Help with configuration of MacBook Firewall Settings

I was wondering if anyone in the community or the Apple support team has experience on how to properly configure the firewall settings on a Mac to make it resistant against unauthorized access including airdrop, ssh, remote access, remote scripting which are enabled by default on my brand new Mac.


Below is a screenshot of how my Mac is currently configured which has led to several phishing attacks, unwanted shortcuts installed, remote scripting found and more.


Ideally knowing which of the incoming incoming connection types to turn off and leave on would be appreciated as I don't use airdrop, remote access, Automator nor shortcuts.


[Edited by Moderator]

MacBook Air (M4, 2025)

Posted on Aug 16, 2026 3:27 PM

Reply
Question marked as Top-ranking reply

Posted on Aug 16, 2026 7:41 PM

The concerns you describe are unrelated to the macOS application firewall, so as MrHoffman alluded to you would be best served by posting a brand new question with a descriptive title expressing those concerns.


Prior to posting that new question, I recommend downloading and running EtreCheck and including its report. Instructions are here: How to use the Add Text Feature When Posting Large Amounts of Text, i.e. an Etrecheck Report - Apple Community. Should you choose to do that please follow those instructions with care. It's ok to include a link back to this Discussion if you think it would be useful.


You can of course continue this Discussion, but a brand new question with zero replies always elicits more interest on this site. Besides, the title with its reference to the macOS application firewall is already answered: it conveys little to no benefit, except for certain circumstances in which a Mac is used in a shared network environment e.g. a dormitory or communal living. Unless you know of and can articulate justification for using the macOS application firewall I recommend just turning it off.


Moreover, it does absolutely zip to thwart phishing attacks, which at their core require nothing more technologically sophisticated than an email or even a phone call. On that subject I highly recommend reading MrHoffman's User Tip Better Securing Your Data, and Apple Account. From a consumer device security standpoint Macs are effectively impenetrable, while human beings remain the abundant, soft and lucrative target they have always been.


As for your specific questions, I suggest relying upon "Malwarebytes" or things like it is inappropriate and inconsistent with safe computing practices. Correlating phishing attacks with access to sensitive files will require more research. EtreCheck is likely to suggest answers to your other questions.

20 replies

Aug 19, 2026 2:04 AM in response to John Galt

Didn't have a chance to try Etracheck yet but today pretty much confirmed my Mac is beyond compromised.


Unfortunately I don't even have the ability to enable FileVault which goes to MrHoffman's point:


"Disk encryption is automatically enabled in all T2 and Apple silicon Macs, and you will have undoubtedly had FileVault enabled to use a better password for that encryption"


---------


The timing and pattern is what's interesting to see as I logged in today for the first time in a while on a fresh install for a business meeting regarding resetting access level credentials and logins for several websites and domains and despite having stolen device protection enabled, a recovery key and advanced data protection, I couldn't encrypt nor enable FileVault.


What's even more interesting is immediately after my meeting ended I went to the Apple support site and the chat member asked for my Mac's serial and then said he couldn't book me a Genius Bar appointment and needed to first speak to his supervisor and assigned me a case #.


This happened about a week ago as well so I knew it was a bit off as the real Apple support team is always far more helpful and professional.


After logging out I did a clean install and once again it loaded do not disturb settings and a bunch of extensions.


Seeing how this continues to persist strictly whenever I use my Mac, I decided to instead use the official iPhone support app afterwards and booked myself an appointment this week to have the Apple Genius Bar take a look at it.


Hopefully they can replace the hard drive as it seems you are all correct that it is far beyond any sort of remediation at this point from an internal hard drive point of view.


Thank you all again for your input and feedback, it's been of great assistance.

Aug 19, 2026 8:45 AM in response to Techguru45

Techguru45 wrote:
Didn't have a chance to try Etracheck yet but today pretty much confirmed my Mac is beyond compromised.
Unfortunately I don't even have the ability to enable FileVault which goes to MrHoffman's point:
"Disk encryption is automatically enabled in all T2 and Apple silicon Macs, and you will have undoubtedly had FileVault enabled to use a better password for that encryption"
---------
The timing and pattern is what's interesting to see as I logged in today for the first time in a while on a fresh install for a business meeting regarding resetting access level credentials and logins for several websites and domains and despite having stolen device protection enabled, a recovery key and advanced data protection, I couldn't encrypt nor enable FileVault.
What's even more interesting is immediately after my meeting ended I went to the Apple support site and the chat member asked for my Mac's serial and then said he couldn't book me a Genius Bar appointment and needed to first speak to his supervisor and assigned me a case #.
This happened about a week ago as well so I knew it was a bit off as the real Apple support team is always far more helpful and professional.
After logging out I did a clean install and once again it loaded do not disturb settings and a bunch of extensions.
Seeing how this continues to persist strictly whenever I use my Mac, I decided to instead use the official iPhone support app afterwards and booked myself an appointment this week to have the Apple Genius Bar take a look at it.
Hopefully they can replace the hard drive as it seems you are all correct that it is far beyond any sort of remediation at this point from an internal hard drive point of view.
Thank you all again for your input and feedback, it's been of great assistance.


None of which is clear evidence of a compromise.

Aug 19, 2026 9:11 AM in response to MrHoffman

What I've shared has just been the tip of the iceberg unfortunately.


I haven't even been able to connect and log into basic apps half the time as it would freeze and lock up, Apple put it in diagnostic mode again last night as well.


Below is just a few screenshots of the issues and "glitches" I've had to deal with since December since buying the Mac.


Also to combat the attempts of hacking I placed screen time settings on my account to disallow airdrop, shortcuts, changes to accounts and passcode and somehow the hackers found a way to make my son the admin of my computer as a workaround to hack into my machine and make me a standard user.



Screenshots below.



Aug 19, 2026 6:42 PM in response to steve626

You are the one individual so far that identified the true area of apples security weakness which is out of my control. - "My son being part of my family iCloud which is linked to my Mac."


I made a separate post on this forum on the above topic and how Apple can solve and fix this problem so it may be worth checking out.


To answer your question however - No, initially I bought my Mac with a completely separate business Apple ID over the phone with an Apple rep to ensure it would not be tied to my personal iCloud and family sharing account for the obvious reasons stated in this thread.


Apple's business team still sold me the Mac tied to that business Apple ID and only after my hard drive failed I found out through their tech team that Apple business IDs aren't compatible with iCloud and was forced to use my personal iCloud if I wanted to use my Mac.


So given the above, I'm wondering if anyone has ever created a separate Apple ID for work in order to not commingle the two?


Since Apple won't patch the loophole in the family sharing feature I'm pretty much left with the option of just choosing a different brand for my work device at this point.





Aug 19, 2026 6:48 PM in response to Techguru45

Techguru45 wrote:
So given the above, I'm wondering if anyone has ever created a separate Apple ID for work in order to not commingle the two?

Yes! Absolutely! I know MANY people at my employer who have done exactly that to avoid any co-mingling of family or personal accounts and items. It's very common and I'm surprised your employer did not require you to do that. Just create a separate Apple ID that you use for your business stuff, and completely isolate it from your personal Apple ID and everything connected to it.


My employer does not even allow an employee's family members to use the work computer for anything, in any way.

Help with configuration of MacBook Firewall Settings

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.