# Stabilise - Full Content Corpus > Apple-specialist Managed Service Provider in London. We design, run, and secure Apple-first IT environments for creative agencies, film and TV production, architecture practices, and growth-stage startups across the UK. Cyber Essentials Plus certified, an Apple Premium Technical Partner, and not Apple-exclusive: Windows and cloud platforms are supported where they're part of the fleet. For the curated index, see https://stabilise.io/llms.txt. ## Company Stabilise Ltd is a London-based Apple-specialist Managed Service Provider founded in 2025 by Dustin Rhodes and Alan Avins, combining over three decades of enterprise Apple expertise. Legal entity: Stabilise Ltd Address: 6-7 St Cross Street, London, EC1N 8UB Phone: +44 203 355 7522 Email: hello@stabilise.io LinkedIn: https://www.linkedin.com/company/stabilise X: https://x.com/StabiliseLDN YouTube: https://www.youtube.com/channel/UCbKS45GOup2Rr675eSRLBBQ GitHub: https://github.com/Stabilise Partner status and certifications: Apple Premium Technical Partner, Apple Certified Support Professional (ACSP), Apple Certified Macintosh Technician (ACMT), Jamf 300, ISC2, Cyber Essentials Plus. Geographic coverage: on-site across London Zones 1-3, remote UK-wide. Premium-tier urgent tickets have a 15-minute response SLA; other tiers and ticket priorities have their own response targets documented in client agreements. ## Services ### Infrastructure Architecture URL: https://stabilise.io/services/infrastructure-architecture ## Apple Infrastructure That Scales With Your Business Most IT providers treat Macs as a secondary concern. We put Apple at the centre of our infrastructure design, while making sure everything else connects properly. Every infrastructure we design starts with Apple and builds outward. From [zero-touch Mac deployment via JAMF and Apple Business Manager](/apple-business-manager-zero-touch-deployment) to fully managed iPad and iPhone fleets, we architect environments where devices arrive ready to work. Your new starter opens their MacBook and everything is already configured, from apps and permissions through to security policies and email, without IT lifting a finger. ## 99.9% Uptime Through Proactive Monitoring Downtime costs creative businesses thousands per hour, so we monitor every device, network endpoint, and cloud integration around the clock. Our proactive approach catches failing drives, expiring certificates, and configuration drift before they become outages. We maintain a 99.9% uptime record across our entire client base because we fix problems before your team even notices them. Real-time alerting, automated remediation, and quarterly infrastructure reviews keep your environment healthy and predictable. ## Complete Ecosystem Design and Cloud Integration Apple works best when every layer of your stack is designed to work together. We build unified environments that connect Mac, iPad, and iPhone with the cloud platforms your team depends on: Google Workspace, Microsoft 365, Slack, and industry-specific tools. Single sign-on via Okta or Microsoft Entra ID ties it all together with one identity across every service. The result is an infrastructure your team never has to think about and is straightforward for us to secure and manage at scale. ## Why Creative Businesses Need Specialist Infrastructure Film studios, agencies, and architecture practices push hardware harder than most enterprises. Large file transfers over shared storage, GPU-heavy rendering, colour-accurate workflows. These demands break generic IT setups. We understand Thunderbolt networking, NAS storage tuned for video editing, and the specific macOS configurations that keep Final Cut Pro, Adobe Creative Cloud, and Cinema 4D running at full speed. If your infrastructure was designed by people who really understand Apple, it shows in every interaction your team has with their tools. [Get in touch to discuss your infrastructure needs.](/contact) ### Apple IT Support London URL: https://stabilise.io/services/apple-it-support-london ## Less Than 15 Minutes to First Response on Premium Urgent Tickets When something breaks, speed matters. Premium-plan urgent tickets carry a 15-minute first-response SLA, with 30 minutes on Professional. That first response is a real Apple-certified engineer picking up your issue and starting work on it, rather than an automated acknowledgement from a ticketing system. We operate dedicated support channels for every client so your request never sits in a queue behind hundreds of others. During business hours you reach your assigned team directly. Outside hours, our on-call engineers handle critical issues so your overnight renders and early-morning deadlines are never at risk. ## Real Apple Engineers, Not Generalists Most managed service providers have engineers whose primary expertise is Windows. Mac support is an add-on, not a core skill. That approach fails the moment someone needs to troubleshoot a kernel panic on a Mac Studio, resolve an MDM enrolment conflict, or diagnose a Thunderbolt daisy-chain issue. Every engineer on our support team is Apple-certified and works exclusively with Apple environments. They know macOS inside out, from ARD and JAMF troubleshooting to FileVault recovery and Apple Silicon firmware updates. That depth of knowledge is why we resolve 95% of issues on the same day they are raised. ## Support Built Around How You Work We structure support around the way your business already works. That means Slack and Microsoft Teams integration for instant messaging, a client portal for ticket tracking and asset visibility, and scheduled check-ins with your account lead. Whether you have 10 Macs or 300, you get the same level of attention. Our tiered plans cover everything from reactive break-fix through to fully managed IT with proactive monitoring, patching, and quarterly reviews. There are no long-term lock-in contracts either. Clients stay because the service is good, and that suits everyone. ## Why Mac Support Needs Specialists A generalist IT company often applies the same approach to Macs as they do to Windows. That creates friction. You end up with workarounds instead of solutions, slow resolutions because the engineer is learning on the job, and security gaps because macOS was bolted onto a policy framework designed for Active Directory. We built the whole company to avoid that, with purpose-built tooling, Apple-native security policies, and engineers who have spent years working exclusively with Mac, iPad, and iPhone. The difference is obvious from your first support ticket. [Talk to our team about Apple IT support for your business.](/contact) ### Enterprise Security URL: https://stabilise.io/services/enterprise-security ## Zero Breaches Across Our Entire Client Base Security is the foundation of every environment we manage. We maintain a zero-breach track record because we build security into infrastructure from day one rather than layering it on afterward. Every Mac, iPad, and iPhone under our management is protected by MDM-enforced security policies, endpoint detection and response, and automated compliance checks that run continuously. Our approach blocks 99.7% of threats before they reach a user, and our incident response process handles the rest within minutes. ## Cyber Essentials Plus as Standard Every managed client meets Cyber Essentials Plus requirements as a baseline. We handle the entire certification process: vulnerability scanning, policy documentation, remediation, and audit support. So you can present the certificate to clients and procurement teams without diverting your own staff. For organisations in regulated sectors, we extend coverage to ISO 27001 alignment, GDPR technical controls, and SOC 2 readiness. Compliance should open doors for your business, not create administrative overhead. ## MDM-Enforced Policies and Endpoint Protection We use JAMF Pro and Apple Business Manager to enforce security policies at the device level. FileVault encryption is mandatory and escrowed, Gatekeeper and XProtect configurations are locked down, and OS updates go out on a tested schedule so machines stay patched without breaking anyone's workflow. On top of Apple's native protections, we deploy enterprise endpoint detection tools that monitor for behavioural anomalies, ransomware patterns, and credential theft attempts across your entire fleet. Every alert gets triaged by a person on our team before anything is dismissed. ## Security That Does Not Slow Your Team Down The worst security is the kind people work around. We design policies that protect your business without frustrating your team. Single sign-on means one strong password instead of twenty weak ones. Conditional access policies grant the right permissions based on device compliance and location, so your editors can access shared storage on-site without jumping through hoops. The goal is always the same: enterprise-grade protection that feels invisible to the people doing the work. [Speak with us about securing your Apple environment.](/contact) ### Technology Strategy URL: https://stabilise.io/services/technology-strategy ## Fractional CTO Services for Growing Businesses Hiring a full-time CTO costs upwards of six figures before you add equity and benefits. Most businesses with 20 to 200 staff do not need that level of investment. They need strategic technology leadership on a predictable schedule. Our fractional CTO service gives you a senior technology advisor who understands your business, attends your leadership meetings, and owns your technology roadmap. You get the thinking without the headcount, and you can scale the engagement up or down as your needs change. ## Quarterly Planning With an 85% Implementation Rate Strategy is worthless if it stays on a slide deck. We run quarterly technology reviews with every strategy client, setting clear priorities, timelines, and owners for each initiative. Our 85% implementation rate across all clients means the plans we write get delivered. That number exists because we tie strategy directly to execution. Our engineering team carries out the work, so there is no gap between what gets recommended and what gets built. Roadmaps cover hardware refresh cycles, software consolidation, cloud migration, security posture improvements, and budget forecasting across a rolling 12-month horizon. ## Vendor Management and Procurement Technology decisions involve dozens of vendors, each with their own licensing models, renewal cycles, and sales pressure. We act as your single point of contact for vendor evaluation, contract negotiation, and procurement. Whether you are choosing between Google Workspace and Microsoft 365, evaluating NAS solutions from Synology and QNAP, or negotiating an Apple Financial Services lease, we bring market knowledge and volume pricing that individual businesses cannot access alone. Every recommendation is vendor-neutral. We pick the best tool for your workflow, not the one that pays us the highest margin. ## Aligning Technology With Business Growth A good technology strategy removes friction from growth as well as keeping the day-to-day running. We help you plan for office moves, headcount increases, and new workflows before they become emergencies. When you win a new client that requires Cyber Essentials certification, your infrastructure is already compliant. When you hire ten people in a quarter, zero-touch deployment means they are productive on day one. Strategic planning turns IT from a cost centre into a competitive advantage, and that shift is measurable in the speed your business can move. [Book a strategy consultation with our team.](/contact) ### Projects URL: https://stabilise.io/services/projects ## Standalone Projects, No Ongoing Commitment Not every business needs a managed service contract. Sometimes you need a specific problem solved: a network rebuilt, an office fitted out, or a fleet of Macs migrated to a new MDM. Our project work runs from £1,500 for straightforward deployments up to £75,000+ for large-scale infrastructure builds. Every project gets a fixed scope, a clear timeline, and a dedicated project lead. You pay for the outcome, not for an ongoing relationship, though many of our managed clients started with a single project. ## The Projects We Deliver Most Often Our project work covers the full range of Apple infrastructure needs. Network builds and redesigns, including structured cabling, managed switches, and enterprise Wi-Fi with uninterrupted roaming. NAS and shared storage deployments tuned for creative workflows, with Synology, QNAP, and LucidLink configurations optimised for video editing and design teams. Office moves and fit-outs where every desk, meeting room, and AV system is planned, cabled, and tested before your team walks in. Mac fleet migrations from one MDM to another, or from no management to full JAMF enrolment. And Cyber Essentials Plus certification delivered end-to-end, from gap analysis through to audit and certificate. ## How Our Project Process Works Every project starts with a scoping call where we define exactly what needs to happen, what the dependencies are, and what done looks like. You receive a written proposal with line-item pricing rather than a vague estimate that firms up after the work has started. Once approved, your project lead manages delivery from start to finish, coordinating our engineers, your team, and any third-party suppliers. We document everything we build so your next IT provider, or your internal team, can pick up where we left off. Post-project, we run a handover session and remain available for 30 days of follow-up support at no extra cost. ## Built by Apple Specialists The difference between a project delivered by generalists and one delivered by Apple specialists is in the details. We know which Thunderbolt docks cause kernel panics on M-series Macs. We know how to configure 10GbE NAS storage so Premiere Pro timeline scrubbing is instant. We know the exact JAMF policies needed to pass a Cyber Essentials Plus audit without locking down machines so tightly that your designers cannot work. That depth of Apple knowledge means fewer surprises during delivery and a result that works the way your team needs it to. [Tell us about your project and get a fixed-price quote.](/contact) ### On-Site IT Support URL: https://stabilise.io/services/on-site-it-support ## Less Than 90 Minutes to Your Door in Central London Some problems cannot be fixed remotely. A failed switch, a Thunderbolt display that will not handshake, a NAS that needs physical access. These need an engineer on-site. For clients in London Zones 1 to 3, our average arrival time is under 90 minutes from the moment you raise the request. We keep engineers mobile across central and east London throughout the working day so we can respond quickly without pulling someone off another client's site. For locations further out, we schedule same-day or next-day visits depending on urgency, covering the whole of Greater London and the surrounding counties. ## When On-Site Support Makes the Difference Remote support handles the majority of IT issues efficiently, but certain situations demand hands-on work. Network infrastructure installs like running cables, configuring switches, and mounting access points need someone physically in your space. Office moves require coordinated teardown and rebuild of your entire technology environment. Hardware diagnostics on machines that will not boot, display calibration for colour-critical workflows, and AV system setup in meeting rooms all benefit from an engineer who can see and touch the equipment. We handle all of this as part of your support plan or as a standalone visit. ## 95% Same or Next-Day Handling We resolve or make meaningful progress on 95% of on-site requests within the same or next business day. That number reflects both our response speed and the depth of experience our engineers bring to every visit. They arrive with the diagnostic tools, spare cables, and replacement peripherals needed to fix most issues in a single trip. For hardware that requires Apple repair, whether under AppleCare or out of warranty, we manage the entire process including booking, data backup, and courier logistics so your team is not left chasing repair status updates. ## UK-Wide Remote Support Backing Every Visit On-site support does not operate in isolation. Every visit is backed by our remote support team who can prepare diagnostics, pull device logs, and pre-stage configurations before the engineer arrives. For clients outside London, our remote-first support model delivers the same expertise over screen share, with on-site visits arranged when remote resolution is not possible. Whether your team is in Soho or Sheffield, you get Apple-certified engineers who know your environment and can act immediately. [Arrange on-site support for your business.](/contact) ### AI & Automation URL: https://stabilise.io/services/ai-automation ## Stop Scaling With Headcount Every growing business hits the same wall. Revenue doubles but so does the admin. Your team spends hours copying data between systems, chasing approvals, updating spreadsheets, and reconciling invoices. You hire more people to handle the volume, but the inefficiency scales with them. We fix the systems, not the symptoms. Stabilise helps 50 to 100 person professional services firms in creative, legal, and finance connect their tools so their people can do the work that matters. We build automations using open, auditable tools with no vendor lock-in: n8n, Supabase, Airtable, Notion, and your existing platforms. ## Three Ways We Work **Automation Discovery (3 weeks).** A focused sprint that maps your operations, identifies the biggest time drains, and delivers one working automation. Most teams save 10 to 15 hours per week from this alone. **Department Automation (8 to 12 weeks).** Automate an entire department's repetitive work. Connect finance, operations, or client services across 2 to 4 workflows. The kind of project that turns a reactive team into a proactive one. **Enterprise Transformation (16 to 20 weeks).** Connect finance, operations, and client services into one intelligent system with a unified data platform. This is for businesses that want to scale from 5m to 15m without doubling their operations team. ## Ongoing Support Every automation we build comes with monitoring, maintenance, and optimisation. We offer monthly retainers from Essential (up to 5 automations) through Growth (up to 10) to Priority (up to 50 with dedicated support and 24/7 response). That way the system keeps improving, instead of slowly breaking down the way one-off projects tend to. ## Measurable Results From Week One We track every automation against real business metrics. Our clients typically see a 94% reduction in manual errors, 10 to 15 hours saved per team per week, and measurable ROI within 30 days. The first automation goes live in 3 weeks, which tends to surprise people who have sat through six-month software projects before. [Book an automation discovery session with our team.](/contact) ## Industries ### Film & TV Production IT Support URL: https://stabilise.io/industries/film-tv-production A day of downtime on a shoot costs more than a year of IT support. We provide Apple infrastructure built for the pace, pressure, and unpredictability of film and TV production in London. ## IT that moves at production speed **Rapid Fleet Deployment.