macOS

macOS Security Settings: Complete Protection Guide

This guide will help you fully configure macOS security settings: from basic options to disk encryption and app permission controls. You'll gain complete control over your data protection.

Updated at February 17, 2026
10-15 minutes
Easy
FixPedia Team
Применимо к:macOS 12.0 (Monterey) and abovemacOS Ventura 13.0+macOS Sonoma 14.0+

Introduction / Why This Matters

macOS includes powerful built-in tools to protect your data and privacy. Properly configuring these settings prevents unauthorized access to your information, blocks malicious software, and gives you control over which apps can use your camera, microphone, or location. After completing this guide, you will be able to:

  • Protect your data if your Mac is lost or stolen using FileVault.
  • Control which apps can connect to the internet (firewall).
  • Manage permissions for your camera, microphone, and other services.
  • Restrict the launch of unsigned apps via Gatekeeper.

Requirements / Preparation

Before you begin, ensure:

  1. You have a Mac running macOS 12.0 (Monterey) or later (the interface and setting names may differ slightly on older versions).
  2. You are logged in with an administrator account (required to change system security settings).
  3. You have a stable internet connection (for downloading updates and synchronizing FileVault keys).
  4. You have created a backup of important data (e.g., via Time Machine) before enabling disk encryption.

Step-by-Step Instructions

Step 1: Open the Security & Privacy Pane

System security settings are gathered in one place:

  1. From the Apple menu (☰) in the top-left corner, select System Settings (or "System Settings" in the English version).
  2. In the settings list, find and click Security & Privacy.
  3. To make changes, click the lock icon in the bottom-left corner of the window and enter an administrator password.

⚠️ Important: Some settings (like enabling FileVault) require a restart. Ensure you have saved all open documents.

Step 2: Configure General Security Settings

The General tab contains key options:

  • Automatic system updates: Enable to let macOS install security updates automatically.
  • Allow apps downloaded from: Select App Store and identified developers — this enables Gatekeeper, which verifies app digital signatures. The Anywhere option disables this protection and is not recommended.
  • Require password: Set an interval (e.g., "immediately") after which macOS will request a password when waking from sleep or the screensaver.
  • Show password hints: Enable to see password hints during entry (convenient but less secure).

Step 3: Enable and Configure the Firewall

The firewall blocks incoming network connections, protecting against remote attacks.

  1. Navigate to the Firewall tab.
  2. Click Turn On Firewall.
  3. For fine-tuning, click Firewall Options:
    • Block all incoming connections: Enable only for maximum protection (e.g., on public networks), but this may disrupt network services (file sharing, game servers).
    • Automatically allow signed software to receive incoming connections: Leave this enabled.
    • Allow incoming connections for: Here you can add specific apps permitted to accept connections (e.g., a game client or file-sharing service). Click + and select the app from the /Applications folder.

Step 4: Activate FileVault for Disk Encryption

FileVault encrypts the entire system disk, protecting data at the physical level.

  1. In the FileVault tab, click Turn On FileVault.
  2. Choose a recovery method:
    • Use iCloud to unlock your disk and reset your password: The key will be linked to your Apple ID. Convenient, but requires iCloud access.
    • Create a recovery key: You will receive a 24-character key. Write it down and store it in a safe place (not on the same Mac!). If you forget your password and lose the key, your data cannot be recovered.
  3. The encryption process will begin. Duration depends on disk size and system activity. You can continue working, but performance may decrease slightly.
  4. After completion, restart your Mac. On startup, the system will request your user password to decrypt the disk.

💡 Tip: If multiple users are on the Mac, FileVault must be enabled separately for each (or use a shared recovery key).

Step 5: Configure Privacy Permissions

This tab controls app access to your personal data.

  1. Navigate to the Privacy tab.
  2. Select a category from the left list:
    • Camera: Grant access only to trusted apps (FaceTime, Zoom, Teams). Disable others.
    • Microphone: Similarly, only allow necessary programs.
    • Location Services: Disable entirely or select apps that require geolocation (maps, navigation).
    • Contacts, Calendars, Photos, and others: Review the app list and remove unnecessary entries.
  3. To add an app to the list, click + below the apps list and select the executable (usually in /Applications).

Step 6: Additional Settings (Optional)

  • System Integrity Protection (SIP): Enabled by default; do not disable without specific cause.
  • Remote Management/Apple Events: Disable if you do not use remote management.
  • Analytics & Improvements: Your choice.

Verification

Ensure your settings are working:

  1. Firewall: Try connecting to your Mac from another computer on the network (e.g., via ssh or file sharing). The connection should be blocked unless an exception exists for that service.
  2. FileVault: After restarting, the system should ask for a password before loading the OS. In FileVault, the status should show "Encryption Completed".
  3. Permissions: Launch an app you denied camera access to (e.g., Skype). It should show a permission error or simply not detect the device.
  4. Gatekeeper: Try running an app from an unknown source (downloaded outside the App Store). A warning should appear.

Potential Issues

Issue: Cannot enable FileVault, message "Not enough space for encryption"

Solution: FileVault requires free disk space (approximately 1/3 of the disk volume). Free up space by deleting unnecessary files, or use an external disk for temporary data storage.

Issue: App does not request camera/microphone permission, even though enabled in settings

Solution: Some apps use custom drivers or require permission within their own internal settings. Check the app's documentation. Also, ensure the app has a checkmark in the Privacy settings list.

Issue: Firewall blocks a legitimate network app, and I don't know how to add an exception

Solution: In Firewall Options, click + and add the app's executable (usually in /Applications). If the app has already attempted to connect, it will appear in the list automatically — just uncheck the block.

Issue: After enabling FileVault, Mac is very slow to boot/run

Solution: On the first boot after enabling encryption, the system may run slower. Allow 1-2 hours for background encryption to complete. If the issue persists, check if the disk is overloaded (via Activity Monitor) and ensure sufficient free space.

Issue: Cannot change "General" settings (grayed out)

Solution: Click the lock icon in the bottom-left corner and enter an administrator password. If that doesn't work, settings may be managed via policies (MDM) on a work or school Mac — contact your administrator.

F.A.Q.

How to enable the firewall on macOS?
What is FileVault and why should you enable it?
How to manage app permissions for camera and microphone?
Why does macOS block apps from unknown sources?

Hints

Open the Security & Privacy pane
Configure general security settings
Enable and configure the firewall
Activate FileVault for disk encryption
Configure privacy permissions
FixPedia

Free encyclopedia for fixing errors. Step-by-step guides for Windows, Linux, macOS and more.

© 2026 FixPedia. All materials are available for free.

Made with for the community