The goal of the latest version of Defense Against Configurations from ThreatLocker is simple. It makes security vulnerabilities visible in macOS so they can be fixed before they are exploited. Following the release of DAC for Windows in August 2025, ThreatLocker has launched DAC for macOS, which is currently in Beta.
See also: Don't put a camera cover on your MacBook

Misconfigurations are a gift to attackers: default settings that are left open, remote access that should be disabled (such as outdated network protocols like SMB v1), or encryption that was never enabled.
The built-in ThreatLocker feature scans Macs up to four times a day using the existing ThreatLocker agent, highlighting dangerous or non-compliant settings in the same control panel you already use for Windows.
The agent performs a configuration scan and reports the results to the console. On macOS, the initial Beta focuses on high-value checks:
– FileVault disk encryption status
– Built-in firewall status
– Sharing and remote access settings, including remote login
– Local administrator accounts and participation controls
– Automatic update settings
– Gatekeeper and application source controls
– Selected security and privacy preferences that reduce the attack surface
See also: iPad Pro, MacBook Pro and Vision Pro receive updates from day one

Findings are grouped by endpoint and by category. Each item includes clear remediation instructions and mapping to major frameworks such as CIS, NIST, ISO 27001 , and HIPAA. The intention is to shorten the path from discovery to remediation, not add another alert queue.
Design firms, media studios, and production teams often base their workflows on Macs for good reason. M-series processors are powerful, quiet, and efficient for video and design software. But security visibility doesn’t always come with it.
Expanding configuration scanning to macOS helps these teams find vulnerabilities before they are exploited, such as unencrypted disks, disabled firewalls, residual administrator accounts, or permissive sharing settings. It closes the gaps that attackers seek and gives administrators the same level of visibility they already rely on for Windows.
See also: AI Browser Dia becomes available to Mac users

This Beta isn’t just about macOS coverage. It’s about giving IT and security teams real visibility into where they stand. When DAC shows a Mac out of compliance, it connects those findings to ThreatLocker policies that can fix them. This visibility helps organizations align with their security frameworks, meet insurance requirements, and harden their environments without the guesswork. Some users come to ThreatLocker specifically because of DAC, and they stay because it makes other ThreatLocker controls make sense. Visibility into configuration is the gateway to real control.
