Skip to main content

macOS Profiles

SureMDM empowers IT administrators to configure and distribute individual or multiple profiles to enrolled macOS devices, offering a versatile approach to customization. The profiles can be deployed to the devices based on system and user levels.

note

macOS profiles will be supported only for Premium and Enterprise licenceses.

Supported Enrollment Types for macOS Profiles

When creating an macOS profile in SureMDM, administrators must first select the Enrollment Type, which determines how the device will be managed and which configurations are applicable. The available enrollment types are described below:

Enrollment TypeDescription
Device Enrollment and Automated Device EnrollmentThis enrollment type enables complete device management and control, making it ideal for corporate-owned devices. Administrators can enforce organization-wide policies and configure device settings, applications, and restrictions across the entire device.
User EnrollmentUser Enrollment is designed for personal (BYOD) devices where only work-related data and applications are managed. This approach protects user privacy by keeping personal data separate from organizational management while still allowing administrators to enforce required policies for corporate resources.

alt text

Channel Types

Device Channel - This is a default profile. For this User Profile should be disabled. When a profile is deployed on the enrolled macOS device(s), it gets applied to all users of a device irrespective of whether they have logged into the device or not.  

User Channel - To enable User Profile on the SureMDM console, navigate to Profiles > macOS and select User Profile. Once enabled, when a profile is deployed on the enrolled macOS device(s), it gets applied to a specific managed user who has currently logged into the device.

alt text

note

For example, consider a scenario where a macOS device is shared between two users: user1 is a managed user, while user2 is not managed. If the User Profile is applied to the device and user2, who is currently logged in, does not have a managed profile, the applied profile will enter a "Pending" state. To learn more about various job statuses, you can click here.

The macOS profiles supported for User/ System levels are given in the table below. 

SettingsDevice ChannelUser Channel
Restriction ProfileYesYes
Blocklist/Allowlist AppsYesYes
Application PolicyYesYes
Wi-Fi ConfigurationYesYes
Certificate ProfileYesYes
Passcode PolicyYesYes
Mail Configuration--Yes
Exchange ActiveSync--Yes
File VaultYes--
Privacy Preferences Policy ControlYes--
Content Caching SettingsYes--
Software UpdateYesYes
Directory ProfileYesYes
Web Content FilterYesYes
Firewall ProfileYes--
VPNYesYes
Mac Security (Gatekeeper Settings)YesNo
System ExtensionsYesNo
DNS ConfigurationYesNo
Energy SaverYesNo
Contact SettingsNoYes
Font ManagementYesYes
AirPrint ConfigurationYesYes
Disk ManagementYesNo
Safari SettingsNoYes
Safari BookmarksNoYes
Safari ExtensionsNoYes
Software Update ManagementYesNo