Laptop firewall basics for company devices: enable OS firewalls on all profiles via MDM
Laptop firewall configuration is a foundational endpoint control that many teams assume is "on by default"—until an MDM inventory or SecureSlate Asset Management scan shows otherwise. Public Wi-Fi, home networks, and travel hotspots all sit outside your corporate perimeter; the host firewall is often the last line of defense on a roaming device.
This guide covers:
- Why OS firewalls matter for company laptops and compliance programs
- What "enabled on all profiles" means in practice
- Platform-specific settings for macOS, Windows, and Linux
- How to enforce firewall policy through MDM
- How SecureSlate validates Firewall as part of your X/5 endpoint score

GIF via GIPHY
Related guides:
- MDM compliance guide
- BYOD policy
- Screen lock policy best practices via MDM
- Pass 5/5 endpoint security checks in SecureSlate
- MDM vs manual screenshots for audit evidence
- Device enrollment checklist for remote teams
Key takeaways
- OS firewall must be enabled on all network profiles—domain, private, and public—not only the corporate network.
- MDM enforcement prevents user disable and gives auditors configuration proof, not verbal assurance.
- SecureSlate Asset Management tracks Firewall as one of five endpoint checks (X/5).
- Firewall pairs with encryption, antivirus, password policy, and screen lock for a complete endpoint baseline.
- Continuous monitoring beats pre-audit screenshot collection for Type II operating effectiveness.
Why laptop firewalls matter
Corporate network security—VPNs, zero trust, SSE—protects traffic in transit to your applications. It does not stop a malicious process on the laptop itself from listening on an open port or accepting inbound connections on a coffee-shop network.
Auditors sampling CC6/CC7 (SOC 2) or Annex A network controls commonly ask: Is the host firewall enabled on employee devices? Teams without MDM often discover that developers disabled firewalls for local testing, or that Windows public profile defaults were never hardened after a OS upgrade.
What good looks like
| Control | Target state | Common audit question |
|---|---|---|
| Firewall enabled | On for all active network profiles | Show me configuration for domain, private, and public |
| Stealth / block inbound | Default deny inbound; allow required apps | What exceptions exist and who approved them? |
| User cannot disable | Enforced via MDM; local override blocked | How do you detect drift? |
| New enrollments | Firewall on before device is productive | What is day-one baseline for remote hires? |
| Evidence cadence | Continuous sync to GRC platform | Point-in-time or full observation period? |
SecureSlate passes the Firewall check when the OS firewall is enabled on all profiles. Anything less counts against your X/5 endpoint score.
Platform-specific basics
macOS
- Application Firewall (System Settings → Network → Firewall) should be On.
- MDM uses the Firewall payload to enforce enablement and manage allowed apps.
- Verify both built-in firewall and that third-party security tools have not replaced it without documentation.
Windows
- Windows Defender Firewall must be enabled for Domain, Private, and Public profiles.
- Group Policy or MDM CSP (
./Device/Vendor/MSFT/Firewall/...) sets profile defaults. - Public profile is the most commonly disabled after troubleshooting—re-check after major updates.
Linux (managed endpoints)
- Depends on distribution:
ufw,firewalld, or equivalent. - MDM or configuration management (Ansible, Puppet) should enforce
enabledstate and document allowed ports.
| OS | Firewall service | MDM payload / policy |
|---|---|---|
| macOS | Application Firewall | Firewall payload |
| Windows | Windows Defender Firewall | Firewall CSP / GPO |
| Linux | ufw / firewalld | Custom profile or CM tool |
MDM enforcement workflow
- Define baseline — Firewall on, all profiles, documented exceptions for dev tools if required.
- Create MDM profile — Separate profiles per OS; test on pilot devices including public-network scenario.
- Block local disable — Restrict settings pane changes where platform supports it.
- Enroll fleet — Use the device enrollment checklist for remote onboarding.
- Monitor in SecureSlate — Firewall check should show pass; investigate any device below 5/5.
- Remediate and retest — Re-push profile or open ticket; confirm pass on next sync.
Pair firewall enforcement with screen lock policy and full 5/5 endpoint guidance for audit-ready coverage.
How SecureSlate checks Firewall
SecureSlate Asset Management evaluates five endpoint security checks:
| Check | Pass criteria (summary) |
|---|---|
| HD Encryption | Full-disk encryption enabled |
| Anti-Virus | Approved AV running and current |
| Password Policy | Meets org complexity / length rules |
| Screen Policy | Idle lock ≤15 min; password on unlock |
| Firewall | OS firewall enabled on all profiles |
The dashboard aggregates results as X/5 per device. GRC and IT teams prioritize remediation on devices scoring below 5—before auditors or enterprise buyers request samples.
SecureSlate MDM plus Asset Management connects enforcement to evidence: configure once, enroll devices, and export compliance history for SOC 2, ISO 27001, or customer security reviews.
Evidence auditors expect
| Evidence | Source | Frequency |
|---|---|---|
| Network / endpoint security policy | Policy repository | Annual or on change |
| MDM firewall configuration | MDM export or SecureSlate sync | Continuous |
| Device sample (5–25 endpoints) | SecureSlate Asset Management | Per audit period |
| Exception approvals | Ticket / GRC system | As needed |
| Remediation records | ITSM | On failure |
For Type II audits, evidence must span the observation window—not a single export the week before fieldwork.
Common mistakes
- Only enabling domain profile — Remote workers live on private/public profiles daily
- Assuming AV suite replaces OS firewall — Confirm both are active and documented
- Developer exceptions without expiry — "Temporary" disable becomes permanent
- No monitoring after OS upgrade — Major macOS/Windows releases reset settings on some devices
- Manual checks once per year — Drift happens weekly; automate with Asset Management
Troubleshooting failed checks
| Symptom | Likely cause | Fix |
|---|---|---|
| Windows public profile off | User or app disabled after network change | Re-push MDM profile; block local edits |
| macOS firewall off | User disabled in Settings | Enforce via MDM; verify profile assignment |
| Check passes in MDM, fails in SecureSlate | Agent sync delay or enrollment gap | Re-enroll device; confirm Asset Management agent |
| Intermittent pass/fail | VPN or third-party filter conflict | Document architecture; align auditor narrative |
| Linux not reporting | Agent unsupported or CM drift | Extend MDM scope or exclude with documented compensating control |
Laptop firewall compliance with SecureSlate
SecureSlate MDM and Asset Management give you firewall enforcement, continuous X/5 monitoring, and audit-ready exports—without quarterly screenshot hunts across a distributed fleet.
Get started for free · Free readiness score
FAQ: Laptop firewall and MDM
Does SecureSlate require a third-party firewall?
No—the Firewall check validates that the OS firewall is enabled on all profiles. Third-party tools may supplement but do not replace this baseline unless your policy explicitly defines an equivalent.
What does "all profiles" mean on Windows?
Domain, Private, and Public network profiles must all have the firewall enabled. Public is critical for remote workers on home and guest Wi-Fi.
How does firewall relate to my SOC 2 network controls?
Host firewall supports logical access and boundary protection narratives for endpoint devices—especially CC6.6 and CC6.7 in SOC 2 Trust Services Criteria. Exact mapping depends on your system description.
Can developers run local servers with firewall enabled?
Yes—MDM can allow specific inbound rules for approved development tools. Document exceptions with approver and review date.
How quickly does SecureSlate detect a disabled firewall?
Detection follows your Asset Management sync cadence—typically within hours of agent check-in, not at quarterly audit time.
Should BYOD devices meet the same firewall standard?
Yes, if BYOD devices access company data. See BYOD policy for enrollment and container options.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
