# Create Profiles Last updated: August 14, 2026 This page explains how to create MDM profiles to enforce policies and restrictions on managed devices across Android, iOS/iPadOS, macOS, Windows, and tvOS platforms. It covers the step-by-step profile creation process, how to modify or copy existing profiles, and moving profiles to Trash for clean-up. Best practices for grouping policies and guidance on handling conflicting settings across multiple profiles are also included. Profiles are created to impose one or more policies and restrictions to the managed devices/groups. You need to create separate MDM profiles for devices of different OS types and versions. This is to implement/associate policies with the devices. Follow the steps mentioned below to create a profile. 1. On the Mobile Device Management web console, navigate to **Profiles**. 2. Profiles can be created for various platforms, including **Android, iOS/iPadOS, macOS, Windows, and tvOS**. Select the desired platform to proceed with creating a profile tailored to its specific requirements. ![Create Profile - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/create_profile.png) 3. Provide the below mentioned basic information: 1. **Name of the Profile**: Unique name to identify the profile 2. **Description:** A brief description about the profile. 3. **Applicable for (Only for Android):** For Android Management Devices, select the **Android Device Policy app** option to create profiles. For all other Android devices, choose the **MDM Profile** option to create a profile. 4. **Profile Type (Only for Android):** You can select the profile type as either an MDM Profile or an [OEMConfig Profile](https://www.manageengine.com/mobile-device-management/help/app_management/mdm_oemconfig.html). **Android Profile creation:** ![Create Android Profile - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/create_android_profile.png) **iOS Profile creation:** ![Create Ios Profile - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/create_iOS_profile.png) 4. Click **Continue.** Under **Configure Profile** from the left pane, select the configuration profile ([iOS/iPadOS](https://www.manageengine.com/mobile-device-management/help/profile_management/ios/mdm_configuration_profiles.html) / [Android](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_configuration_profiles_for_android.html) / [Windows](https://www.manageengine.com/mobile-device-management/help/profile_management/windows/mdm_configuration_profiles_for_windows.html)) and define the policies and restrictions of the profile. You will have to **save the individual configurations** before you move on to the next configuration within the same profile. ![Create Android Profile Details - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/create_android_profile_details.png) 5. After specifying the required configurations, click **Publish.** ![Create Android Profile Publish - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/create_android_profile_publish.png) To create the next profile, go to **Profiles** and click **Create Profile**. Select the required OS platform, then follow the steps outlined above to create additional profiles for different platforms. ![Create Second Profile - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/create_second_profile.png) ![Created Profile - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/created_profile.png) A published profile is not applied to any of the devices until they are associated to the [devices](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_associating_profiles_to_devices.html) or [groups](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_associating_profiles_to_groups.html). ## Associating multiple profiles to the same device Let us assume you are associating two profiles to the same device: **Profile 1**: Restricts camera and sets minimum passcode length as 4 **Profile 2**: Allows camera and sets minimum passcode length as 6 Let us see how the profiles get applied on the devices: | PLATFORM | DESCRIPTION | CAMERA | MINIMUM PASSCODE LENGTH | |---|---|---|---| | iOS | Most secure combination of settings get applied | Restricted | 6 | | Windows | Most secure combination of settings get applied | Restricted | 6 | | Android | Most recent profile settings get applied | Allowed | 6 | ## Modify a profile To modify a profile, 1. On the web console, navigate to **Device Mgmt >** **Profiles.** 2. Here you can view the list of all the profiles that have been created already. 3. Click on the ellipsis icon under the **Actions** column, of the profile that you want to modify and select **Modify Profile** from the dropdown. You can modify, copy, or move the profile to the trash. Click on the "Modify Profile". ![Modify Profile - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/modify_profile.png) 4. You can modify the "**Profile Name**" and "**Description**" using the following steps. However, the "**Profile Type**" and "**Applicable For**" details cannot be modified. ![Modify Profile Name - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/modify_profile_name.png) 5. After making the required changes, click **Save** to apply them. To make the changes live in the profile, click **Publish**. ![Modify Profile Details - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/modify_profile_details.png) 6. The profile version details will automatically update after modifying the profile configurations. ![Modify Profile Version - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/modify_profile_version.png) When