temporarily adjust the policy and restore it afterwards.

Connect your Microsoft tenant to AuPoint and harden your Macs in minutes, firewall, stealth mode and Gatekeeper included, with an impact preview and one-click reversibility, no PowerShell required. Start free at aupoint.io and bring your Macs up to the same standard as the rest of your fleet.

Secure your tenant in 15 minutes

Free trial