** New series greenlit? 30 MacBook Pros configured with Final Cut, DaVinci, or Avid, enrolled in MDM, and delivered to your production office within days rather than weeks. **On-Set & Location Support.** Productions don't happen in tidy offices. We're on-site across London Zones 1-3, whether your edit suite is in Soho or your production office is in a warehouse in Hackney. **Dailies & Rushes Infrastructure.** 10GbE networks, NAS for shared editorial storage, DIT ingest pipelines. Built to handle 4K and 8K without bottlenecks. Delivery specs for Netflix, Apple TV+, and BBC all covered. **Content Security.** TPN-ready architecture, with encrypted storage, strict access controls, and endpoint protection, so your pre-release content stays protected the whole way from ingest to delivery. **Wrap & Decommission.** When the production wraps, we manage secure device recovery and data wiping. Nothing leaves the building with sensitive content on it. Certified destruction when needed. **Under 15-Minute Response.** When a render crashes at 2am or an edit suite goes down before a client screening, you need someone who understands what's at stake. Premium urgent tickets carry a 15-minute response SLA, handled by people who have worked to a production deadline before. ## Trusted by teams working with the biggest names We treat content security with the seriousness it demands. Our clients work with Marvel, Apple TV+, Disney+, Netflix, Amazon Prime Video, and the BBC. 99.9% Uptime guarantee · <15min Premium urgent response · 300+ Devices under management · Zero Content breaches ## Focus on the production. We'll handle the tech. Free infrastructure assessment. We'll audit your current setup and show you exactly where the bottlenecks are. ### Apple IT for Creative Agencies URL: https://stabilise.io/industries/creative-agencies Most MSPs treat Macs as a secondary concern, and their engineers rarely have the macOS depth creative teams need. That shows quickly when your team runs Adobe CC all day and colour accuracy is part of the deliverable, because a profile mismatch isn't cosmetic. It's a client problem. ## Mac support from people who know your tools **Creative Workflow Support.** Adobe CC, Figma, After Effects, Final Cut, DaVinci, Sketch. We work around these tools every day, so licence issues, plugin conflicts, font management, and colour profiles get diagnosed correctly on the first pass instead of after three rounds of guessing. **Fast Onboarding & Offboarding.** New designer starts Monday? Their MacBook arrives configured, enrolled, loaded with every app they need, and sitting on their desk. When someone leaves, we lock accounts, wipe devices, and revoke access within hours. **Storage for Big Files.** Creative teams generate enormous files. We deploy NAS with high-speed networking so your team pulls assets, collaborates on shared projects, and pushes deliverables without waiting. **Render Farm Management.** Motion graphics and video work needs rendering power. We manage your render infrastructure so overnight jobs finish on time, monitored and restarted if they fail. **Security Without Friction.** You handle sensitive brand assets and unreleased campaigns. We deploy endpoint protection, encrypted backups, and Cyber Essentials compliance without slowing anyone down. **Unlimited Support.** Your team can message us as often as they need to; there are no ticket limits and no call centre in the way. 95% of issues get resolved the same day. ## What happens when your MSP gets it Creative agencies switch to us because their previous provider couldn't tell the difference between a font cache issue and a kernel panic. We can. 95% Same-day resolution · <15min Premium urgent response · 99.9% Uptime guarantee · Zero Breaches ## Stop settling for IT that doesn't get your tools. Book a free audit. We'll assess your creative workflow infrastructure and show you what's holding your team back. ### Apple IT for Architecture Practices URL: https://stabilise.io/industries/architecture-practices ArchiCAD, Rhino, V-Ray, Revit through Parallels. Your software demands serious hardware, configured correctly. We spec, deploy, and manage Mac workstations optimised for the way architects work. ## Everything your practice needs to run smoothly **Workstation Optimisation.** Mac Studios, Mac Pros, MacBook Pros, specced for your software, not from a generic catalogue. RAM, storage, and GPU matched to ArchiCAD, Rhino, V-Ray, and your real project sizes. **CAD & BIM on macOS.** Revit and AutoCAD through Parallels, configured properly. Native ArchiCAD, SketchUp, Rhino, V-Ray with licence management, plugin compatibility, and performance tuning handled. **Project Storage & Collaboration.** NAS with high-speed networking so the whole practice gets fast access to shared project libraries, without the version conflicts and slow transfers that creep into ad hoc file sharing. Structured backups and off-site replication come as part of it. **Render Farm Support.** Competition deadline approaching? We manage your render infrastructure, from dedicated machines to distributed rendering across your fleet off-hours. Monitored overnight, failures caught immediately. **On-Site Support.** Plotters, large-format printing, meeting room AV for client presentations, physical network infrastructure. Things remote support can't fix. We're on-site across London Zones 1-3. **Practice-Scale Security.** Endpoint security, encrypted backups, and Cyber Essentials compliance covering your project data, client IP, and planning submissions, all without adding friction to the design workflow. ## IT support that understands architecture, not just IT Architecture sits in an awkward spot for IT. The workstation demands are heavy, the files are enormous, and half the problems involve something physical like a plotter. Generic MSPs tend to handle one of those well and fumble the rest. 99.9% Uptime guarantee · <15min Premium urgent response · 95% Same-day resolution · 100% Client retention ## Your practice deserves better IT. Free infrastructure assessment. We'll look at your workstations, storage, and workflows, then show you where you're leaving performance on the table. ### IT for Startups URL: https://stabilise.io/industries/startups You've got a product to ship, a team to grow, and investors to answer to. We build and manage your entire Apple infrastructure so you can focus on what matters most: your product. ## Everything from your first Mac to your fiftieth **Identity & Access.** SSO across every tool, with Google Workspace or M365 as your identity provider, and Okta or JumpCloud when you outgrow the basics. Everyone gets one login, and when somebody leaves, their access leaves with them. **Zero-Touch Enrolment.** Every Mac enrolled in MDM from the moment it ships. Pre-configured with apps, security policies, and settings. New hire opens the lid and they're working. **Cloud Platforms.** Google Workspace or Microsoft 365 set up the way it should have been on day one, with shared drives, email routing, and security defaults that make sense for a small team. We do it once so you can stop thinking about it. **Ongoing Support.** Your team Slacks us when something breaks. We fix it fast, with a 15-minute response SLA on Premium urgent tickets. Real engineers who know your setup, your tools, and your team. **Security That Grows.** Cyber Essentials when your first enterprise client asks. Endpoint protection from day one. When you're ready for SOC 2 or ISO 27001, the foundation is there. **System Ownership.** We document everything as we go: network diagrams, asset registers, runbooks. If you ever bring IT in-house, your new hire inherits a working, documented system rather than a mystery. The infrastructure is yours. ## Built for how startups work We know you're not buying a 3-year enterprise contract, and we know your headcount might double next quarter or might not. Everything about how we work assumes you're running lean and that plans will change. 75→190 Users at one AI startup we scale with · 30-day Rolling contracts · <15min Premium urgent response · 100% Yours to keep Case study: How we rolled out phishing-resistant MFA across 196 startup identities in under two weeks (/case-studies/phishing-resistant-mfa-okta) Cyber Essentials Plus certified. ## Stop figuring out IT. Start here. Book a free audit and we'll look at what you've got, flag what needs fixing, and leave you with a clear plan. It takes about 15 minutes and there's no commitment attached. ## Case Studies ### Phishing-Resistant MFA in Under Two Weeks URL: https://stabilise.io/case-studies/phishing-resistant-mfa-okta ## The brief: phishing-resistant, not just MFA An AI software company came to us with a hard requirement and a tight deadline. Their own customer was asking for phishing-resistant multi-factor authentication across the systems used to access their data, and it was heading into a contract. Ordinary MFA was not enough. One-time codes, SMS and tap-to-approve push prompts all still rely on a shared secret or a human decision an attacker can relay, and that is exactly what modern phishing kits are built to defeat. The scope was roughly 110 staff accounts on Google Workspace and an 86-member GitHub organisation. We delivered the Google side inside a single committed week, with GitHub following immediately behind, both under one fixed-price statement of work. ## Why we enforced it at the Google layer Almost everything this organisation used signed in with "Sign in with Google". That is the lever. Rather than onboarding dozens of applications one by one, we put Okta in front of Google Workspace as the identity provider and enforced phishing resistance at the Google authentication event itself. Every app that used Google to log in inherited the stronger control without a single application being modified. The enforced factor is Okta Verify with FastPass, configured to require a biometric on every authentication. We deliberately removed the weaker options as acceptable factors: TOTP, SMS and standalone push were all excluded, so there was no quiet fallback to something phishable. ## What phishing-resistant really means here In place of a password or a code, each person authenticates with a cryptographic credential generated and held device-bound in their device's secure hardware, the Secure Enclave on a Mac, the TPM on Windows. The private key never leaves the device, and it is only released after the user verifies themselves with Touch ID, Face ID or a device PIN. That is two factors in one gesture: possession of the enrolled device, proven by a key that cannot be copied off it, and the user's own biometric. Because the credential is cryptographically bound to the organisation's Okta tenant, there is no shared secret for a fake login page to capture and nothing for an adversary-in-the-middle to relay. It defeats credential phishing by design and meets NIST AAL3 on properly configured devices. No hardware tokens to buy and post, and no corporate credential ever synced to a personal cloud account. This is the same Secure Enclave and Touch ID foundation that Apple's Platform SSO is built on, which we wrote about in [Platform SSO on macOS 27](/blog/platform-sso-macos-27-mac-login-without-microsoft). ## GitHub: a second front GitHub does not offer "Sign in with Google", so it needed its own integration. We placed the GitHub organisation behind Okta SAML single sign-on and reused the same phishing-resistant authenticator policy, which meant developer access landed on exactly the same security bar as everything else. That required an upgrade to GitHub Enterprise Cloud, handled by the client directly with the vendor. The detail that keeps developers productive: existing SSH keys and personal access tokens keep working once their owner completes a one-time SSO authorisation of each one. We audited every token, key and machine account against the organisation's repositories first, so anything that would break at enforcement was a deliberate, known decision rather than a surprise on cutover day. ## Rolling it out without breaking everyone's morning A security control nobody can use is not a win. We ran this as a staged rollout: build with no user impact, an enrolment window with daily reporting and named escalation for stragglers, a small pilot cutover to validate real workflows including mail clients and developer command-line tools, then the organisation-wide switch with a staffed support window on the day. Recovery was designed in from the start, not bolted on after. The handful of super admin accounts that sit outside SSO by Google's own design were treated as a documented, compensated exception, secured with passkeys and a written recovery procedure. That break-glass thinking is the part most rollouts underrate, and it is the same lesson we cover in [why passkey rollouts fail on recovery, not cryptography](/blog/enterprise-passkey-rollout-fails-on-recovery-not-cryptography). ## The evidence pack Because this existed to satisfy a contractual requirement, proof mattered as much as the configuration. We delivered an evidence pack for both workstreams: the Okta authenticator policy export, the enforcement configuration, an enrolment completion report, and a documented register of exceptions with their compensating controls. The client could hand that straight to their own customer as evidence the control was real and enforced. If you want the same outcome for your organisation, here is [how we approach an Okta rollout](/projects/okta-implementation-rollout), and it pairs naturally with [SSO and identity management](/projects/identity-access-management) if you are standardising your whole login experience at the same time. ## Projects Capability write-ups describing the kinds of project we scope and deliver, including method and technology. These are not individual client engagements; for those, see Case Studies above. ### Okta Implementation & Rollout URL: https://stabilise.io/projects/okta-implementation-rollout We deploy Okta as your identity provider and roll it out across your whole team. Phishing-resistant MFA, single sign-on for Google, GitHub and your SaaS estate, automated provisioning, and a recovery plan that holds up. Fixed scope, fixed price. ### Mobile Device Management Rollouts URL: https://stabilise.io/projects/mobile-device-management-rollouts Full MDM deployments across Jamf, Mosyle, IRU, and Microsoft Intune. Zero-touch enrollment, security baselines, app deployment, and lifecycle automation for Apple-first and cross-platform fleets. ### Cloud Storage Migrations URL: https://stabilise.io/projects/cloud-storage-migrations Move your data between cloud platforms or from on-prem storage to the cloud. Google Drive, SharePoint, Dropbox, OneDrive. We handle the heavy lifting. ### Email & Platform Migrations URL: https://stabilise.io/projects/email-platform-migrations Migrate between Google Workspace, Microsoft 365, on-prem Exchange, or any email platform. Zero data loss, zero downtime for your team. ### Fleet Refresh & Hardware Lifecycle URL: https://stabilise.io/projects/hardware-refresh-lifecycle Plan and execute a full hardware refresh. Procurement through Apple Business Manager, zero-touch deployment, old device recovery and certified wiping. ### SSO & Identity Management URL: https://stabilise.io/projects/identity-access-management Roll out single sign-on, centralise identity, and automate user provisioning. Okta, JumpCloud, Entra ID, Google, configured properly from day one. ### Password Manager Rollout URL: https://stabilise.io/projects/password-manager-rollout Deploy 1Password across your team with shared vaults, admin policies, and SSO integration. Stop your team reusing passwords. ### SaaS & Endpoint Backup URL: https://stabilise.io/projects/saas-backup-deployment Cloud backup for Google Workspace, Microsoft 365, and Mac endpoints. Because 'it's in the cloud' doesn't mean it's backed up. ### VoIP & Cloud Telephony URL: https://stabilise.io/projects/voip-cloud-telephony Migrate from traditional phone lines to a modern cloud phone system. Better calls, lower costs, works from anywhere. ### Office Network Design & Installation URL: https://stabilise.io/projects/office-network-design-installation Complete technology deployment for any workspace including network, devices, and AV systems ### Cyber Essentials Certification & Ongoing Compliance URL: https://stabilise.io/projects/cyber-essentials-certification-ongoing-compliance A complete Cyber Essentials and CE Plus service that fixes issues, perfects your submission, and keeps you fully compliant with ongoing monitoring and expert support. ### Meeting Room Technology Upgrade URL: https://stabilise.io/projects/meeting-room-technology-upgrade Wireless presentation, video conferencing, and room booking systems across multiple spaces ### Network Attached Storage URL: https://stabilise.io/projects/network-attached-storage Enterprise Synology NAS for creative businesses. 