macOS Intelligent Hub can monitor system events to help administrators block specific software from running on a managed device. While security tools should still be used for malware, viruses, or other malicious software, this functionality helps with basic restrictions such as games, CLI tools, messaging apps, or even OS update installers.
Note
After upgrading to Intelligent Hub for macOS version 24.11, replace any existing custom profile to retrict application access, if applicable. Refer to the KB article for details.
Prerequisites
- The enrolled device is running Omnissa Workspace ONE UEM 2410.
- Omnissa Workspace ONE Intelligent Hub 24.11 or later is installed.
Create an Advanced Security Controls Profile
You can use advanced security controls payload to customize settings to prevent specified apps and processes from being launched.
To create a Advanced Security Controls profile, perform the following steps:
- In the UEM Console, navigate to Resources > Profiles and Baselines > Profiles > Add a Profile > macOS .
- Click Device Profiles, and select Advanced Security Controls.

-
To define app or process settings, configure the following including:
Settings Description BundleIDs Any bundle identifiers related to the app or executable that should not be launched. Names The names of any app bundles or processes that should not be launched. Paths The path to any binaries that should not be launched. CDHash Values The CDHash values of any items that should not be launched. SHA 256Hash values If enabled, displays a message when blocked. Display message dialogue when blocked If enabled, displays a message dialogue. Message Customize a message to display to the user if the process is blocked -
Click the summary for the configured values and click Next. Select Save and Publish.
War diese Seite hilfreich?