Mac firewall guides

Deploy Outbound with MDM

Deploy Outbound’s system-extension and content-filter profiles before the app requests activation. Use a pilot Mac and user-approved device-channel MDM enrollment.

Updated

Step by step

  1. Prepare the sample profiles. Download the system-extension, content-filter and managed-preferences profiles from the IT page. Verify bundle identifiers and signing team against the intended build.
  2. Install the system-extension policy. Send the system-extension policy first. Review the macOS 15-or-later non-removable restriction and your emergency removal procedure.
  3. Install the content-filter profile. Send the content-filter configuration next. It identifies the app and data-provider extension and enables socket filtering.
  4. Apply managed preferences. Set the mode, editing policy, optional HTTPS feed and export path. Sign profiles using your organization’s normal process and verify installation on the pilot.
  5. Install and open the app. Once a signed release is available, install Outbound.app into Applications and open it so it requests activation. Check outboundctl status and test controlled allow and deny rules before expanding deployment.

Enrollment and release limits

Apple’s system-extension MDM documentation describes device management for system extensions. User Enrollment is not sufficient for these samples. Outbound’s fleet compatibility results are not yet published.

Profiles to download

The feed and audit export keys need your own values. Do not deploy example domains as real infrastructure.

Verification before a wider rollout

Test the VPN, authentication, software updates and endpoint filters used by your organization. Confirm that a failed feed download preserves the previous rules and that your recovery policy can remove the filter. A profile’s successful installation is not a traffic compatibility test.

Outbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.