10-25GbE speeds, bulletproof backups, and a deployment planned around your production schedule. ### WiFi Surveys & Improvements URL: https://stabilise.io/projects/wifi-surveys-improvements Professional WiFi surveys using NetSpot and UniFi Design Center. We map your coverage, identify dead zones, and deliver evidence-based improvements for flawless wireless perfor ### Post-Acquisition Data Consolidation URL: https://stabilise.io/projects/post-acquisition-data-consolidation Merged data estates from multiple organisations with deduplication and security alignment ### Rapid Office Deployment (48-Hour Setup) URL: https://stabilise.io/projects/rapid-office-deployment-48-hour-setup Fast-track temporary office infrastructure for time-critical projects ### Notion Systems & Automation Projects URL: https://stabilise.io/projects/notion-systems-automation Custom Notion workspace design, automation, and integration for London businesses. Replace tool chaos with one connected system. ### 10 Gigabit Network Infrastructure Deployment URL: https://stabilise.io/projects/ten-gigabit-network-infrastructure-deployment High-bandwidth network architecture for media-intensive workflows and shared storage ### Complete Workspace Modernisation URL: https://stabilise.io/projects/complete-workspace-modernisation End-to-end office technology refresh including infrastructure, devices, and user training ## Blog ### Tailscale vs Cloudflare Zero Trust for UK Businesses URL: https://stabilise.io/blog/tailscale-vs-cloudflare-zero-trust-for-uk-businesses Published: 2026-08-13T00:00:00.000Z Category: apple-mdm-security Tailscale and Cloudflare Zero Trust solve the same problem in opposite ways. Tailscale builds an encrypted WireGuard mesh directly between your devices: your laptop talks to the office server peer to peer, at whatever speed the line supports, and on a healthy connection Tailscale's own infrastructure never carries your data. Cloudflare routes everything through its global edge, which is exactly what makes its identity checks, traffic filtering and clientless browser access possible, and it means even two machines in the same office reach each other via a Cloudflare data centre. If the things you protect live on site (storage, build servers, dev infrastructure), Tailscale is usually the better fit. If you are gating web apps for a mixed workforce and third parties, or you need to inspect and filter traffic, Cloudflare usually wins. Plenty of teams run both. A note on where we stand before the detail: we run Tailscale internally at Stabilise and deploy it for client fleets, so that half of this comparison is first-hand. We have not deployed Cloudflare Zero Trust for a client. That half is built on Cloudflare's documentation, its published post-mortems, and the accounts of teams who have written honestly about running it. No vendor relationship either way. If you want the primer on why zero trust access beats a traditional VPN at all, we covered that in [Traditional VPNs vs Tailscale and Twingate](/blog/traditional-vpn-vs-tailscale-twingate-zero-trust-remote-access). This post assumes you are past that question and choosing between the two most talked-about answers. ## What Tailscale is and how it works Tailscale is a mesh VPN built on WireGuard. Install the client on every device you care about, sign in with the identity provider you already use (Google Workspace, Microsoft 365, Okta and others), and every device gets a stable private IP on your own private network, called a tailnet. The clever part is what Tailscale's servers do not do. The coordination server exchanges public keys and access policies, and that is all. Private keys never leave your devices, and traffic flows directly between machines wherever NAT traversal succeeds, which Tailscale says is well over 90% of connections. Direct means fast: in Tailscale's own benchmarks, tuned connections exceed 10 Gbit/s between capable machines. Your office NAS, reached from home, performs at whatever speed the slower of the two internet connections allows, with no shared concentrator in the middle. When a direct path fails (symmetric NAT, hostile hotel Wi-Fi, some CGNAT setups), traffic falls back to Tailscale's DERP relay servers. The connection keeps working and stays end-to-end encrypted, but throughput drops sharply. That fallback behaviour is the honest asterisk on every Tailscale speed claim, and it matters when you are sizing expectations for remote file work. Access control lives in a policy file you can code-review. Rules like "engineering can SSH to production, marketing cannot see it at all" are enforced on each device. Tailscale also runs on the storage itself: there is an official package in Synology's Package Center, plus QNAP support, so a NAS can join the tailnet without any port forwarding. ## What Cloudflare Zero Trust is (and how WARP, Access, Gateway and Tunnel fit together) Cloudflare's offer is harder to describe because it is four products wearing one badge, and the names have shifted. In February 2026 Cloudflare renamed the WARP client to the Cloudflare One Client, so you will see both names in its documentation for a while yet. **The client (WARP)** runs on each device and sends its traffic to Cloudflare's edge. The same app powers the free consumer 1.1.1.1 service; enrolled in a company's Zero Trust organisation, it starts enforcing policy and reporting device health. **Access** is the identity gate. Put an internal web app behind Access and every request must pass your rules first: who the user is, which identity provider group they belong to, what state their device is in. It speaks SAML and OIDC, and GitHub works as an identity provider, which dev teams tend to like. **Gateway** is the filter. Because traffic transits Cloudflare, it can block malicious domains, enforce acceptable-use policies, and (with a Cloudflare certificate installed on every device) decrypt and inspect TLS traffic for data loss prevention. **Tunnel** connects your infrastructure. A small daemon called cloudflared runs next to your app or on your network and makes outbound-only connections to Cloudflare, so nothing needs a public IP or an open inbound port. One practical warning from Cloudflare's own docs: create the Access policy before you publish the tunnel route, or your internal service is briefly reachable by anyone. Notice what all four have in common: everything transits Cloudflare. There is no peer-to-peer path. Even Cloudflare's device-to-device feature relays through its network, so two Macs sitting on the same studio LAN, talking via Cloudflare, round-trip through the nearest data centre. That is the architectural fork this whole comparison hangs on. We took a longer, single-product look at the client in [our Cloudflare WARP analysis](/blog/should-your-business-deploy-cloudflare-warp-a-comprehensive-analysis-for-uk-enterprises), recently updated for the rename and the 2025-26 reliability record. ## Why businesses are moving off traditional VPNs The short version: the perimeter appliance became the way in. Between 2024 and 2026, every major VPN appliance vendor shipped at least one critical flaw that attackers exploited in the wild. Ivanti Connect Secure was exploited at scale twice, with the NCSC confirming active exploitation against UK networks. Palo Alto's GlobalProtect took a maximum-severity flaw in 2024 and another exploited bug in 2026 that Qilin ransomware affiliates used for initial access. Check Point gateways leaked password hashes. Akira ransomware walked through SonicWall firewalls that were fully patched with MFA enabled. Fortinet's SSO bypass in December 2025 was being exploited within days; [we wrote up what UK businesses should do about it](/blog/fortinet-firewalls-are-getting-hacked-even-after-patching-cve-2025-59718---what-uk-businesses-need-to-do-now) at the time. Verizon's 2025 Data Breach Investigations Report put a number on the trend: among breaches that began with a vulnerability exploit, the share involving VPNs and edge devices grew almost eightfold in a year, from 3% to 22%. These boxes sit on the public internet, hold credentials for everything behind them, and get patched slowly. Both tools in this comparison remove that box. There is no listening appliance to scan, access is per resource rather than per network, and a stolen credential meets a device check instead of a flat LAN. The NCSC's zero trust guidance is blunt about the destination: assume the network is hostile and verify every request. Its device security guidance goes further, noting there would be little benefit in a VPN once you have fully adopted zero trust networking. ## Gating access on device health, not just passwords The feature that separates both of these tools from a legacy VPN is posture checking: access decisions that consider the state of the machine, not just the person typing. The signals are the ones an auditor would ask about. Is disk encryption on? Is the OS current? Is the security agent running? Is this a company-managed device at all? A personal laptop with the right password gets a different answer from a managed, encrypted, patched MacBook, which is the entire point. **In Cloudflare,** the client checks things like disk encryption, OS version and firewall state natively, and posture can also come from your security stack: CrowdStrike, SentinelOne, Intune and others plug in as posture sources. An Access rule can then say "finance app: finance group, managed device, encryption on." **In Tailscale,** posture conditions attach to the access policy, and the richer signals come from integrations with the tools already managing your fleet: Jamf, Iru (formerly Kandji), CrowdStrike, SentinelOne and Intune among them. Posture integrations require its Standard tier or above. For UK businesses this is not an abstract nicety. The [Cyber Essentials v3.3 changes](/blog/cyber-essentials-v3-3-the-complete-guide-to-april-2026-changes) that took effect in April 2026 made missing MFA and missed 14-day high-risk patching into automatic failures. Posture-gated access will not patch your Macs for you, but it turns "are our devices compliant" from a quarterly spreadsheet exercise into a condition enforced at the moment of access, with logs to show for it. That is exactly the evidence security questionnaires and CE assessors ask to see. ## Remote access to on-site storage: where the architectures diverge Here is the question the homelab blogs and vendor pages all skip: what happens when the thing you need to reach is a storage box in your own office, and the files are big? **Tailscale's answer is structural.** Put Tailscale on the NAS (the Synology package is official) or on a machine in front of it, and remote access is a direct WireGuard connection. A photographer pulling a shoot from the studio RAID gets the upload speed of the studio line. In the office, devices talk over the LAN as they always did. The caveat is the relay fallback: a client stuck behind hostile NAT drops to DERP speeds, so a team member on tethered CGNAT mobile broadband will feel it. **Cloudflare's answer is a proxy.** SMB file sharing over the private network route works, and Cloudflare documents it, along with the caveats: private IP ranges are excluded from the client by default (an easy setup miss), and SMB is latency-sensitive, so every chatty protocol round trip travels to the nearest Cloudflare data centre and back. Cloudflare's proxied HTTP hostnames also enforce a 100MB upload cap, which rules out Tunnel public hostnames as a general file-drop endpoint; the private-network path avoids that limit but still hairpins through the edge. For a dev house, the same fork shows up as infrastructure access. Tailscale gives you SSH to build servers and databases over direct connections, ephemeral CI runners that join the tailnet and vanish, and a Kubernetes operator. Cloudflare counters with browser-rendered SSH and RDP that need no client at all, which is genuinely useful for giving a contractor scoped access to one box for one week. For a studio, the calculus is starker. A proxy-based edit workflow (cut on lightweight proxies, conform against full-resolution media at the end) survives either tool. The ingest and conform steps, where the terabytes move, want the direct path. If remote edit is the goal, the strongest pattern we have seen is a remote-desktop tool like Parsec or Jump Desktop running over Tailscale: pixels travel, media never leaves the building. Our [creative remote access piece](/blog/the-creative-remote-access-challenge-vpn) covers that workstation-first approach, and our [Synology guide for Mac businesses](/blog/synology-nas-best-practices-for-mac-based-businesses) covers the storage end. **The flip side:** if your "on-site data" is really a web app, an internal wiki, a Grafana dashboard, something viewed rather than transferred, Cloudflare's model costs you almost nothing in practice and buys you clientless access for people you would never enrol in your mesh. ## Deploying each on a managed Mac fleet Both deploy cleanly through MDM, and we covered the general pattern in the [Tailscale and Twingate piece](/blog/traditional-vpn-vs-tailscale-twingate-zero-trust-remote-access). The comparison-specific details are the ones that bite. **Tailscale on macOS** ships two client variants (App Store and standalone) with different preference domains, and Jamf-ready configuration schemas for both. Pick one variant fleet-wide and stay on it. Keep the client current: Tailscale publishes security bulletins at a steady clip, including a January 2026 fix for a root-level flaw in the standalone macOS variant's helper service, and a 2025 advisory that MDM-supplied auth keys had been logged, worth knowing if you scripted enrolment with a shared key. **Cloudflare on macOS** deploys as a signed package with a managed preferences payload, and supports a no-MDM config file for scripted installs. The trap is downstream: if you turn on Gateway's TLS inspection, anything that pins its certificates breaks until you add explicit do-not-inspect exemptions. Cloudflare's own deployment guide for Iru (Kandji) calls this out, because the MDM agent's certificate pinning is incompatible with inspection. Cloudflare's docs concede the general point plainly: it is never possible to inspect absolutely all traffic, something will always break. **Do not run both clients on one Mac by default.** They compete for the network extension layer and each other's control traffic; making them coexist takes deliberate split-tunnel exclusions. It is solvable, and documented by people who have done it, but it belongs in your deployment design, not in a user's Tuesday afternoon. ## Running both: a common pattern, with caveats The cleanest articulation we found of the hybrid pattern comes from an engineering write-up that runs both: Cloudflare as the perimeter for human traffic, Tailscale as the fabric for machine traffic. Public-facing and browser-based things sit behind Access; servers, agents and storage talk over the tailnet and never touch a public edge. It works, and it maps to what each tool is best at. The friction shows up in three predictable places: both clients want to own DNS on the device, both wired to the same identity provider can encode subtly different policies for the same person, and advertised subnet ranges can collide. Decide which tool owns which layer up front and the pattern is stable. ## Trade-offs, side by side | Dimension | Tailscale | Cloudflare Zero Trust | |---|---|---| | Architecture | Peer-to-peer WireGuard mesh | Everything proxies through Cloudflare's edge | | Best at | Direct access to on-site storage and infrastructure | Gating web apps, filtering traffic, third-party access | | Traffic inspection / DLP | None by design; pair with EDR | Gateway inspection, DLP, browser isolation (paid tiers) | | Clientless access | No, client required | Yes: browser-rendered SSH, RDP, VNC and web apps | | Device posture | Via MDM/EDR integrations (Standard tier up) | Native client checks plus EDR/MDM integrations | | On-site file work | LAN-speed when direct; relay fallback is slow | Every transfer hairpins through the edge; SMB workable but slow | | Behind CGNAT | Usually fine for private access; relay fallback | The dependable choice for publishing services outbound-only | | Free tier | Personal use, small device counts | Full Zero Trust for up to 50 users | | When the vendor has a bad day | Existing connections keep flowing; new logins stall | Access is the front door, so an outage locks every door | | Your data path | Direct between your devices on healthy connections | Transits a single vendor, one certificate away from inspection | Two rows deserve expansion. **Reliability.** Cloudflare's 18 November 2025 outage took Access authentication down for hours along with a fifth of the web; its February 2026 incident broke dedicated egress for six hours. Cloudflare publishes unusually candid post-mortems, which counts for something, but concentration is the price of its model. Tailscale's control plane has had incidents too; the architectural difference is that established WireGuard sessions keep flowing when it does, and only new logins and key rotations stall. **Cost shape.** Cloudflare's free tier covers 50 users, which is remarkable and embarrasses Tailscale's small free plan. Past free, both charge per user per month in dollars, and the expensive Cloudflare capabilities (DLP, browser isolation, egress IPs) live in enterprise contracts. Check both pricing pages before you plan a budget; both change more often than blog posts get updated. ## A decision framework for startups, dev houses and studios **Choose Tailscale when the crown jewels are machines.** On-site storage, build infrastructure, databases, render boxes, staging environments. Engineering-led startups fit here almost by default, and it is what we run ourselves and deploy for clients. **Choose Cloudflare Zero Trust when the crown jewels are apps and the audience is mixed.** Internal web tools for a broad workforce, contractor and client access without installing anything, staging sites for reviewers, plus filtering and DLP obligations a regulator or enterprise customer imposes. The 50-user free tier makes it a very cheap experiment. **Studios with on-site media:** Tailscale for the data path, and consider remote workstations over it rather than remote file transfer. Use Cloudflare, if at all, for the browser-shaped things around the edges: review portals, internal dashboards, the booking wiki. **Genuinely both:** common, sensible, and worth doing deliberately. Cloudflare for humans reaching apps, Tailscale for machines reaching machines. Decide who owns DNS before you start. Whichever way you lean, the same rule applies that we give every client about zero trust: the tool is the easy part. The value is in the policy (who can reach what, from which devices, in what state) and in wiring it to the identity provider and MDM you already run. That design work is where we spend our time, on Tailscale tailnets and on the [identity stack underneath](/blog/okta-vs-entra-id-vs-google-vs-jumpcloud-mac-idp-comparison-2026), and it is the part worth getting right first. ### The Startup Mac Stack: Jamf, Okta, and Onboarding That Runs Itself URL: https://stabilise.io/blog/the-startup-mac-stack-jamf-okta-and-onboarding-that-runs-itself Published: 2026-08-04T00:00:00.000Z Category: apple-mdm-security The stack that fast-growing startups keep landing on has four pieces: Macs bought through Apple Business, managed with Jamf Pro, protected by Jamf Protect, and tied together by Okta with your HR system as the source of truth. Wired up properly, onboarding runs itself. HR marks the offer as signed, Okta builds the accounts, a MacBook ships from Apple straight to the new hire's home, and on day one they open the lid, sign in once, and everything is there. Nobody from IT touched the laptop. This is our bread and butter as an [Apple MSP for startups](/industries/startups), and it's the stack that carried one of our AI startup clients from 75 to 190 users. Here's each piece, and why it earns its place. ## Why do startups standardise on Macs? Mostly because their people ask for them, and the numbers say you should let them. Across all professional developers, macOS sits at about a third (31.8% in the [2024 Stack Overflow survey](https://survey.stackoverflow.co/2024/technology)). But that average hides the pattern that matters: what people pick when the company lets them choose. Cisco's IT team reported in 2023 that 59% of new hires chose a Mac when offered one, rising to 65% among staff due a refresh. In a hiring market where startups compete with much bigger salaries, the laptop is one of the few perks that costs nothing extra to get right. **The support burden is the part founders underrate.