MDM and Configuration Profiles for Mac Hardening
How MDM, Automated Device Enrollment, supervision, configuration profiles and Declarative Device Management fit together to enforce a macOS security baseline.
Most controls described on this site can be set by hand on a single Mac. Doing the same across hundreds of machines, keeping them set, and proving that they are set is a different problem. Mobile Device Management (MDM) is Apple's supported answer. This guide explains how MDM works on macOS, how enrollment types affect what you can enforce, how configuration profiles are structured, where Declarative Device Management fits, and how to verify what is actually applied on a Mac.
What MDM is on macOS
MDM is a protocol built into macOS. The Mac trusts an MDM server after enrollment, and the server sends commands (install a profile, lock the device, install an update, query inventory) through the Apple Push Notification service. The Mac wakes up, contacts the server, and processes queued commands. The MDM server can be a commercial product or an open-source project; the client side is always Apple's built-in agent.
MDM does not give the server arbitrary code execution. It can only do what the protocol and payloads allow. Organizations that need scripts or package installation usually add a management agent delivered by the MDM, which is a separate trust decision.
Enrollment types
How a Mac is enrolled determines which controls are available.
| Enrollment type | How it happens | Supervised | Typical use |
|---|---|---|---|
| Automated Device Enrollment (ADE) | Mac is assigned in Apple Business Manager or Apple School Manager and enrolls during Setup Assistant | Yes | Organization-owned Macs |
| Device enrollment, user-approved | User installs an enrollment profile and approves it in System Settings | No | Existing Macs not in Apple Business Manager |
| Account-driven or User Enrollment | Managed Apple Account signs in; work data is separated from personal data | No | Personally owned Macs (BYOD) |
Automated Device Enrollment and supervision
When an organization buys Macs through Apple or a participating reseller, the serial numbers appear in Apple Business Manager or Apple School Manager and can be assigned to an MDM server. On first boot, or after an erase, Setup Assistant contacts Apple, discovers the assignment and enrolls the Mac automatically. Macs enrolled this way are supervised, and the enrollment can be made non-removable by the user.
ADE is the foundation of a durable baseline: a Mac that is erased re-enrolls on next setup, so wiping it does not escape management. It also lets the MDM configure the Mac before the user reaches the desktop.
User-approved MDM
Some payloads are considered privileged, including kernel and system extension policies and Privacy Preferences Policy Control (PPPC). macOS only honors them when the enrollment is user-approved, which ADE satisfies automatically. For manual enrollments, the user must approve the MDM profile in System Settings. A Mac that is "enrolled" but not user-approved will silently ignore these payloads.
Bootstrap token
On Apple silicon and T2 Macs, MDM can escrow a bootstrap token. It lets the MDM grant Secure Tokens to accounts, authorize software updates and approve certain kernel extension changes without a local volume owner typing credentials. It is closely related to the FileVault guide and the software updates guide.
Configuration profiles
A configuration profile is a property list, usually with the .mobileconfig extension. The outer dictionary describes the profile; the PayloadContent array holds one or more payloads, each configuring one area.
| Key | Where | Purpose |
|---|---|---|
PayloadType | Outer and each payload | Configuration for the outer profile; a reverse-DNS type such as com.apple.security.firewall for payloads |
PayloadIdentifier | Outer and each payload | Stable reverse-DNS identifier; installing a profile with the same identifier replaces the old one |
PayloadUUID | Outer and each payload | Unique identifier; generate with uuidgen |
PayloadVersion | Outer and each payload | Format version, normally 1 |
PayloadDisplayName | Outer and each payload | Human-readable name shown in System Settings |
PayloadScope | Outer | System or User on macOS |
PayloadContent | Outer | Array of payload dictionaries |
A minimal profile enabling the Application Firewall with stealth mode:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>PayloadContent</key>
<array>
<dict>
<key>PayloadType</key>
<string>com.apple.security.firewall</string>
<key>PayloadIdentifier</key>
<string>com.example.baseline.firewall.payload</string>
<key>PayloadUUID</key>
<string>REPLACE-WITH-UUID-1</string>
<key>PayloadVersion</key>
<integer>1</integer>
<key>EnableFirewall</key>
<true/>
<key>EnableStealthMode</key>
<true/>
</dict>
</array>
<key>PayloadDisplayName</key>
<string>Baseline - Firewall</string>
<key>PayloadIdentifier</key>
<string>com.example.baseline.firewall</string>
<key>PayloadScope</key>
<string>System</string>
<key>PayloadType</key>
<string>Configuration</string>
<key>PayloadUUID</key>
<string>REPLACE-WITH-UUID-2</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</plist>
Validate syntax before distribution:
plutil -lint baseline-firewall.mobileconfig
Signing profiles
Signing a profile lets macOS show who issued it and detects tampering in transit. MDMs usually sign automatically. To sign a hand-built profile with a certificate from your keychain:
security cms -S -N "Your Signing Certificate Name" \
-i baseline-firewall.mobileconfig \
-o baseline-firewall-signed.mobileconfig
Signing does not make a profile more privileged. Privilege comes from how it is delivered: through a user-approved or supervised MDM enrollment.
