Skip to main content
Question

Limit Terminal access to admin only

  • November 6, 2025
  • 2 replies
  • 34 views

e080241
Forum|alt.badge.img+1

I have been tasked by our security team to limit the terminal app to only allow admin accounts to open it due to a vulnerability. Any suggestions or best practices/advice on this? I do not want to rescrict the app completely because we use it for troubleshooting but we want the standard user to be locked down as much as possible. 

2 replies

AJPinto
Forum|alt.badge.img+26
  • Legendary Contributor
  • 2802 replies
  • November 6, 2025

This is something your security team should be doing with an Endpoint Permissions Manager tool. You can block list the application with a Jamf app restriction, but that is all or nothing. If they want this to be granular they will need to onboard a tool (if one does not already exist) that can do this.


mattjerome
Forum|alt.badge.img+7
  • Jamf Heroes
  • 88 replies
  • November 6, 2025

You should also then look into blocking apps like iTerm. That would be an easy work around for any developer. Maybe a better tactic is to block sudo access or make people standard users.