** IBM's data from its own fleet, presented back in 2019, showed 5% of Mac users contacting the help desk against 40% of PC users, and 7 engineers supporting 200,000 Macs where Windows needed 20. Forrester's April 2024 Total Economic Impact study (commissioned by Apple, so read it with that in mind) found 60% fewer support tickets per Mac per year. A 30-person startup doesn't have an IT team. Every ticket that never gets raised is founder time back. **Macs also hold their value.** The same 2024 Forrester study put a MacBook Air at 30% residual value after four years against 10% for a comparable enterprise PC. When you're buying laptops 20 at a time on a seed budget, the resale column is real money. We went deeper on the retention side of this in [our post on device choice and employee loyalty](/blog/why-apple-devices-higher-employee-retention-data-2025). The short version: people stay longer at companies that give them tools they like. ## What does the standard startup Mac stack look like? Four layers, each doing one job: | Layer | Tool | The job | | --- | --- | --- | | Purchasing and enrolment | Apple Business (free) | Every Mac you buy is assigned to your company before it ships | | Device management | Jamf Pro | Settings, apps, patching, and compliance enforced on every Mac | | Endpoint security | Jamf Protect | macOS-native threat detection and the evidence trail auditors want | | Identity and provisioning | Okta + your HRIS | One login for everything, driven by the HR record | Apple Business is the piece people still know by its old name. Apple merged Apple Business Manager and Apple Business Essentials into a single free platform called Apple Business in April 2026, and it remains the foundation everything else stands on. Sign up once (UK companies need a D-U-N-S number matching their registered name), link your Apple customer number or your reseller's number, and every Mac you buy from then on belongs to your organisation the moment the order is placed. One honest note on the middle layers: we're agnostic about the tools. We deploy Kandji and Mosyle as happily as Jamf, and EDRs like CrowdStrike Falcon where they fit better, so the recommendation comes down to cost, functionality, and what your compliance targets demand. The stack shape stays the same whichever names are in the boxes. Jamf is on this page because it's the most common answer at the point a startup gets serious, and it has the deepest bench of integrations with the rest of this list. ## What do Jamf Pro and Jamf Protect add over Apple's free tools? Apple Business ships with a basic built-in MDM these days, and for a five-person team it can be enough. We wrote up [when the built-in MDM stops being enough](/blog/apple-business-built-in-mdm-when-to-upgrade-uk-2026) separately. Jamf Pro earns its licence at the point where scale and proof start to matter. It enforces your security baseline (FileVault, screen lock, firewall) as policy rather than as a checklist someone forgets. Its app catalogue installs and patches over a thousand common titles automatically, so the design team's apps stay current without anyone raising a ticket. And its compliance benchmarks let you audit the whole fleet against CIS and NIST baselines from one console, then export the evidence. Jamf Protect is the security layer, and the reason we reach for it on Mac fleets is architectural. It's built on Apple's own Endpoint Security framework, so it does behavioural threat detection on the device itself and supports new macOS versions from day one, rather than being a Windows agent ported across. It also gives you USB device control and telemetry you can hand to an auditor or a SIEM. We compared it against CrowdStrike, SentinelOne and Sophos in [our Mac EDR comparison](/blog/jamf-protect-vs-crowdstrike-vs-sentinelone-vs-sophos-edr-mac-comparison-2026). **For startups, this pair is really a compliance story.** The day your first enterprise customer sends a security questionnaire, the questions are about disk encryption, patching, screen lock, malware protection, and whether you can prove any of it. AI startups hit this earlier than anyone, because their customers are nervous about data. MDM-enforced controls plus Protect's reporting is that proof, and it covers most of the device-control evidence for Cyber Essentials, SOC 2, and ISO 27001. Set up properly, it turns the questionnaire from a fire drill into a form-filling exercise. ## How do Okta and your HR system automate provisioning? The average company now runs 101 apps, per Okta's own Businesses at Work 2025 report. Somebody has to create accounts in all of them, with the right permissions, every time someone joins. At most startups that somebody is a founder with a spreadsheet of invite links, and it takes them a full day per hire. The fix is to make the HR system the source of truth. Okta calls the pattern HR-driven provisioning: your HRIS (Workday, BambooHR, HiBob, and others) syncs new-joiner records into Okta, and the record itself carries what Okta needs. Department and role decide which groups the person lands in, and group rules decide the apps. An engineer gets GitHub, a designer gets Figma, everyone gets Google Workspace, Slack and Notion, all created over SCIM with the right permission level. Nobody clicks through admin consoles. **The clever part is the timing.** Okta's Workflows automation can create accounts in a non-activated state ahead of the start date and switch them on when day one arrives. That's a documented Okta pattern, not a hack we invented. It's also what makes the welcome email possible: a day or two before their start, the new hire gets their sign-in details and knows exactly what Monday morning looks like. First impressions are set before they've met anyone. Okta's published pricing starts at $6 per user per month, with the popular tier at $17. Choosing between Okta, Entra ID, Google and JumpCloud for a Mac fleet is its own decision, and we wrote [a full comparison](/blog/okta-vs-entra-id-vs-google-vs-jumpcloud-mac-idp-comparison-2026). We also do [Okta implementations as a service](/projects/okta-implementation-rollout). ## What does the new hire's first day look like? Put the four layers together and the flow reads like this: 1. **Offer signed.** HR completes the record in the HRIS: name, role, department, start date. 2. **Okta picks it up.** The record syncs in, group rules assign the app bundle, and accounts are created downstream in a non-activated state. 3. **The MacBook is ordered.** Bought under your Apple customer number, assigned to your organisation automatically, shipped by Apple to the new hire's home. It never visits an office. 4. **The welcome email lands.** A day or two before the start date, Okta sends sign-in instructions. 5. **First boot.** The Mac checks in with Apple, sees it belongs to your company, and enrols itself in Jamf before the desktop appears. Security baseline applied, apps installing, Protect running. 6. **One sign-in.** The new hire authenticates with Okta and everything they need is open by the second cup of coffee. The part that matters for a startup is that the flow is identical for hire number 8 and hire number 80. The system doesn't get tired, doesn't forget the Figma licence, and doesn't need a new IT hire every 40 heads. One AI startup we support scaled from 75 to 190 users on exactly this stack. ## What happens when someone leaves? Offboarding is the same pipeline run backwards, and it's where the stakes are higher. In a 2022 Beyond Identity survey of workers in the US, UK and Ireland, 83% admitted they could still access accounts at a former employer. Self-reported, so treat the precise number gently, but every IT provider has seen the pattern behind it: offboarding done from memory always misses something. With this stack, HR marks the leaver's end date and one deactivation cascades through everything. Okta kills the sessions and deprovisions the downstream accounts over SCIM. Jamf can lock or wipe the Mac remotely. Okta Workflows handles the polite parts on a schedule: transfer their files to a manager, hold payroll access for the notice period, delete the rest after your retention window. The security questionnaire question "how do you revoke leaver access?" gets a one-sentence answer. The AI startup that grew from 75 to 190 users took identity a step further with us: phishing-resistant MFA rolled out across 196 identities in under two weeks. [That case study is here](/case-studies/phishing-resistant-mfa-okta). ## Where does this go wrong without help? Every startup that calls us has hit some version of the same five walls. **The Macs came from Amazon.** Retail and marketplace purchases never auto-enrol. They can be added by hand with Apple Configurator, but the user gets a 30-day window to remove management, and someone has to physically do each machine. Buying through Apple Business costs nothing and makes the problem disappear. **Apple Business was set up after the laptops.** Nothing fails loudly. The Macs just arrive as ordinary consumer devices, get set up by hand, and quietly accumulate as unmanaged risk. **Access lives in someone's head.** Accounts created ad hoc, permissions granted on request, a shared 1Password vault standing in for an identity layer. Fine at 10 people. At 40, nobody can answer who has access to what. **Offboarding is a checklist in Notion.** Usually followed. Usually. **The questionnaire arrives before the evidence does.** A big customer's security review lands, the deal is waiting on it, and the answers need infrastructure that takes weeks to build properly. This is the most common moment startups first ring us, and it's a far more expensive moment than the one where you set it up calmly at 20 people. If any of those sound familiar, that's the pain this stack was designed to remove. ## Set it up once, properly None of the pieces here are exotic. What's rare is having them wired together so HR, identity, devices and security behave as one system, and having someone who has done it enough times to dodge the sharp edges. That's what we do. We'll audit what you've got, design the stack around your headcount plans, and run it with you as you grow, [from your first 5 Macs to your 190th](/industries/startups). [Talk to us about your setup](/contact). The audit is free, and we've seen far messier starting points than yours. ### AI Governance for UK Businesses: Why It Matters and How to Enforce It URL: https://stabilise.io/blog/ai-governance-for-uk-businesses-implement-and-enforce Published: 2026-07-23T00:00:00.000Z Category: apple-mdm-security AI governance is how a business controls the way AI tools are used with its data: which tools are allowed, what staff can put into them, and how that is enforced and recorded. It matters now because employees are already using AI, often through personal accounts that send company and client data to public models, and because rules like the EU AI Act's transparency obligations start to apply from August 2026. The mistake most businesses make is stopping at a written policy. A policy nobody can enforce changes nothing. Real AI governance pairs a clear acceptable-use policy with technical controls on your devices: discovering which AI tools are in use, allowing the safe ones, blocking the rest, and keeping an audit trail. On a Mac fleet, that enforcement runs through your MDM. ## What AI governance really means AI governance is the rules that decide how AI gets used inside your business, and the proof those rules are being followed. It answers three questions: which AI tools are approved, what data staff are allowed to put into them, and how you enforce and evidence that. The word people forget is enforce. Plenty of businesses have written an AI policy. Far fewer can tell you which AI apps are running on their laptops right now, or stop someone pasting a client contract into a free chatbot. Governance is both halves, the policy and the enforcement. A policy on its own is a document. Enforcement is what makes it real. ## Why AI governance matters now **Your staff are already using AI, with or without permission.** Gartner found that 57% of employees use personal generative-AI accounts for work, and 33% have uploaded sensitive data to tools their employer never approved (figures cited by [Jamf](https://www.jamf.com/solutions/ai-governance/)). Every one of those uploads is company or client data leaving your control, and potentially training a public model. **The rules are starting to bite.** From 2 August 2026, the [EU AI Act's](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) transparency obligations apply. If you run a customer-facing chatbot, generate synthetic media, or publish AI-generated content, you have to disclose it. The tougher high-risk rules were pushed back to December 2027 and 2028 under the June 2026 Digital Omnibus, but the transparency deadline holds. This catches UK firms too: if you offer an AI system to users in the EU, the Act applies wherever you are based. **The UK route is quieter but real.** The UK has no single AI law. It runs a principles-based approach through existing regulators, mainly the ICO, Ofcom, the CMA, and the FCA. The one to watch is the [ICO](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/), which now has a statutory duty to produce a code on AI and automated decision-making, expected in summer 2026. Wherever you use personal data with AI, that code will shape what counts as reasonable. **Your clients and insurers are asking.** Enterprise procurement, cyber-insurance renewals, and due-diligence questionnaires increasingly ask how you govern AI. "We don't" is a lost deal or a higher premium. ## The frameworks, and which a UK business should care about Three names come up constantly. Here is what each is for, without the fog. **NIST AI RMF** is a voluntary risk-management framework from the US, structured around four jobs: govern, map, measure, and manage. No certificate, no legal force, just a sensible operating model. For most UK SMEs it is the best place to start, because it is practical and free. **ISO/IEC 42001** is the first international standard for an AI management system, and unlike NIST you can be certified against it by an auditor. Worth it when a customer or investor wants proof, the same way ISO 27001 or Cyber Essentials works for security. **The EU AI Act** is law, organised by risk tier. You care about it if you sell or offer AI systems into the EU. If you do not touch the EU market, it is context, not a compliance job. For a typical UK business the honest order is: use NIST AI RMF as your working model, add ISO 42001 if you need something certifiable to win deals, and treat the EU AI Act as a live requirement only if you have EU exposure. The UK's ICO code sits underneath all of it wherever personal data is involved. ## Shadow AI: the risk your policy misses Shadow AI is any AI tool your team uses for work that IT has not approved or cannot see. A designer running a free image model, a developer pasting proprietary code into a chatbot, someone summarising a client call in a personal account. It is the AI version of shadow IT, and it is the gap most policies never close. Banning AI outright does not work. People use it anyway, just more quietly, and you lose the visibility that governance depends on. The approach that works is governed enablement: give people sanctioned tools that are safe to use, make the safe path the easy path, and control the rest. You get the productivity without the data leaking somewhere you cannot audit. ## It is not just chatbots anymore: AI agents and MCP The conversation has moved past chatbots. Developers and power users now run AI agents and coding assistants like Claude Code, Cursor, and GitHub Copilot, and connect them to tools and data through Model Context Protocol (MCP) servers. These do not just answer questions, they take actions and reach into systems. That raises the stakes. An agent with access to your code repositories or a connected data source can move far more than a copy-pasted paragraph. Governing AI in 2026 means knowing which agents and MCP connections are running on your machines, not just which websites people visit. Most AI policies were written for chatbots and have not caught up. ## How to implement AI governance, step by step You do not need a forty-page framework to start. You need these steps, in order. 1. **Discover what is already in use.** You cannot govern what you cannot see. Find the AI apps, browser extensions, and agents running across your fleet before you write a single rule. 2. **Write a short acceptable-use policy.** Plain English: which tools are approved, what data is never allowed into AI (client data, credentials, anything personal or confidential), and who to ask. One page beats forty. 3. **Classify your data.** Staff need to know what counts as sensitive. Tie the policy to a simple data-classification scheme so "keep confidential data out of AI" means something concrete. 4. **Give people a sanctioned path.** Roll out business-grade AI tools with the right privacy settings, so the safe option is also the convenient one. 5. **Enforce it technically.** The step most people skip. Block unapproved AI apps and domains, apply data-loss-prevention rules, and configure the AI features you do allow. Policy plus enforcement, not policy alone. 6. **Train, then review.