Manual installation limits
Since macOS 11 Big Sur, double-clicking or scripting a profile install only stages it; the user has to approve it in System Settings. Privileged payloads such as PPPC still require MDM delivery. For anything beyond a lab machine, deliver profiles through MDM.
A baseline payload map
The payloads below cover most of the controls on this site. Configure keys conservatively and test on a pilot group first.
| Area | Payload type | Guide |
|---|---|---|
| FileVault enforcement | com.apple.MCX.FileVault2 | FileVault |
| Recovery key escrow | com.apple.security.FDERecoveryKeyEscrow | FileVault |
| Application Firewall | com.apple.security.firewall | Firewall and pf |
| Encrypted DNS | com.apple.dnsSettings.managed | Firewall and pf |
| Gatekeeper | com.apple.systempolicy.control | Gatekeeper and XProtect |
| Privacy pre-approvals | com.apple.TCC.configuration-profile-policy | TCC and privacy |
| System extensions | com.apple.system-extension-policy | SIP and platform integrity |
| Managed login items | com.apple.servicemanagement | Logging and detection |
| Passcode policy | com.apple.mobiledevice.passwordpolicy | Accounts and privileges |
| Restrictions | com.apple.applicationaccess | Various |
| Software updates | com.apple.SoftwareUpdate (legacy) | Software updates |
For a complete, tailored set built from recognized baselines, the NIST macOS Security Compliance Project can generate profiles for you; see the mSCP and CIS benchmarks guide.
Declarative Device Management
Traditional MDM is imperative: the server sends a command, the device executes it, and the server polls to learn the result. Declarative Device Management (DDM), supported on macOS 13 Ventura and later, changes that model. The server sends declarations describing the desired state, and the Mac applies and maintains them autonomously, reporting changes back through a status channel.
Declarations come in four kinds:
- Configurations: settings to apply, such as software update enforcement or passcode policy. Legacy profiles can also be wrapped in a configuration.
- Assets: supporting data, such as credentials or documents, referenced by configurations.
- Activations: rules that decide when configurations apply, optionally with predicates.
- Management: organization information and server capabilities.
For hardening, DDM matters most for software update enforcement, status reporting and reliability. The Mac enforces state even if it cannot reach the server, and the server learns about drift without polling. Apple continues to move new management features to DDM and has deprecated several legacy MDM mechanisms, so expect your baseline to become more declarative over time.
Choosing an MDM
Commercial options widely used for Macs include Jamf Pro, Microsoft Intune, Mosyle and Addigy, among others. Open-source projects include MicroMDM and NanoMDM, which provide the core MDM protocol and suit teams comfortable building their own tooling, and Fleet, which combines device management with osquery-based visibility. Evaluate candidates on DDM support, speed of supporting new macOS releases, PPPC and system extension handling, bootstrap token escrow, and reporting.
Verify it
# Enrollment state
profiles status -type enrollment
# Show installed configuration profiles (run as root for system scope)
sudo profiles show -type configuration
# Show the Automated Device Enrollment configuration from Apple
sudo profiles show -type enrollment
On a correctly enrolled organization-owned Mac, the status output looks like:
Enrolled via DEP: Yes
MDM enrollment: Yes (User Approved)
You can also review installed profiles in System Settings > General > Device Management. If a Mac assigned in Apple Business Manager missed enrollment during setup, sudo profiles renew -type enrollment prompts it to fetch the enrollment again.
Common pitfalls
- Unapproved enrollments. Privileged payloads are silently ignored without user-approved MDM. Check
profiles statuson every new Mac. - Reusing UUIDs or identifiers across unrelated profiles. Identical identifiers replace each other. Keep identifiers unique and stable.
- Conflicting profiles. Two profiles managing the same key produce unpredictable results. Keep one owner per setting.
- Removable MDM on company Macs. Configure ADE so users cannot remove enrollment.
- No bootstrap token escrow. Without it, updates and account token management on Apple silicon require local credentials.
- Profiles without testing. A bad restrictions or PPPC profile can break workflows fleet-wide. Pilot first.
Checklist
- Organization-owned Macs in Apple Business Manager or Apple School Manager, assigned to an MDM, enrolled via ADE, supervised and non-removable.
- Bootstrap token escrowed.
- Baseline profiles signed, linted, uniquely identified and piloted.
- DDM used for software update enforcement where supported.
- Enrollment and profile state verified during onboarding and monitored continuously.