Category Filter
 
 

Last updated: August 14, 2026

macOS Configuration Profiles

This page provides an overview of macOS Configuration Profiles available in MDM, enabling administrators to enforce policies and restrictions on managed Mac machines. It covers a comprehensive range of profile types — including Passcode, Wi-Fi, VPN, FileVault Encryption, Firewall, Certificates, Active Directory Binding, and more — each customizable and storable in specific versions for flexible assignment to devices or groups. Use this page as a reference to understand which profile specifications are available and navigate to detailed configuration guides for each.

You can configure a profile to impose policies and restrictions on the managed mac machines. The following profile specifications can be customized and stored in specific versions, to be associated with devices/groups at any point of time. The specifications are listed below with the options to customize it. These profiles are tailored for managing mac machines.

Profiles Supported

  • Passcode - Define parameters for creating a password.
  • Restrictions - Configuring restrictions and permissions for Mac machines.
  • Wi-Fi - Configuring Wi-Fi and proxy settings for devices to connect to a secure Wi-Fi network.
  • Virtual Private Network (VPN) - Configuring VPN and Proxy settings to securely access corporate data from the devices.
  • Per-App VPN - Configuring VPN for specific apps.
  • App Notifications - Configure App Notifications for specific apps to allow/restrict notifications and also customize the app's notification settings such as sounds, previews and alerts.
  • FileVault Encryption - Configuring Mac FileVault to encrypt information stored in Mac machines.
  • Firewall - Protect devices by setting up a firewall, to barricade them from untrusted networks or hazardous incoming connections.
  • AirPrint - Integrate with Certificate Authority to automate distribution client certificates to secure devices through certificate-based authentication.
  • Global HTTP Proxy - Integrate with Certificate Authority to automate distribution client certificates to secure devices through certificate-based authentication.
  • Certificate - Distribute certificates to managed devices to secure access to services such as e-mail, Wi-Fi, etc.
  • Simple Certificate Enrollment Protocol (SCEP) - Integrate with Certificate Authority to automate distribution client certificates to secure devices through certificate-based authentication.
  • Active Directory Binding - Configuring Mac AD Binding to remotely bind Mac machines to Active Directory.
  • Firmware Password - Configuring the Firmware Password to ensure secure system bootups.
  • Personal Preferences Privacy Control - Configuring Privacy Preference Policy Control (PPPC) to automatically grant permissions requested by Mac applications.
  • System Extensions - Configuring System Extensions to approve kernel, network, driver, and security extensions on managed Mac machines.
  • AD certificate policy - Configuring AD certificate policy to enhance security on macOS devices.
  • Custom Configuration - Configuring customized profiles using third-party tools such as Apple Configurator and distribute them via MDM.

Frequently Asked Questions

  • How many macOS configuration profile types does ManageEngine MDM support? ManageEngine MDM supports a comprehensive range of macOS configuration profile types including Passcode, Wi-Fi, VPN, FileVault Encryption, Certificate, SCEP, Restrictions, Active Directory Binding, AirPrint, and more.
  • Can multiple macOS configuration profiles be applied to the same Mac device? Yes, multiple configuration profiles can be applied simultaneously to managed Mac devices in ManageEngine MDM. Profiles can be associated at device or group level.
  • Do macOS configuration profiles work on both Intel and Apple Silicon Macs? Yes, configuration profiles in ManageEngine MDM apply to all enrolled Mac devices regardless of processor architecture, including Intel-based and Apple Silicon Mac machines.
Jump To