** A short session on what is allowed and why, then revisit every quarter, because the tools change monthly. ## Where governance meets your Apple fleet For a Mac business, the enforcement in step five runs through your device management. This is the part we do day to day. Because we are a Jamf shop, we can see and control AI at the operating-system level on Apple Silicon: discover which AI apps, agents, and MCP servers are running, allow the sanctioned ones, and block the rest by user or group. We control the Apple Intelligence features and the ChatGPT integration built into macOS, so the AI that ships with the operating system follows your policy rather than each user's preference. Every enforcement decision is logged, which is the audit trail the EU AI Act's transparency rules expect. For more on the Apple side, we covered the [enterprise security questions Apple Intelligence raises](/blog/apple-intelligence-enterprise-security-uk-it-managers), and [what Gemini's Gmail changes mean for your data](/blog/gmails-gemini-ai-update-what-uk-businesses-need-to-know-about-email-privacy). ## It plugs into the compliance you already have AI governance is not a separate programme bolted on the side. It sits on top of the security and data controls you should already have. The data-classification work supports [GDPR](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/). The device enforcement is the same MDM that underpins [Cyber Essentials](/blog/cyber-essentials-plus-why-our-clients-pass-without-scrambling) and [NIS2](/blog/nis2-compliance-apple-it-infrastructure-uk-2025). If your security foundation is solid, AI governance is a layer, not a rebuild. If it is not, this is a good reason to fix it. AI is already in your business. The only real choice is whether it is governed. If you would like a clear view of which AI tools are running across your team, and a plan to bring them under control, [get in touch](/contact) and we will take a look. ### Synology Best Practices for Mac-Based Businesses: Security, Settings and 10GbE (2026 Guide) URL: https://stabilise.io/blog/synology-nas-best-practices-for-mac-based-businesses Published: 2026-07-10T00:00:00.000Z Category: apple-mdm-security Most Synology guidance on the internet is written for home users, and almost all of it assumes Windows. If you run a Mac-based business, you inherit a set of problems those guides never mention: Finder search that silently does nothing on network shares, .DS_Store files breeding across every folder, Time Machine backups that fail with cryptic errors, and 10GbE networks that benchmark beautifully and then transfer files at a tenth of the speed. We deploy and manage Synology NAS units for Mac-first companies across London, as a [Mac-specialist provider rather than a Windows generalist](/blog/mac-specialist-msp-vs-windows-first-generalist-uk), so this is the guide we wished existed. It runs from first-day basics to the advanced networking most articles skip, and every section ends with a step-by-step you can follow directly. Everything here reflects DSM 7.3/7.4 and macOS 26 Tahoe as of July 2026. One framing note before we start: a NAS on your network is a server, and it holds the most valuable data in your business. Treat its setup with the same seriousness you would treat a cloud migration, because attackers certainly do. In March 2026 Synology patched a critical 9.8-severity remote code execution flaw in DSM's telnet service, and in 2024 researchers demonstrated a zero-click exploit against Synology Photos with an estimated one to two million devices exposed to the internet. The gap between a hardened NAS and a default one is enormous, and it is mostly a matter of an afternoon's configuration. ## Buying the right box: rack first for most businesses For most businesses we deploy for, the right Synology is a rackmount RackStation, not a desktop DiskStation. If you have a comms room, or even a small wall-mounted cabinet, rack is the sensible default: built-in fast networking, room to grow, redundant power on the models that offer it, and a box that lives somewhere it is allowed to be loud. Desktop DiskStations are the exception, for offices with genuinely nowhere to rack a unit. ### RackStation: the business default RackStations split into two tiers, and the split maps neatly onto budget and workload. **RS Plus is the business entry tier.** These run AMD Ryzen CPUs with ECC memory and scale from 4 bays up to 16. The 4-bay RS422+ and RS822+ start on 1GbE and take a 10GbE or 25GbE card; from the 12-bay RS2423+ up, 10GbE is built in, and the 16-bay RS2825RP+ (2025) is also 25GbE-ready. For resilience, look at the **RP variants** (RS822RP+, RS1221RP+, RS2423RP+II, RS2825RP+), which add redundant, hot-swap power so a dead PSU does not take the NAS down. All of them take RX expansion shelves, so a 12-bay unit grows to 24 drives without replacing the head unit. **RS xs and xs+ are the performance tier.** The RS1626xs+ (a short-depth 1U 4-bay), RS3621xs+, RS3626xs, RS4826xs+ and RS6426xs+ all ship **dual 10GbE built in** and take PCIe cards for 25GbE. Head-unit bay counts run 4 to 16, and expansion scales the top models to 48 or 64 drives. This is the tier for post houses, render pipelines, and anyone whose working storage is the business. Two rack realities worth planning for. **Rack gear is loud**, which is the point: it belongs in a comms room away from desks, which is exactly why it suits a business better than a desktop unit humming next to someone's monitor. And **check rack depth** before ordering, because full 2U RackStations are deep and will not fit a shallow wall cabinet. That is what the short-depth 1U models like the RS1626xs+ are for. As with the desktop range, verify the specific model's spec sheet before buying, not the product family. Synology shifts which models carry built-in 10GbE between generations. ### No rack? The desktop path (and the DS925+ trap) If you have nowhere to rack a unit, a desktop Plus model is fine, with one trap to avoid. **If you want 10GbE, the newest 4-bay is the wrong NAS.** The DS925+ is Synology's default small-business desktop pick, but it dropped the 10GbE network upgrade slot its predecessor the DS923+ had. There is no path to 10GbE on a DS925+, full stop. A Mac team on a desktop unit that wants fast networking starts at the DS1525+ (5-bay, takes Synology's E10G22-T1-Mini module in a dedicated slot) or the DS1825+ (8-bay, with a PCIe slot for a full 10GbE or 25GbE card). If you do not need 10GbE, the DS925+ is a fine box. **On drives, the 2025 lockdown saga is mostly resolved.** In April 2025 Synology blocked storage pool creation with non-validated third-party drives on its 2025 Plus models, and the backlash was loud enough that DSM 7.3 (October 2025) reversed it. Third-party 3.5-inch hard drives and 2.5-inch SATA SSDs work again, with an "unverified" label and reduced health analytics. The reversal does not cover M.2 NVMe: storage pools on NVMe still require drives from Synology's compatibility list, so budget for listed NVMe if you plan an all-flash working tier. Sizing is simpler than vendors make it. For a team of 5 to 25 Macs doing office work, a 12-bay RS Plus RackStation (or a 4-to-8-bay desktop where there is no rack) with NAS-rated drives (Synology HAT, Seagate IronWolf, WD Red Plus) is plenty. For video, photography, or audio teams, the network and the drive count matter more than the CPU, which is why the tier choice above is the decisive spec. ### Step by step: speccing the NAS 1. Rack or no rack? With a comms room or cabinet, choose a RackStation: RS Plus for office and general business use, RS xs/xs+ for media and heavy workloads. Desktop DiskStation only if there is nowhere to rack one. 2. Decide on 10GbE. On RackStations it is built in from the 12-bay RS Plus up and across the whole xs range. On desktop that means DS1525+ or DS1825+, never the DS925+. 3. If uptime is critical, choose an RP (redundant-power) model, and consider two units for High Availability (covered later). 4. Fill at least 4 bays with NAS-rated drives. More smaller drives usually beats fewer huge ones for speed and rebuild risk, and RX expansion shelves add bays later without a forklift upgrade. 5. If buying a 2025-or-newer model with third-party drives, expect "unverified" warnings. They are cosmetic for HDDs and SATA SSDs. 6. Only buy M.2 NVMe drives that appear on Synology's compatibility list for your model. 7. Buy a second Synology (or budget for cloud) at the same time as a backup target. "We'll add backup later" is how businesses lose data. ## First-day setup: the decisions that are hard to change later **Choose Btrfs and SHR when you create the volume.** Btrfs gives you data checksums, self-healing on redundant arrays, and snapshots, which are the foundation of the ransomware protection covered later. SHR (Synology Hybrid RAID) tolerates one drive failure and handles mixed drive sizes gracefully; use SHR-2 on arrays of five or more drives. The file system cannot be changed without rebuilding the volume, so get this right on day one. (One exception worth knowing: if the NAS will also run Surveillance Station for cameras, Synology's guidance prefers ext4 for that workload. Keep cameras on a separate volume or a separate box.) **Skip QuickConnect during the setup wizard.** You can add remote access properly later (we recommend Tailscale, covered in the security section). The wizard makes QuickConnect feel mandatory; it is not. **DSM 7 already handles the admin account.** Fresh installs force you to create a named administrator and disable the default "admin" account automatically. Older guides tell you to disable admin as step one; on a new NAS your job is just to verify it shows as disabled in Control Panel > User & Group. If you migrated from an older system, check and disable it manually. **Know which DSM branch you are on.** As of July 2026 there are two current lines: DSM 7.4 (released 16 June 2026, still rolling out through the summer) and DSM 7.3.2, which is the long-term support branch with security fixes committed to October 2027. A new NAS may arrive with either. Both are fine; what matters is Control Panel > Update & Restore set to install important updates automatically. Synology shipped over 50 proactive security updates in the past year, and unpatched NAS units are exactly what gets exploited. **Structure shares by team, not one big folder.** Permissions on Synology are cleanest at the shared-folder level. Create per-team shares (Finance, Projects, Studio) rather than one giant share with per-subfolder permissions. Enable the Recycle Bin on every share, and add a Task Scheduler job to purge recycle bin contents older than 30 days so deleted files do not accumulate forever. **Permissions go on groups, never users.** Create groups first (finance, production, everyone), assign share permissions to groups, then drop users into groups. It is the difference between onboarding a new hire in one step and auditing forty individual permission entries a year from now. A note on directory services, because Mac businesses ask: do not bind your Macs to a directory. Apple itself steers organisations away from directory binding, and Synology's Directory Server is a Windows-oriented Samba Active Directory. For a small Mac shop, local DSM users and groups, named to match your identity provider (Google Workspace, Entra ID, Okta), is the honest, boring, reliable answer. DSM 7.2+ supports OIDC single sign-on for the web interface if you want the login tidied up, but SMB file access still maps to DSM accounts underneath. **Give the NAS a fixed address, wired.** The NAS plugs into your core switch over Ethernet, never Wi-Fi, with a DHCP reservation (or static IP outside the DHCP pool) so its address never changes underneath your Macs' mounted shares. ### Step by step: day one 1. Run the wizard: create your named admin account, skip QuickConnect, skip the Synology account (you can add one later for update notifications). 2. Verify the default "admin" account is disabled: Control Panel > User & Group. 3. Storage Manager: create an SHR storage pool, then a Btrfs volume. 4. Control Panel > Update & Restore: enable automatic installation of important updates, scheduled out of hours. 5. Create groups, then users, then per-team shared folders with Recycle Bin enabled. 6. Task Scheduler: add a monthly "Empty Recycle Bin" task with 30-day retention. 7. Give the NAS a DHCP reservation on your router or firewall. 8. Control Panel > Notification: configure email (and push via Synology account if you added one), then send a test. A dead drive you never hear about is a second dead drive waiting to happen. ## Security hardening: an afternoon that pays for itself The recent CVE record justifies taking this seriously. Beyond the March 2026 telnet flaw (CVE-2026-32746, CVSS 9.8, patched across DSM 7.2, 7.3 and 7.4), the 2024 "RISK:STATION" vulnerability in Synology Photos was a zero-click remote code execution bug demonstrated at Pwn2Own, with researchers estimating one to two million exposed devices. Neither has been confirmed as exploited in the wild, but that is the wrong comfort to take: the lesson is that critical flaws in NAS software are found regularly, and the fix ships before most owners install it. Here is our hardening baseline for every business Synology we manage, and it pairs with the [Mac security baselines](/blog/mac-security-baselines-ncsc-cis-uk-businesses) we apply to the Macs themselves. **Enforce 2FA for every account.** Control Panel > Security > Account lets you enforce two-factor authentication for all users or specific groups. Enforce it for everyone, not just admins. Synology's Secure SignIn app gives one-tap approval, and hardware keys (including Touch ID on Macs, via Safari) work through the FIDO2 option. DSM also enables Adaptive MFA by default for administrators without 2FA, but do not rely on the fallback; enforce the real thing. **Turn on the brute-force protections.** Control Panel > Security > Protection: enable Auto Block (block an IP after, say, 5 failed logins within 5 minutes) and enable DoS protection on your LAN interface. Under the Account tab, enable Account Protection as well, which locks accounts against attacks from untrusted clients even when the attacker rotates IPs. **Enable the firewall, and understand its default.** Control Panel > Security > Firewall. A subtle trap: switching the firewall on with no rules allows everything. Create a rule allowing your LAN subnet, a rule allowing your VPN range if you use one, then set the default action to deny. If the business only operates from the UK, a geo-block rule denying everything else costs nothing and removes a lot of noise. **Fix the web interface.** Control Panel > Login Portal > DSM tab (this moved from Network settings in DSM 6, which still confuses guides): move the default ports 5000/5001 to a high, non-obvious pair. We use five-digit ports well away from the defaults, not 5002; every automated scanner on the internet knows Synology's numbers, and moving well clear of them takes your NAS out of the drive-by sweeps. Then tick "Automatically redirect HTTP connections to HTTPS", and enable HSTS. Then install a proper certificate: Control Panel > Security > Certificate has built-in Let's Encrypt support. The one catch is that Let's Encrypt's HTTP-01 validation needs port 80 reachable from the internet during issuance; if you will not open that even briefly, use a DNS-validated wildcard certificate instead. **Disable what you do not use.** SSH and Telnet are off by default in DSM 7; leave them off (and never enable Telnet, which is where that 9.8 CVE lived). Disable AFP (more on that below), and leave NFS, FTP, SNMP and rsync off unless something specifically needs them. Also disable UPnP port forwarding on your router: a NAS should never be punching its own holes in your firewall. **Remote access: use Tailscale, not port forwarding, and probably not QuickConnect.** Being fair to QuickConnect: it is a relay, opens no inbound ports, and is meaningfully safer than exposing DSM to the internet directly. But it still presents your DSM login page through Synology's infrastructure, guarded by nothing more than your credentials and 2FA. The cleaner business posture is Tailscale, which has an official package in Package Center: it builds a WireGuard-based private network between the NAS and your team's Macs, exposes nothing publicly, and takes about ten minutes. (Synology's own VPN Server package still has no WireGuard option, so Tailscale fills that gap too.) Whatever you choose, never forward ports 5000/5001 from the internet to your NAS. **Run Security Advisor monthly.** It is built into DSM and catches drift: weak passwords, new services, missing updates. Schedule it and read the report. **This section is also your Cyber Essentials work.** If your business holds or is chasing Cyber Essentials (or fills in cyber insurance questionnaires), a NAS is in scope, and this baseline covers four of the five CE control themes: firewalls, secure configuration, user access control with MFA, and security update management. The snapshot and off-site backup stack in the next sections is what insurers mean when they ask about ransomware recovery. We are [Cyber Essentials Plus certified](/blog/cyber-essentials-plus-why-our-clients-pass-without-scrambling) ourselves, and a NAS configured to this baseline does not raise assessor questions. ### Step by step: hardening checklist 1. Control Panel > Security > Account: enforce 2FA for all users; enable Account Protection. 2. Control Panel > Security > Protection: enable Auto Block and DoS protection. 3. Control Panel > Security > Firewall: allow LAN and VPN subnets, then default-deny. Add a UK-only geo rule if appropriate. 4. Control Panel > Login Portal > DSM: move ports 5000/5001 to high five-digit ports, force HTTPS redirect, enable HSTS. 5. Control Panel > Security > Certificate: issue a Let's Encrypt certificate and set it as default. 6. Control Panel > File Services: disable AFP. Control Panel > Terminal & SNMP: confirm SSH and Telnet are off. 7. Install Tailscale from Package Center for remote access; remove any QuickConnect or port forwarding you no longer need. 8. Open Security Advisor, run a scan, and schedule it monthly alongside a calendar reminder to skim Synology's security advisories. ## File sharing for Macs: SMB done properly **AFP is dead; be precise about how dead.** Apple removed the AFP server from macOS in Big Sur, and deprecated the AFP client in macOS 15.5 with a plain statement that it will be removed in a future version. It still functions in macOS 26 Tahoe, and DSM still ships an AFP service, but Synology's own documentation says to disable AFP and use SMB for Macs. So: disable AFP on the NAS, standardise on SMB3, and if any workflow still touches AFP, migrating it is now a scheduled task rather than a debate. The SMB settings that matter for Mac fleets all live in Control Panel > File Services > SMB, with the interesting ones behind the Advanced Settings button. **Set the protocol floor and ceiling.** Maximum protocol SMB3, minimum SMB2. Nothing on a modern network needs SMB1, and leaving it available is a security hole. **Kill .DS_Store pollution with veto files.** In Advanced Settings, the veto files field accepts a pattern list; enter `/.DS_Store/._*/` to stop Macs writing their metadata droppings onto shares (Windows users and sync tools will thank you). Two gotchas nobody mentions. First, veto only affects new files: existing .DS_Store files become invisible rather than deleted, which can look alarmingly like data loss, so clean up existing dot-files first. Second, every filename on the share is checked against the veto list, so keep the list short or you will slow down the very folder browsing you were trying to fix. **Leave signing on auto, and do not force encryption casually.** Older Mac performance guides tell you to disable SMB signing for speed. As of macOS 26 that advice can break mounts entirely (see the Time Machine section below); leave server signing on Auto. Transport encryption is available and works, but forcing it costs a large slice of throughput, so reserve "force" for genuinely sensitive shares and let clients negotiate elsewhere. **Know that Finder search does not work on Synology shares.** This is the single most common Mac-office complaint, and it is structural: DSM has never shipped Samba's Spotlight search backend, so Finder searches against an SMB share either crawl or quietly return nothing. No settings fix it. The workable alternatives are Synology's Universal Search in the web interface, File Station, or the Synology Drive client, which maintains its own index. And index deliberately: Universal Search indexing on a busy production share creates constant I/O, so index the folders people search and prune the rest. **Watch for filename landmines.