Hi,
We discovered this during a compliance security review of our macOS rollout, and wanted to raise it here, partly as a question and partly as a feature request for the future.
We know that local users cannot remove or fully disable XFENCE on macOS, which is good. However, we found that the "Advanced…" option in XFENCE Preferences. which appears grayed out in the UI can actually still be clicked and used to edit the XFENCE configuration locally (e.g. adding custom policy rules) by any local user with on the machine.
Our understanding was that a grayed-out control should mean the setting is locked/managed centrally and not editable locally…but in practice, local users are still able to modify the XFENCE configuration this way.
Is this expected behavior, or are we misunderstanding how the "grayed out" state is supposed to work here? If it is expected, we'd like to submit this as a feature request: local XFENCE configuration editing (via the Advanced rule editor) should be blocked/locked entirely when the setting is managed centrally, similar to how the rest of the client's protections cannot be disabled locally.
Anyone else seeing the same issue? Shouldn't there be better tamper protection on macOS devices?
Br.
kimloh