Apple Business User Guide
- Welcome
-
-
-
- Intro to Configurations
-
- AirDrop configuration
- AirPlay configuration
- AirPrint configuration
- App Access configuration
- Apple Intelligence & Siri configuration
- Application Layer Firewall configuration
- Certificate configuration
- Content Caching configuration
- Custom configuration
- Data Management configuration
- Energy Saver configuration
- FileVault configuration
- Gatekeeper configuration
- iCloud configuration
- Lock Screen configuration
- Password and Screen Unlock configuration
- Software Update configuration
- VPN configuration
- Web Clip configuration
- Web Filter configuration
- Wi-Fi configuration
- Edit a configuration
- Apply Blueprints
-
- Glossary
- Document revision history
- Copyright and trademarks

Create a Gatekeeper configuration in Apple Business
macOS includes a technology called Gatekeeper, which is designed to help ensure that, by default, only trusted software runs on a user’s Mac. Trusted software refers to apps that have been signed by the App Store or signed by a registered developer and notarized by Apple. Both the App Store review process and the notarization pipeline are designed to ensure that apps contain no known malware. Sometimes using even a benign app triggers the loading of a malicious plug-in without the user’s knowledge. Gatekeeper protects against the distribution of these malicious plug-ins. Sometimes plug-ins are automatically loaded alongside an app. To avoid loading a possibly malicious plug-in, Gatekeeper opens those apps from randomized, read-only locations.
In Apple Business, sign in with a user whose role is Organization Administrator.
To view roles and permissions, see Intro to roles and permissions.
In your browser, choose Devices > Configurations > All Configurations.
Select All Configurations, select Add
next to Gatekeeper
, then enter a name for the configuration.Select one of the following:
Allow apps from the App Store: Select to allow only apps that have been downloaded from the App Store.
App Store and identified developers: Select to allow only apps that have been downloaded from the App Store and from developers identified by Apple.
Apps from anywhere: Select to allow any apps to launch on the Mac, regardless of where they originated.
Choose whether to allow a user to use the contextual menu in the Finder to open an app that Gatekeeper would prevent.
Select Save.