** Two classes of trouble. Characters that are illegal over SMB (backslash, colon, asterisk, question mark, quotes, angle brackets, pipe) will fail on copy; creative teams with punctuation-heavy file names hit this weekly. Subtler is Unicode normalisation: macOS composes accented characters differently (NFD) from most other systems (NFC), and files that arrive on the NAS through rsync or Linux tools can show up from a Mac as un-openable or duplicated. Files copied via Finder over SMB are safe; if you sideload with rsync, use `--iconv=utf-8-mac,utf-8`. **Use Windows ACLs, which is the default.** DSM shared folders on Btrfs use Windows ACLs that apply consistently across SMB, File Station and Synology Drive. That is the right model for Mac teams; do not switch shares to plain POSIX permissions. Remember users need both share-level permission and ACL permission to see anything, which is the first thing to check when "I can't open the folder" tickets arrive. ### Step by step: SMB for a Mac fleet 1. Control Panel > File Services > SMB: enable SMB, set maximum protocol SMB3, minimum SMB2. 2. Same screen: disable the AFP service tab entirely. 3. SMB > Advanced Settings > Others: enable opportunistic locking, SMB2 lease and SMB3 durable handles (most are on by default; verify). 4. Advanced Settings: set veto files to `/.DS_Store/._*/`, after sweeping existing dot-files off the shares (`dot_clean` on a Mac, or find-and-delete from File Station). 5. Leave server signing on Auto. Leave transport encryption on client-negotiated except for genuinely sensitive shares. 6. Control Panel > File Services > Advanced: confirm Bonjour discovery is on so shares appear in Finder's sidebar. 7. In Universal Search on the NAS, index only the folders people genuinely search. 8. On Macs, connect via `smb://nas-name.local` or the reserved IP, then drag the share into Login Items for auto-mount. ## Time Machine to the NAS, without the heartbreak Time Machine to a Synology share is the cheapest per-Mac backup there is, and set up carelessly it will absolutely eat your volume and then fail when you need it. Here is the version that survives contact with reality. **Give each Mac its own quota.** Time Machine only prunes old backups when it believes the disk is full, so an uncapped Time Machine share grows until it consumes the volume. Create a dedicated `TimeMachine` shared folder, create one DSM user per Mac (tm-daves-mbp, tm-edit-01), and set a per-user quota on the Btrfs volume sized at roughly 1.5 to 2 times each Mac's drive. Per-user quotas beat one folder-level quota because the first Mac to back up cannot starve the rest. **Broadcast the share to Macs.** Control Panel > File Services > Advanced: enable Bonjour service discovery and "Enable Bonjour Time Machine broadcast via SMB", then set your Time Machine folder under "Set Time Machine Folders". One heads-up: enabling the broadcast quietly switches on several SMB settings (SMB3, opportunistic locking, durable handles) if they were off. That is fine, since you want them anyway, but do not be surprised that your SMB config changed. **Exclude the Time Machine share from snapshots and recycle bins.** Time Machine writes into constantly-churning sparsebundle images. Snapshotting that share bloats your snapshot storage for zero benefit (Time Machine is already versioned), and a recycle bin on it doubles every deletion. Disable both for the Time Machine share specifically. **The macOS 26 Tahoe problem, and the current fix.** Since Tahoe, a wave of Mac users have hit `BACKUP_FAILED_DISCONNECTED_DISK_IMAGE` errors backing up to NAS targets: Tahoe tightened the Mac's SMB client behaviour, and long-running Time Machine sessions get their disk image yanked mid-backup. As of July 2026 Apple has not documented a fix, but the community workaround is stable and we use it on managed fleets: create `/etc/nsmb.conf` on the Mac with settings that pin the protocol and require signing: ``` [default] protocol_vers_map=6 signing_required=yes ``` Then reboot (or unmount and remount the share). Note what this does: it turns signing on. That is a straight inversion of a decade of "disable signing for NAS speed" advice, and it is why we no longer recommend the old speed tweaks. Treat this as a point-in-time workaround, and retest after each macOS update in case Apple changes the behaviour again. **Verify backups, do not trust them.** A backup you have never restored from is a hope, not a backup. Hold Option and click the Time Machine menu bar icon for "Verify Backups" (this works for network destinations), and perform a real test restore of a file per Mac per quarter. **For fleet-grade backup, add Active Backup for Business.** Synology's ABB package backs up Macs centrally, is licence-free, and officially supports macOS 26 Tahoe. The honest caveat: restoring a Mac from ABB is not a Windows-style bare-metal restore; recovery runs through a working macOS install plus Migration Assistant. So the pairing we deploy is ABB as the centralised, IT-controlled fleet backup and Time Machine as each user's self-service file recovery. They cost nothing extra and cover each other's gaps. ### Step by step: Time Machine that keeps working 1. Create a `TimeMachine` shared folder on the Btrfs volume. Disable its recycle bin, and exclude it from any snapshot schedules. 2. Create one DSM user per Mac, in a `timemachine` group with access only to that share. 3. Control Panel > User & Group > (user) > Quota: set each user's quota to 1.5 to 2x that Mac's internal drive. 4. Control Panel > File Services > Advanced: enable Bonjour, enable the Time Machine broadcast via SMB, and set the Time Machine folder. 5. On each Mac: System Settings > General > Time Machine > Add Backup Disk, pick the broadcast share, sign in as that Mac's dedicated user. 6. On macOS 26 Tahoe, deploy the `/etc/nsmb.conf` workaround above if backups fail with disk image disconnection errors. 7. Quarterly: run "Verify Backups" from the Time Machine menu (Option-click) and restore one real file per Mac. 8. Install Active Backup for Business and enrol the fleet as the second, IT-owned layer. ## Ransomware resilience and real backup A NAS is not a backup. If the only copy of your data lives on the Synology, you have centralised your risk, not reduced it. The good news is that Synology's own tooling covers the full 3-2-1 pattern (three copies, two media, one off-site) without third-party licences. **Snapshots are your ransomware undo button.** Install Snapshot Replication and schedule Btrfs snapshots on every business share: hourly during work hours is a sensible default, with Smart Retention keeping hourlies for a day, dailies for a week, weeklies for a month. When a Mac gets compromised and starts encrypting files over SMB, snapshots let you roll the share back to 10:00 this morning in minutes. They are near-free on Btrfs; there is no reason not to run them everywhere except the Time Machine share. **Make some snapshots immutable.** Since DSM 7.2, snapshots can be made immutable for a protection period that nobody, including administrators, can shorten or delete. That "including administrators" is the point: stolen admin credentials are exactly how modern ransomware deletes your snapshots before encrypting. It also cuts the other way, since an immutable snapshot retention set too long will eat volume space with no escape hatch. Start at 7 days on your critical shares, watch consumption for a month, then extend if you have headroom. **Replicate to a second box.** Snapshot Replication to a second Btrfs Synology (in another room, or another site) gives you a warm copy with the whole snapshot history, and failover measured in minutes. Note the target must also be Btrfs, so the bargain ext4-only J-series cannot be your replication target. **Hyper Backup gets a copy off-site.** Point Hyper Backup at Synology C2, Backblaze B2 (via the S3 destination, around $6 per TB per month), or a Synology at another office running Hyper Backup Vault. Enable client-side encryption, and understand what you are signing: the encryption password can never be changed, and losing it makes the backup permanently unrecoverable. Export the encryption key when the task is created and store it in your password manager, not on the NAS it protects. Then enable scheduled backup integrity checks with data verification, and calendar a quarterly test restore. **Maintenance is part of backup.** A UPS connected over USB with Safe Mode set to trigger after a few minutes of outage (the goal is a clean shutdown, not riding out the powercut). Monthly quick S.M.A.R.T. tests, quarterly extended ones. Data scrubbing every three months, which on redundant Btrfs pools detects and repairs silent corruption; note scrubbing needs redundancy, so a Basic or RAID 0 pool quietly loses one of Btrfs's headline benefits. And notifications configured and tested, because every one of these protections is worthless if the drive-failure email goes nowhere. **On rack hardware, use the redundancy you paid for.** If you bought an RP model, plug the two power supplies into different circuits (or a UPS and mains) so a failed PSU or a tripped breaker does not stop the NAS. For a business that cannot tolerate downtime at all, Synology High Availability pairs two identical units as an active/passive cluster over a dedicated heartbeat link: if the active box fails, the passive one takes over in minutes with the same data and address. It needs two matching units and halves your usable capacity, so it is for uptime-critical shops, not every office. And it is resilience, not backup, so you still run the full 3-2-1 stack above. ### Step by step: the protection stack 1. Install Snapshot Replication. Schedule hourly snapshots on business shares with Smart Retention. Exclude the Time Machine share. 2. Enable immutable snapshots on critical shares with a 7-day protection period; review space use after a month. 3. If you have a second Btrfs Synology, configure Snapshot Replication to it on at least a daily schedule. 4. Install Hyper Backup; create an encrypted backup task to C2, Backblaze B2, or an off-site Vault. Export the encryption key to your password manager immediately. 5. Enable scheduled integrity checks with data verification on the Hyper Backup task. 6. Connect a UPS: Control Panel > Hardware & Power > UPS, Safe Mode after 3 to 5 minutes. 7. Storage Manager: schedule monthly quick and quarterly extended S.M.A.R.T. tests, plus data scrubbing every 3 months. 8. Calendar a quarterly restore test: one file from snapshots, one from Hyper Backup. Twenty minutes that validates the entire stack. ## 10GbE for Macs: the end-to-end version This is where Mac creative businesses feel the biggest gains, and where the internet's advice is thinnest. A 10GbE link is ten times gigabit on paper; whether you see even half of that depends on every link in the chain: NAS port, switch, cable, Mac interface, and the drives behind it all. **The NAS end.** Covered in the buying section, but to recap: most RackStations have 10GbE built in (dual ports across the xs range, and from the 12-bay RS Plus up), which is a big part of why rack is the business default. On desktop the fork is sharper: DS925+ cannot do 10GbE at all; DS1525+ takes the E10G22-T1-Mini module; DS1825+ takes full PCIe cards (dual SFP+ or 10GBASE-T, including a combo card that adds NVMe slots). SFP+ with DAC cables or transceivers runs cooler and cheaper at short range; 10GBASE-T (RJ45) reuses familiar copper cabling. Either is fine for an office; just pick one ecosystem and match the switch. **The Mac end.** Every current Mac Studio has 10GbE built in. Mac mini offers it as a build-to-order option (order it that way; it cannot be added later). MacBooks need a Thunderbolt adapter, and the Sonnet Solo10G, OWC Thunderbolt 10G, and QNAP QNA-T310G1T all deliver about 9.4Gbps real-world. One important distinction: those are Thunderbolt adapters. Cheap USB Ethernet adapters run Apple's built-in class drivers, often top out well below 10GbE, and usually cannot do jumbo frames, which matters in a moment. **The middle.** Cat6a cable for 10GBASE-T runs (Cat6 only manages 10GbE to about 55 metres; Cat6a does 100). For switches, small businesses generally land on the UniFi Aggregation (8 SFP+ ports), the UniFi Flex XG (10GbE RJ45, fanless, office-friendly), or QNAP's QSW range. Server-room switches like the Netgear XS508M work but sound like it. **The real bottleneck: the drives.** A 10GbE network can move roughly 1,100 MB/s. A half-filled 4-bay array of spinning drives delivers perhaps 400 to 800 MB/s sequential, and far less on small files. If your transfers plateau around those numbers while iperf3 shows 9.4Gbps, the network is fine; the spindles are the ceiling. Fixes, in order of value: more drives in the array, an all-NVMe volume for active projects (compatibility-list drives only, remember), and only then SSD caching. On that last point, an NVMe read cache barely helps video editors, because large sequential ProRes reads bypass the cache's strengths; cache shines on small-file churn like thumbnails and project indexes. For a video team, two NVMe drives as a fast working volume beats the same drives as cache almost every time. **SMB Multichannel and LACP: pick one, and probably pick neither.** DSM 7.2+ supports SMB3 Multichannel (Control Panel > File Services > SMB > Advanced Settings > Others), but it requires separate NICs with individual IPs and is mutually exclusive with link aggregation, so a bonded LACP pair must be unbonded to use it. Meanwhile macOS's multichannel support defaults to failover rather than aggregation, picking the single fastest link, and reliability reports on Apple Silicon remain mixed. LACP, for its part, never speeds up a single client; it only helps many clients in aggregate. The honest recommendation for a Mac office: give the NAS and the heavy Macs one fast 10GbE link each and skip the link-combining cleverness entirely. ### Step by step: 10GbE rollout 1. Confirm the NAS supports 10GbE (see the buying section) and fit the module or card. 2. Wire the NAS and heavy-workstation Macs into a 10GbE switch with Cat6a (or SFP+/DAC). 3. MacBooks get Thunderbolt 10GbE adapters, not USB ones. 4. Prove the network first: run iperf3 between a Mac and the NAS (install it on the NAS via Container Manager with host networking, otherwise you benchmark Docker's NAT instead of the NIC). Expect around 9.4Gbps. 5. Then test real SMB copies with a large file. 700 to 1,100 MB/s means everything is working against a fast array; 400 to 800 MB/s with clean iperf3 means the drives are the ceiling, not the network. 6. If the array is the bottleneck: add spindles or move active projects to an NVMe volume before touching any network tuning. ## Jumbo frames and MTU 9000: the honest version Every 10GbE guide eventually says "enable jumbo frames", and most hand-wave the details. We have tested MTU 9000 on real all-wired Mac-to-Synology networks, and the honest answer has two halves: on a segment you fully control, the speed difference is real and worth having. On a mixed network, it is the fastest way to break file sharing in ways that are miserable to diagnose. **What it is.** Standard Ethernet frames carry 1,500 bytes (MTU 1500). Jumbo frames raise that to 9,000, meaning fewer packets and less per-packet overhead for bulk transfers. On paper, free performance. **What we see in practice.** In our own testing on fully wired 10GbE segments, jumbo frames deliver a substantial jump in sustained SMB throughput on large files, which is exactly the workload creative teams care about. Published benchmarks are contradictory (some show single-digit gains, some show MTU 9000 slower than 1500), and the difference is usually the network being tested: the benefit collapses the moment any hop in the path is misconfigured. **Why we still tell mixed offices to leave it alone.** The failure mode is uniquely horrible: MTU must match on the NAS and every Mac, and every switch in the path must pass large frames. One forgotten 1500 device produces the classic mixed-MTU signature: pings work, small files copy, and large transfers hang or die silently. Wi-Fi clients are permanent 1500 hops. Most USB Ethernet adapters on Apple Silicon cannot do jumbo at all. And if a spinning-drive array is your bottleneck, jumbo frames speed up the part that was not the problem. **When it is worth it.** A fully wired, fully inventoried segment you completely control, where the NAS and the 10GbE Macs move very large sequential files all day. If that is you, the gain justifies the setup discipline. Here is how to do it properly, in the only order that avoids cutting yourself off: 1. Switch first. Enable jumbo frames on the switch (UniFi: Settings > Networks, Jumbo Frames toggle, which sets 9216). Switch MTU only needs to be greater than or equal to the endpoints, so 9216 against endpoint 9000 is correct, not a mismatch. 2. NAS second: Control Panel > Network > Network Interface > select the 10GbE interface > Edit > "Set MTU value manually" > 9000. Fair warning: applying this restarts network services and drops active SMB sessions, so do it out of hours. 3. Macs last: System Settings > Network > select the 10GbE service > Details > Hardware > Configure: Manually > MTU: Custom > 9000. Or from Terminal: `networksetup -setMTU en0 9000` (substitute your interface). 4. Now verify, and note the Mac-specific trap: the textbook test everyone copies from Linux guides, `ping -D -s 8972 `, fails on macOS with "message too long" even when jumbo frames are working perfectly, because macOS caps raw ping payloads at 8,192 bytes. Use `ping -D -s 8184 ` instead; if that returns replies with the don't-fragment flag set, your path is passing jumbo frames. 