Outbound for Mac
Per-app outbound control for managed Macs
Outbound gives Mac administrators managed preferences, an HTTPS rule feed and JSON Lines audit export. Teams licences are per seat, billed yearly; contact us for pricing.
Updated
Prepare a pilot before deployment
These are Outbound 1.0’s configuration samples, not evidence of a completed fleet deployment. Validate them on a pilot Mac before any rollout.
System-extension and content-filter policies require user-approved MDM enrollment on the device channel. User Enrollment is not sufficient. See Apple’s system-extension payload documentation.
Download the sample profiles
- System-extension policy: install first.
- Content-filter configuration: install second.
- Managed preferences: adapt to your organization.
- Sample rule feed: a schema-versioned example with 3 rules.
Sign profiles with your MDM’s profile-signing certificate. The samples identify app com.outboundfirewall.outbound, extension com.outboundfirewall.outbound.filter and signing team 5GS535L4GD. Recheck those identifiers against the release you deploy.
The system-extension sample includes NonRemovableSystemExtensions, a macOS 15-or-later control. Review whether that restriction fits your recovery policy before installing it.
Managed preferences
Preferences use the domain com.outboundfirewall.outbound. These policy keys take effect when forced by a configuration profile, not when merely written as ordinary user defaults.
| Key | Type | Behavior |
|---|---|---|
Mode | String | alert, silentAllow or silentDeny. |
ManagedRulesOverride | Boolean | Prioritizes managed rules when true. |
UsersMayEditRules | Boolean | Locks user rule editing when false. |
DisableAlerts | Boolean | Resolves ask decisions with the mode default without an alert. |
RuleFeedURL | String | HTTPS URL for the managed rule feed. |
RuleFeedPinnedSHA256 | String | Optional 64-digit hexadecimal SHA-256 of the exact feed bytes. |
AuditExportPath | String | Destination directory for complete audit-log lines. |
Deliver rules over HTTPS
The managed feed is fetched at launch and every 6 hours. It accepts at most 50,000 rules. A failed fetch, invalid schema or mismatched pin leaves the previous managed rules in place. Invalid pin values are errors, not an instruction to disable pinning.
shasum -a 256 rule-feed.json
outboundctl feed check rule-feed.jsonAdd RuleFeedURL and RuleFeedPinnedSHA256 inside the sample’s forced mcx_preference_settings dictionary. The feed and export keys are not prefilled in the sample. Use your real HTTPS endpoint and computed digest.
Managed rules are replaced together; user and blocklist rules remain. An empty feed removes managed rules. Removing the feed preference also removes its managed rules. Plan those changes deliberately.
Send audit logs to your collector
Outbound writes one JSON Lines file per UTC day and retains 30 days locally. A forced AuditExportPath copies complete lines to the chosen directory, at most once a minute. The app user needs write permission there; the collector needs read permission.
outboundctl audit export --to /path/to/audit-exportThe path above is illustrative. Create and secure your actual export directory before running the command. The app does not send logs directly to a SIEM API. Your collector forwards the files and applies your retention policy.
Deployment steps · Audit export guide · CLI reference
Plan your recovery
In Ask mode, an unanswered connection is allowed after 8 seconds for UDP or 60 seconds for TCP by default, then added to Review. You can change the wait (15–120 seconds for TCP) or have unanswered connections blocked. With alerts disabled, the mode default applies without a prompt. Use and test Strict mode if unknown traffic must be blocked.
Keep an MDM path for removing the filter policy. Do not claim compatibility with your endpoint security stack until your own pilot has passed. See published test status.