Mac firewall guides
Deploy Outbound with MDM
Deploy Outbound’s system-extension and content-filter profiles before the app requests activation. Use a pilot Mac and user-approved device-channel MDM enrollment.
Updated
Step by step
- Prepare the sample profiles. Download the system-extension, content-filter and managed-preferences profiles from the IT page. Verify bundle identifiers and signing team against the intended build.
- Install the system-extension policy. Send the system-extension policy first. Review the macOS 15-or-later non-removable restriction and your emergency removal procedure.
- Install the content-filter profile. Send the content-filter configuration next. It identifies the app and data-provider extension and enables socket filtering.
- Apply managed preferences. Set the mode, editing policy, optional HTTPS feed and export path. Sign profiles using your organization’s normal process and verify installation on the pilot.
- Install and open the app. Once a signed release is available, install Outbound.app into Applications and open it so it requests activation. Check outboundctl status and test controlled allow and deny rules before expanding deployment.
Enrollment and release limits
Apple’s system-extension MDM documentation describes device management for system extensions. User Enrollment is not sufficient for these samples. Outbound’s fleet compatibility results are not yet published.
Profiles to download
The feed and audit export keys need your own values. Do not deploy example domains as real infrastructure.
Verification before a wider rollout
Test the VPN, authentication, software updates and endpoint filters used by your organization. Confirm that a failed feed download preserves the previous rules and that your recovery policy can remove the filter. A profile’s successful installation is not a traffic compatibility test.
Outbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.