5. Re-run iperf3 and a real large-file copy. On a properly configured all-wired segment you should measure a clear improvement on sustained transfers. If you did not, something in the path is still at 1500: find it, or set everything back to 1500 rather than living with a half-converted network. ## The condensed checklist For the version you can run down in a maintenance window: **Day one:** named admin only, QuickConnect skipped, SHR + Btrfs, per-team shares with recycle bins, groups-based permissions, DHCP reservation, auto-updates on, notifications tested. **Security:** 2FA enforced for all, Auto Block + Account Protection + DoS protection on, firewall default-deny with LAN/VPN allows, ports changed with HTTPS + HSTS forced, Let's Encrypt certificate, AFP/NFS/FTP/Telnet off, Tailscale for remote access, Security Advisor scheduled. **Mac sharing:** SMB3 max / SMB2 min, veto files for .DS_Store, signing on Auto, Bonjour on, Universal Search indexing pruned, ACL + share permissions both checked. **Time Machine:** dedicated share, one DSM user and quota per Mac, broadcast via SMB enabled, snapshots and recycle bin off for that share, Tahoe nsmb.conf workaround where needed, quarterly verify and restore test, ABB alongside. **Protection:** hourly snapshots with Smart Retention, immutable snapshots (7 days) on critical shares, replication to a second Btrfs box, encrypted Hyper Backup off-site with the key in your password manager, UPS + S.M.A.R.T. + scrubbing scheduled, quarterly restore drills. **Networking:** RackStation with built-in 10GbE for most businesses (desktop DS1525+ or DS1825+ where there is no rack, never the DS925+ for 10GbE), Thunderbolt adapters for MacBooks, iperf3 before blaming anything, drives upgraded before networks tuned, jumbo frames on segments you control end to end (they are worth it there) and 1500 everywhere else. If you would rather hand the whole thing to people who do this weekly, this is exactly the kind of [infrastructure work](/services/infrastructure-architecture) we do for Mac-based businesses across London: design, [security hardening](/services/enterprise-security), migration off ageing servers, and the ongoing management that keeps a NAS boring. [Get in touch](/contact) and we will take a look at what you are running. ### Okta vs Entra ID vs Google vs JumpCloud: Choosing an Identity Provider for a Mac-First Business in 2026 URL: https://stabilise.io/blog/okta-vs-entra-id-vs-google-vs-jumpcloud-mac-idp-comparison-2026 Published: 2026-07-03T00:00:00.000Z Category: apple-mdm-security Pick your identity provider by how it treats the Mac login window, not by the SSO feature grid. Every vendor on this page can put a login box in front of Salesforce. Only some of them can put your company credentials on the Mac itself, and the gap between them is wide. Here is the short version. Microsoft Entra ID is the default answer for Microsoft 365 shops: Platform SSO is generally available, deploys through Intune or Jamf Pro, and the licence is already inside Business Premium. Okta has the strongest security ceiling of the four, with Secure Enclave-backed Platform SSO and phishing-resistant FastPass, but the Mac login piece lives in Okta Device Access, which is quote-priced. Google has no Platform SSO extension at all, so Google Workspace shops need a bridge like Jamf Connect. And JumpCloud skips Apple's framework entirely, bundling directory, MDM, and the Mac login into one agent at a published price. The rest of this post is the evidence, from vendor documentation and from fleets we run. ## The 2026 landscape in one paragraph Entra ID is the volume player: if your business runs Microsoft 365, you already own it, and Microsoft has spent two years making it a genuinely good Mac citizen. Okta is the vendor-neutral choice with the deepest device trust story on macOS, priced accordingly and sold in suites. Google is a strong identity platform with mature passkey support that has simply never shipped the Mac login piece. JumpCloud is the consolidator, aimed at smaller teams that want directory, SSO, MFA, and Mac management from one console and one invoice. We compared the broader field, including OneLogin, Ping, and the open-source options, in our [identity platform showdown](/blog/identity-management-platform-showdown-which-sso-and-iam-solution-works-best-for-uk-businesses). This post is the Mac-first cut of that decision. ## Why the Mac login window is the real test For years, Macs had a split personality problem. The Mac password and the identity provider password were two different things that drifted apart, and IT spent its life explaining which one to type where. Apple's fix is Platform SSO, a framework that lets an identity provider live at the macOS login window itself. Sign in to the Mac, and you are signed in to everything. Done properly it also means MFA happens before the desktop appears, not after. macOS 26 Tahoe made setup smoother during Automated Device Enrolment, and macOS 27 goes further this autumn with a web-based login window and Touch ID by policy. We covered the mechanics in [Platform SSO on macOS 27](/blog/platform-sso-macos-27-mac-login-without-microsoft). That is why the IdP question looks different on a Mac fleet. The evaluation is not "does it do SAML", they all do. It is four sharper questions: 1. Can it drive the Mac login window through Platform SSO? 2. Does it federate with Apple Business Manager for Managed Apple Accounts? 3. What does MFA feel like on Apple hardware, day to day? 4. What does it cost once you include the Mac pieces? ## Which identity providers support Platform SSO on macOS? | | Platform SSO | Modes | What it needs | Status | |---|---|---|---|---| | **Microsoft Entra ID** | Yes, first party | Secure Enclave key, smart card, or password sync | Company Portal app, deployed via Intune or Jamf Pro, macOS 13+ | Generally available | | **Okta** | Yes, first party | Desktop Password Sync or Secure Enclave keys | Okta Device Access, Identity Engine, Okta Verify, macOS 14+ on Apple silicon | Shipping; Secure Enclave mode added 2026 | | **Google Workspace** | No | Bridge via Jamf Connect, XCreds, or similar | Third-party tool plus MDM | No first-party extension | | **JumpCloud** | Sidesteps it | Agent manages the local account; JumpCloud Go for web SSO | JumpCloud agent, enrolled device | Shipping | **Microsoft** is furthest along. Platform SSO for macOS with Entra ID is [generally available](https://techcommunity.microsoft.com/blog/microsoft-entra-blog/now-generally-available-platform-sso-for-macos-with-microsoft-entra-id/4437424), with three authentication methods, and registration during Automated Device Enrolment went GA as well, so a new Mac can come out of the box already bound to Entra. You do not need Intune to use it; the configuration deploys from Jamf Pro just as happily, which is how we ship it. **Okta** treats the Mac as a first-class device, but through a paid door. Platform SSO lives inside [Okta Device Access](https://help.okta.com/oie/en-us/content/topics/oda/macos-pw-sync/about-psso.htm) and requires Identity Engine, Okta Verify, and Apple silicon on macOS 14 or later. The interesting move came this year: [Secure Enclave-backed keys](https://www.okta.com/blog/product-innovation/okta-platform-sso-macos-secure-enclave/), which drop password sync entirely in favour of hardware-bound credentials. On macOS 26 Tahoe, Okta can also insert itself into Setup Assistant during Automated Device Enrolment, so the very first thing a new starter sees is an Okta sign-in. Authenticate first, provision second. **Google** is the surprise gap. There is no Google Platform SSO extension, no roadmap statement, nothing. If you want Google credentials at a Mac login window, a bridge tool does the work: Jamf Connect or the open-source XCreds put a Google-backed login screen on the Mac and keep the local password in sync. This works fine, we run it for clients, but it is an extra agent and, in Jamf Connect's case, an extra licence. When someone claims "we're a Google shop so identity is sorted", the Mac login window is the part that is not. **JumpCloud** answers a different question. Its agent creates and manages the local macOS account directly, so the JumpCloud password simply is the Mac password, and JumpCloud Go adds hardware-backed, phishing-resistant sign-in to web apps using Touch ID. No Platform SSO required, because JumpCloud is also the directory and the MDM. That consolidation is the whole pitch. ## What about Managed Apple Accounts and Apple Business Manager federation? Managed Apple Accounts used to be something you could mostly ignore. Not any more. Apple keeps attaching things to them: device enrolment, app licensing, iCloud controls, activation lock recovery, and now the management switches for Apple Intelligence. Federation is what makes them usable at scale, because staff sign in to their Managed Apple Account with the same credentials as everything else, and accounts appear automatically instead of being hand-created. Apple Business Manager federates natively with **Microsoft Entra ID** and **Google Workspace**, and Apple opened the door to everyone else with custom identity provider support built on OIDC for sign-in, SCIM for directory sync, and the OpenID Shared Signals Framework for security events. **Okta** [documents the full integration](https://help.okta.com/oie/en-us/content/topics/apps/configure-apple-business-manager.htm): federated authentication, automatic Managed Apple Account provisioning from Okta directory data, and Okta notifying Apple when something security-relevant happens to an account. You need Single Sign-On, Universal Directory, and Lifecycle Management on the Okta side. The practical read: all four platforms can live with Apple Business Manager, but Entra and Google get there with the least configuration, and Okta's version is the most capable once set up because the SCIM sync and security signals come with it. ## What does MFA feel like day to day? Feature lists hide the thing users notice most: what happens at every single sign-in. **Okta FastPass** is the strongest experience we have deployed. We recently enforced it across a 110-person AI company, on a customer-driven deadline, in under two weeks. The credential is generated and held in the Mac's Secure Enclave, released only by Touch ID, and cryptographically bound to the Okta tenant. There is no code to type, no push prompt to fat-finger approve, and nothing for a phishing page to capture. We removed TOTP, SMS, and standalone push as acceptable factors entirely, and 196 Google and GitHub identities landed on NIST AAL3. The full write-up is in [the case study](/case-studies/phishing-resistant-mfa-okta). **Microsoft** has closed most of the gap. Authenticator now holds device-bound passkeys, FIDO2 security keys are mature, and on a Mac with Platform SSO the Secure Enclave key means the login window itself is doing phishing-resistant authentication before the desktop loads. The everyday experience for a Business Premium shop is Touch ID and the occasional Authenticator prompt, which is a long way from the code-typing era. **Google** was earliest to passkeys and it shows: enrolment is smooth, Safari and Chrome on macOS both cooperate, and Titan keys slot in for high-risk roles. The weakness is not the factor, it is that the strong factor only guards the browser session. Without the login window piece, the Mac itself is still protected by whatever local password the user chose. **JumpCloud Go** is genuinely phishing-resistant, hardware-bound, and pleasant to use. One concrete quirk from the field: it requires the Mac's onboard Touch ID sensor, so it does not work with the lid closed on a docked laptop. If your office is full of clamshell-mode MacBooks driving external displays, your users will meet that limitation in week one. One UK note: Cyber Essentials requires MFA on cloud services, and any of these four clears that bar. The phishing-resistant options clear it with room to spare, and they are what customer security questionnaires increasingly ask for by name. Whichever you pick, plan the recovery path before enrolment day; we wrote up why [passkey rollouts fail on recovery, not cryptography](/blog/enterprise-passkey-rollout-fails-on-recovery-not-cryptography). ## Pricing in 2026 List prices in July 2026, per user per month, from vendor pricing pages. USD where no UK list price is published. Treat all of these as starting points; identity vendors negotiate. | | Entry price | What the Mac login really costs | Watch for | |---|---|---|---| | **Microsoft Entra ID** | P1 at $6, P2 at $9 | Nothing extra. Included in Microsoft 365 Business Premium (roughly £18 per user on UK list) | Conditional Access needs P1; you likely own it already | | **Okta** | Starter suite from $6, Essentials from $17 | Device Access sits in the quote-priced Professional and Enterprise suites | Annual billing only; the headline $6 does not include the Mac pieces | | **Google Workspace** | Identity included with Workspace; Cloud Identity Premium $6 standalone | A Jamf Connect or similar licence on top, since there is no first-party option | The bridge tool is the hidden line item | | **JumpCloud** | SSO $11; full Platform $19; Platform Prime $24 | Included, because the agent is the login | Per-user cost looks high until you cancel the separate MDM | Three observations from quoting these for real fleets. **Entra ID is close to free for most UK SMEs.** Business Premium is already on the bill, which is why "we'll just use Entra" is the default answer we hear. **Okta's public pricing understates a Mac-first deployment.** The capabilities in this post are exactly the ones behind the quote wall. Make sales put the Device Access number in writing. **JumpCloud's sticker shock fades when it replaces two or three other products.** And returns if it does not. ## Which one should you pick? **Already on Microsoft 365: use Entra ID.** This holds even if Jamf runs your Macs; Platform SSO deploys from Jamf Pro, and the identity layer and the MDM layer are separate decisions. We covered that split in [Jamf Pro vs Intune vs iru](/blog/jamf-pro-vs-microsoft-intune-vs-iru-apple-mdm-comparison-2026). Turning on what Business Premium already includes beats paying twice for a second IdP you do not yet need. **On Google Workspace: keep Google as the IdP and add a bridge.** Jamf Connect or XCreds gives you the login window Google never shipped. If security requirements outgrow that, the move is not to rip out Google, it is to put Okta in front of it. That is exactly what the client in [our MFA case study](/case-studies/phishing-resistant-mfa-okta) did: Google Workspace stayed, Okta became the front door, and every app inherited phishing-resistant MFA overnight. **Security-led, contract-driven, or heading into compliance: Okta.** When a customer contract says phishing-resistant MFA and means it, FastPass plus Secure Enclave Platform SSO is the deepest device trust story on macOS today. You pay for it, and for regulated or high-value environments it is worth paying for. **Under about 50 staff with no MDM and no directory: JumpCloud.** One agent, one console, one invoice, and the Mac login handled without Apple's framework. The trade-off is concentration: identity, device management, and MFA all fail together if the relationship sours, so weigh that against the simplicity. ## The honest caveats Platform SSO in any flavour wants properly enrolled, MDM-managed Macs, and on current Okta it wants Automated Device Enrolment specifically. It is not a BYOD story. It also has sharp edges at the OS boundary. Apple's macOS 15.4 update broke Okta Device Access enrolment until an Okta Verify fix landed, which is a good reminder that whoever owns your Macs needs to be watching both vendors' release notes, not just one. And none of this removes the need for a recovery plan. Strong authentication that locks out your own staff is just an outage with better cryptography. If you are staring at this decision for your own fleet, this is work we do week in, week out: [how we approach an Okta rollout](/projects/okta-implementation-rollout), and what a wider [identity and access project](/projects/identity-access-management) looks like. Or skip ahead and [talk to us](/contact) about which of the four fits your stack. We will tell you if the answer is the one you already own. ### Platform SSO on macOS 27: one login for the Mac and everything else, no Microsoft required URL: https://stabilise.io/blog/platform-sso-macos-27-mac-login-without-microsoft Published: 2026-06-29T00:00:00.000Z Category: apple-mdm-security There is a quiet lie running underneath most Mac fleets. Staff log in to their Mac with one password, sign in to Google or Microsoft 365 with another, and IT crosses its fingers that the two stay in step. They never quite do. Someone changes their work password on Monday, their Mac keeps asking for the old one, and by Wednesday there is a ticket and a reset and ten minutes nobody gets back. Platform SSO was Apple's answer to that, and it has been sitting in macOS since Ventura. It was good in theory and awkward in practice, the kind of feature you read about and filed under "later." macOS 27 is the release that makes it worth turning on. It moves Platform SSO into Apple's modern management model, lets your identity provider take over the actual Mac login screen, and, the part most coverage misses, none of it needs Microsoft. Here is what changed, the exact keys, and why an Apple-first business can run this with the tools it already has. ## The two-password problem Think about what a login really proves. When someone types their password into the macOS login window, the Mac checks it against a local account stored on that device. That is all it knows. It has no idea whether that person is still employed, whether their cloud account is locked, or whether the password matches the one they use for email. The Mac login and the company identity are two separate worlds that happen to share a string of characters. That gap is where the friction lives. Passwords drift out of sync. Offboarding means disabling the cloud account and then separately remembering to deal with the Mac. Multi-factor authentication protects your email and your SaaS apps but stops at the Mac's front door, so the most privileged session on the device, the local login, is often the one with the weakest check on it. Platform SSO closes the gap by tying the local macOS account to your identity provider. The password becomes the IdP password. The login becomes a real identity event. And from macOS 27, that event can happen at the login window itself, with your provider's own multi-factor flow, before the desktop loads. ## What Platform SSO really does The core idea is registration. The device registers with your identity provider, then the user registers, and from then on the Mac and the IdP share a trusted relationship. How the user proves themselves after that depends on the mode you choose. Per [Apple's deployment guide](https://support.apple.com/guide/deployment/platform-sso-for-macos-dep7bbb05313/web), the main ones are: - **Password sync.** The local Mac password and the IdP password become one. Change it in either place and the other follows. This is the gentlest path and the easiest to explain to staff, because nothing about the login looks different, it just stops drifting. - **Secure Enclave key.** The Mac generates a hardware-bound key in the Secure Enclave and uses that to authenticate, so after setup the user is not really typing a synced password at all. This is the passwordless end of the spectrum. - **Web-based.** The new one. macOS renders your identity provider's actual sign-in page in a secure web view, which means whatever MFA your IdP already enforces, including QR code sign-in, works at the Mac. Whichever mode you pick, the win is the same. One identity, one set of credentials, one place to disable when someone leaves. It is the Mac finally behaving like a managed endpoint of your identity platform instead of an island with its own keychain of local accounts. It is fair to say this is among the most important things Apple has shipped for the enterprise, and the Apple-admin press has been arguing exactly that for a while. ## What macOS 27 changed Three changes turn Platform SSO from "interesting" into "configure it this summer." **It moved into Declarative Device Management.