a profile is modified and published, it is not applied to the devices to which they were applied before. A new version of the profile is listed, you can upgrade the latest version to the group, so that the current members of the group will have the latest version of the profile applied to them. The previous version of profile will be overwritten by the latest version. ## Copy a Profile The **Copy Profile** feature in Mobile Device Manager Plus (MDM) allows you to duplicate existing profiles, enabling you to reuse previously configured settings without starting from scratch each time. By duplicating a profile, you can adjust policies as needed to meet specific organizational requirements, saving time and effort. MDM distinguishes duplicate profiles from the originals by appending "_Copy" to the profile name, which can be modified if desired. Cloned profiles provide a convenient base, allowing you to customize policies, test them on managed test devices, and then assign them to other devices or specific user groups. This feature streamlines profile creation, making it easy to update policies for select users and reduce repetitive setup tasks. **To duplicate a profile on MDM,** 1. Navigate to the **Device Mgmt** tab on the MDM console. 2. On the left pane, click on the **Profiles** tab to view the list of profiles which have been previously created. 3. Choose the profile that you want to duplicate and click on the ellipsis under the **Actions** column. Now, click on **Copy Profile**. 4. Save the profile after making changes to the profile name/policies, if required. 5. Click on **Publish** to save the changes. - Modify a profile to make changes to the existing profile. This alters the configuration of the profile. - Copy a profile to duplicate the existing profile which can subsequently be modified, without having to disturb the original profile's configuration. ## Moving a profile to Trash When you want to delete a profile associated with devices/groups, you can simply move the profile to Trash. Moving profiles to Trash ensures the profiles are automatically disassociated from the devices/groups. These profiles are automatically deleted after **90 days**. The profiles can also be deleted or restored manually from Trash by the user. However, the restored profiles don't automatically get associated with the previously associated groups/devices. These restored profiles can be associated to the devices/groups. The following steps explain the moving of profiles to Trash: 1. On the web console, navigate to **Profiles** 2. Under **Profiles tab,** you can view the list of all the profiles that have been created already. 3. Select the profiles to be moved to Trash. ![Move Profile - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/move_profile.png) 4. Click on the **Move to Trash** button and the profiles are moved to Trash. ![Move Profile Trash - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/move_profile_trash.png) The profiles can be viewed by clicking ![Trash - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/trash.jpg). The profiles can be deleted or restored from here. ![Move Profile Trash View - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/move_profile_trash_view.png) ## Best Practices - Policies which require constant changes such as Restrictions should not be grouped with e-mail account related policies such as Exchange, Wi-Fi etc., as every time a modified version of the profile containing all these policies is re-distributed, the passcode for the account-based services such as Exchange and configurations such as Wi-Fi preferences, previously synced mails etc., specified in the account-related policies is reset and has to be manually entered by the user again. Consider the case of Exchange - as MDM uses third-party mail clients such as Gmail, Samsung mail to configure Exchange, even reassociating the same policy (with/without modification) removes the existing configuration and then configures Exchange based on the newly associated policy. **This may require some user input**. - SCEP and the associated account policies which are to utilize the certificate provisioned by SCEP must be configured in the same profile. This ensures the same SCEP certificate is used for all the account-related policies configured in the profile. ## Frequently Asked Questions ### 1. What happens when two profiles with conflicting settings are applied to the same device? On iOS and Windows, the most secure combination of settings from both profiles is applied. On Android, the most recently applied profile's settings take precedence. ### 2. Should I use Modify Profile or Copy Profile? Use Modify Profile to change the configuration of an existing profile in place. Use Copy Profile to duplicate a profile so you can adjust the settings independently without disturbing the original profile's configuration. ### 3. What happens to profiles moved to Trash? Profiles moved to Trash are automatically disassociated from their devices/groups and are permanently deleted after 90 days. They can also be deleted or restored manually before that, though restored profiles must be re-associated to devices/groups. ### 4. Why should Restrictions policies be kept separate from Exchange or Wi-Fi policies? Policies that require frequent changes, such as Restrictions, shouldn't be grouped with account-based policies like Exchange or Wi-Fi. Re-distributing a profile that combines both resets the account/Wi-Fi configuration, requiring the user to manually re-enter details such as passwords.