** Platform SSO and the broader Extensible SSO settings now live in a new declaration, [`com.apple.configuration.extensible-sso`](https://support.apple.com/guide/deployment/identity-integration-updates-dep956785e70/web), confirmed in Apple's WWDC26 identity integration notes. This matters for the same reason it mattered for [binary control and the new privacy framework](/blog/macos-27-mdm-binary-control-pppc-replacement-mac-admins): the device holds the declaration and keeps itself in that state, rather than the server pushing a profile and hoping it sticks. SSO config that used to be one of the more brittle things to deploy becomes self-enforcing. **The login window can authenticate against your IdP.** When you configure `UserCreation.NewUserAuthenticationMethods` with `OpenID`, macOS displays a web view that renders your identity provider's sign-in form at the login window, the Lock Screen, and FileVault unlock. It supports multi-step and multi-factor flows and QR code sign-in. You also get `WebAuthentication.URLAllowList` to pin the domains that view may load, `WebAuthentication.AllowPasswordSync` to keep the local password in step, and `Policies.OfflineGracePeriod` to set how many days a user can still log in locally before the Mac insists on a fresh IdP check. That last key matters: it is the difference between a device that bricks itself on a train with no signal and one that stays usable for a sensible window. **Touch ID is enforceable.** Two new keys, `RequireTouchID` and `RequireTouchIDOrWatch`, let you make biometric authentication a policy rather than a per-user preference. Apple-admin coverage from [Jamf](https://www.jamf.com/blog/wwdc26-key-takeaways-for-apple-admins/) and [ManageEngine](https://www.manageengine.com/mobile-device-management/articles/wwdc-2026-apple-admins-mdm-changes.html) both call this out, because "everyone has Touch ID on" stops being a hope and starts being a control you can attest to in an audit. There is a smaller change worth noting too: Authenticated Guest Mode now extends to FileVault-protected Macs, which clears a long-standing snag for shared and loaner devices where encryption and guest access used to fight each other. ## You do not need Microsoft for this Read most Platform SSO guides and you would think it is a Microsoft feature. Page after page assumes Entra ID and Intune. That is because Microsoft writes a lot of documentation, not because it is a requirement. Platform SSO is built into macOS and configured through MDM. It is identity-provider agnostic. All it needs is an app containing an SSO extension that is compatible with your IdP, and the major providers all ship one: Microsoft Entra, Okta, Google, and Jamf's own connector among them. The OS does the heavy lifting. Your MDM delivers the declaration. Your IdP supplies the extension and the sign-in page. For the businesses we work with, that is the whole point. A creative studio on Google Workspace, an architecture practice on Okta, a startup that never bought into the Microsoft stack: all of them can have IdP login at the Mac login screen, with MFA, managed through [Jamf](/blog/jamf-pro-vs-microsoft-intune-vs-iru-apple-mdm-comparison-2026) and the identity platform they already pay for. We run Jamf as our default and we are Apple specialists rather than Apple-only, so we test these declarations the same way regardless of whether a client's identity lives in Google, Okta or Entra. Okta is where a lot of this work lands for us in practice. We recently put phishing-resistant MFA across a client's entire Google and GitHub access in under two weeks, enforced at the Okta layer with hardware-bound Okta Verify and a biometric on every sign-in, the same Secure Enclave and Touch ID that Platform SSO leans on. The full write-up is in [our phishing-resistant MFA case study](/case-studies/phishing-resistant-mfa-okta), and [how we approach an Okta rollout](/projects/okta-implementation-rollout) sets out the method. If you are still deciding which identity platform to standardise on, our [SSO and IAM showdown](/blog/identity-management-platform-showdown-which-sso-and-iam-solution-works-best-for-uk-businesses) is the place to start, and the good news is that Platform SSO works with all the serious options on that list. ## The honest caveats This is genuinely good, and it is not free of sharp edges. The biggest one is recovery. The moment your Mac login depends on your identity provider, the resilience of that login depends on the resilience of the IdP and the recovery paths around it. A locked-out user, an IdP outage, a staff member whose phone with the authenticator app just went in the Thames: these are the scenarios that decide whether a rollout feels solid or fragile. This is the same lesson we wrote up for passkeys, where [the whole programme lives or dies on recovery, not the cryptography](/blog/enterprise-passkey-rollout-fails-on-recovery-not-cryptography). Set your `OfflineGracePeriod` deliberately, keep a tested break-glass local admin account, and decide your lockout process before you enforce, not after the first ticket. Two smaller ones. IdP extensions move at different speeds, so confirm your specific provider supports the macOS 27 web-login features and not just classic Platform SSO before you build on them. And FileVault plus the new login window deserves real testing in a pilot, because the unlock-then-login sequence is exactly the kind of flow that behaves perfectly on your machine and surprises you on the tenth. ## What to do before the autumn macOS 27 follows Apple's usual rhythm, a summer beta and general availability in the autumn, so there is a clean runway. Here is the order we are working through: 1. **Pin down your identity provider's support.** Check that your IdP's SSO extension covers the macOS 27 web-login window and QR sign-in, not just the older modes. This decides what is on the table. 2. **Pilot password sync first.** It is the lowest-drama mode and it solves the most common pain, the drifting password, on day one. Get that working in a pilot ring before reaching for passwordless or login-window web auth. 3. **Design recovery before enforcement.** Break-glass admin account, a sane `OfflineGracePeriod`, and a written lockout procedure. Test it by deliberately locking someone out. 4. **Layer it into your baseline.** Touch ID by policy and IdP-backed login both map onto [our Mac security baseline guidance](/blog/mac-security-baselines-ncsc-cis-uk-businesses) and give you cleaner answers when an auditor asks how device login is protected. The short version: macOS 27 turns Platform SSO from a feature you kept meaning to look at into one that earns its place, and it does it without dragging you into a management stack you did not choose. Pilot it over the summer, get recovery right, and you walk into the autumn with one identity from the Mac login screen outward. This is the kind of rollout we plan and run for clients as standard. If you want IdP-backed Mac login in place cleanly before macOS 27 lands, [that is what we do](/services/apple-it-support-london). ### macOS 27 changes how Macs are managed: binary control is in, PPPC is out URL: https://stabilise.io/blog/macos-27-mdm-binary-control-pppc-replacement-mac-admins Published: 2026-06-15T00:00:00.000Z Category: apple-mdm-security Two things changed for Mac management at WWDC 2026, and both are a bigger deal than the headlines made them sound. The first: you can now tell a Mac exactly which programs are allowed to run, command-line tools included. If it is not on the list, the operating system stops it. The second: PPPC, the privacy profile every Mac admin has wrestled with for years, is being retired in favour of something far simpler. Neither got much attention next to the Siri news. But if you run a fleet of Macs, these two are the changes that will land on your desk. Here is what they are, in plain terms, and what to do before macOS 27 ships in the autumn. ## The Mac finally gets proper application control For years there has been an awkward gap between iPhones and Macs. On a supervised iPhone you could hand an admin a clean allow list of apps, and nothing else would run. On a Mac you got blunt instruments: Gatekeeper, which only cares whether an app is signed and notarised, and a clumsy "allow apps downloaded from" setting that offered App Store, known developers, or anywhere. Real application allowlisting meant buying a third-party tool and bolting it on. macOS 27 closes that gap. Apple has added native binary control through the [Endpoint Security framework](https://www.jamf.com/blog/wwdc26-key-takeaways-for-apple-admins/), driven by two new keys in the device management schema: `AllowedBinaries` and `DeniedBinaries`. You declare what is permitted, and the OS enforces it. The detail that matters is how it matches. Per [Apple's own deployment guide](https://support.apple.com/guide/deployment/depd567c9ffa/web), binaries are identified by CD Hash, Team ID, or signing ID. So you can be as broad or as tight as you like: - **Team ID** allows everything signed by one developer. Trust Adobe, get every Adobe tool. - **Signing ID** narrows it to a specific application from that developer. - **CD Hash** pins one exact build, down to the cryptographic fingerprint. Nothing else passes, not even a different version of the same app. And it is not limited to apps you double-click. It covers binaries, which means command-line tools too. That is the part the old controls never touched. A script kiddie's downloaded `curl` one-liner, a rogue binary dropped in `/tmp`, an unsanctioned developer tool: if the build is not on your allow list, it does not execute. This is the layer that techniques like [ClickFix](/blog/clickfix-mac-attack-staff-running-malware-uk-businesses) lean on, where the user is tricked into running a command by hand, so closing it off at the OS matters. You are not starting from zero, either. There is an `AlwaysAllowManagedApps` key that automatically permits the apps you already deploy through MDM, so your managed software keeps running without being listed by hand. And this same declaration replaces that old "allowed from" source restriction, folding App Store, identified developers, and the rest into one unified policy instead of a separate toggle. For a regulated business this is the line that opens doors. Application allowlisting is something auditors ask about directly. ManageEngine maps the new control to [NIST SP 800-53 and ISO 27001:2022](https://www.manageengine.com/mobile-device-management/articles/wwdc-2026-apple-admins-mdm-changes.html) software-integrity requirements. Until now, ticking that box on Mac meant extra spend on a dedicated product. From macOS 27 it is a native declaration, defined once, enforced by the operating system. A word of caution before anyone gets excited and locks everything down on a Friday afternoon. An allow list is only safe if it is complete. Miss a legitimate tool your finance team runs once a quarter, and you will hear about it at the worst possible moment. This is a feature you roll out in deny-nothing reporting mode first, watch what really runs, then tighten. We will come back to that. ## PPPC is dead, long live the privacy framework If you have ever managed Macs, you know the pain of PPPC. Privacy Preferences Policy Control was the profile you built so that Zoom could see the camera, your backup tool could read the disk, and your RMM agent could control the screen, all without the user being nagged to approve each one. It worked, but it was fiddly, easy to get wrong, and every app needed its own carefully formatted entry. macOS 27 retires it. In its place is a declarative privacy framework built on a new `Privacy` key, and it works the way PPPC always should have. There are two halves to it, both confirmed in [Apple's app management guide](https://support.apple.com/guide/deployment/depd567c9ffa/web): **For apps**, the `Privacy` key lives in `com.apple.configuration.app.settings` (iOS 27, iPadOS 27 and macOS 27). One key, one place, and it covers Accessibility, Bluetooth, Camera, Dictation, Local Network, Location, Location Accuracy and Microphone. You pre-set the permissions an app should have, and the user gets a single consolidated consent prompt rather than a drip-feed of separate dialogs. **For websites**, the same idea now reaches Safari. The `Privacy` key in `com.apple.configuration.safari.settings` lets you set Camera and Microphone permissions per domain, or by wildcard domain. If your team lives in a browser-based video tool or a web app that needs the mic, you can grant it cleanly across the fleet instead of leaving each person to fumble through Safari's site settings. The old way is officially on the way out. Apple's guide states the corresponding keys in `com.apple.TCC.configuration-profile-policy` are **deprecated in iOS 27, iPadOS 27 and macOS 27**. Deprecated is not removed, so your existing PPPC profiles will keep working through this cycle. But Apple has shown its hand. The new keys are where everything goes from here. The user-facing win is real, too. Prompt fatigue is a genuine security problem. When people are trained by years of pop-ups to click "Allow" on autopilot, they will allow the wrong thing eventually. One clear, admin-shaped consent screen beats ten guesses. ## This all rides on Declarative Device Management Both of these features share a foundation, and it is worth naming. Declarative Device Management, or DDM, has been Apple's modern management protocol for a few years, but it lived alongside the old profile-push model as a sort of preview. At WWDC 2026 Apple moved it to [the standard](https://www.jamf.com/blog/wwdc26-key-takeaways-for-apple-admins/). Binary control, the new privacy framework, credential handling, health reporting: every major announcement this year is built on it. The practical difference with DDM is that the device does the work. Instead of the server pushing a profile and hoping it sticks, the Mac holds a set of declarations and keeps itself in that state, reporting back when something changes. It is faster, more reliable, and it scales without hammering the MDM server. A few other macOS 27 changes land on the same foundation and are worth a mention: - **Software finally uninstalls cleanly.** A new `UninstallBehavior` key with a `Remove` option means deleting an app's declaration genuinely removes the app, closing a long-standing gap where pulling a config left the software sitting on the device. - **Credentials are declared once.** You define a certificate or credential a single time, and your DNS proxy, VPN, SSO and content filter configs all reference it. Rotate it once, and everything that depends on it follows, instead of editing every profile by hand. - **Hardware health reporting** arrives for iPhone and iPad through a new `device.system.health` status item, surfacing the genuineness and status of components like the baseband, camera, Face ID, Touch ID, NFC and Ultra-Wideband. Useful for spotting tampered or failing devices before they are redeployed. If you want the source straight from Apple, the WWDC session [What's new in managing Apple devices](https://developer.apple.com/videos/play/wwdc2026/206/) walks through the lot. ## What to do before the autumn macOS 27 follows Apple's usual rhythm: a public beta over the summer, general availability in the autumn. That gives you a clear runway, and the worst plan is to do nothing and meet these changes for the first time when staff devices start updating. Here is the order we are working through, and the order we would suggest for any managed fleet: 1. **Get the beta into a pilot ring now.** A handful of non-critical Macs on the macOS 27 beta, enrolled in your MDM, so you can see the new declarations in your console and test before anything real depends on them. 2. **Turn on binary visibility before enforcement.** Watch what runs across the pilot group first. Build your allow list from real data, not from a guess about what people use. Only then switch from reporting to blocking. 3. **Migrate your noisiest PPPC apps first.** Pick the three or four apps that generate the most permission prompts and rebuild them on the new `Privacy` key. You will feel the benefit immediately and learn the workflow on low-risk targets. 4. **Check your MDM is keeping pace.** These are native Apple declarations, so any current MDM will get them, but vendors expose new keys at different speeds. Confirm your platform supports the macOS 27 schema before you rely on it. If you are weighing platforms anyway, our [Jamf vs Intune vs Iru comparison](/blog/jamf-pro-vs-microsoft-intune-vs-iru-apple-mdm-comparison-2026) is a good starting point. 5. **Fold it into your security baseline.** Binary control and the privacy framework both map onto the controls in [our Mac security baseline guidance](/blog/mac-security-baselines-ncsc-cis-uk-businesses), and both help on the compliance side. Document them as part of your standard build. The short version: macOS 27 hands Mac admins two tools they have wanted for years, native application control and a privacy model that is not a fight to configure. They are genuinely good changes. They are also the kind that bite if you flip them on without testing. Pilot over the summer, build from real data, and you walk into the autumn ready instead of reacting. This is the sort of platform shift we plan and roll out for clients as a matter of course. If you run Macs and want the new controls in place cleanly before macOS 27 lands, [that is what we do](/services/apple-it-support-london). ### We Couldn't Buy the Board We Needed, So We Designed Our Own PCB with Claude Code URL: https://stabilise.io/blog/fusb302b-usb-c-pd-breakout-pcb-claude-code Published: 2026-06-12T00:00:00.000Z Category: labs There is a moment in every hardware project that never stops being magic: the courier hands you a box, and inside is a physical object that was an idea a few weeks ago. This week that object was our first ever circuit board, and it exists because the board we needed cannot be bought right now. This is also the first post in **Stabilise Labs**, where we write up the experiments and side-quests behind our main work. Expect fewer polished case studies and more honest build logs, mistakes included. ## Why an IT company is designing circuit boards We are building a piece of hardware for [BlankState](https://blankstate.io), our ITAD SaaS platform: an automatic DFU device. The idea is simple to describe and fiddly to build. Plug a single USB-C cable into a Mac or iOS device's DFU port, and the device on the other end puts the machine into DFU mode. DFU matters in IT asset disposition because it is the lowest-level restore state Apple hardware has. If you are erasing and reprovisioning hundreds of Apple silicon Macs, getting each one into DFU is the gate every machine passes through, and Apple's manual route involves a second Mac, Apple Configurator and a key-combination dance with precise timing. BlankState already removes most of that pain. DFU Prep is built into the app: connect the target Mac to the host machine running BlankState, click Place in DFU Mode, and the machine reboots straight into DFU, ready for batch wiping. One click instead of a finger ritual, repeated for as many Macs as you can hand over the desk.