Skip to content

PersistenceNetworkLogs

Configuration Profiles and MDM: macOS Managed Settings

macOS configuration profiles and MDM enrollment records show which policies, certificates, VPNs, TCC grants and extensions were pushed to a Mac, and when.

Location
/private/var/db/ConfigurationProfiles/
Proves
Which profiles and payloads (certificates, proxies, VPN, TCC/PPPC, system extensions, login items) were installed, by MDM or manually, and when
Timestamps
Install dates in the profile store (plist dates); Unified Log entries in UTC
Access
root; the profile store is SIP-protected on current releases, read it from an image or with profiles(1) live
Retention
Profiles persist until removed; install events follow Unified Log rotation
Collection
Aftermath, log collect, sysdiagnose, Disk image

What it is

A configuration profile (.mobileconfig) is a signed or unsigned plist carrying one or more payloads: Wi-Fi, VPN, proxy, root certificates, restrictions, Privacy Preferences Policy Control (PPPC, pre-approved TCC grants), allowed system extensions, managed login items, and more. Profiles arrive through Mobile Device Management (MDM), Automated Device Enrollment (ADE, formerly DEP) or manual installation by a user.

For an investigator they cut both ways: legitimate MDM explains many settings that look suspicious, and a malicious profile is a powerful, quiet persistence and interception mechanism (a rogue root certificate plus a proxy is enough to read TLS traffic).

Where it lives

SourcePathNotes
Profile store/private/var/db/ConfigurationProfiles/Store/Installed profiles and metadata (file names vary by release)
Enrollment state/private/var/db/ConfigurationProfiles/Settings/Includes ADE/DEP activation records and markers such as .cloudConfigHasActivationRecord on many releases
Managed preferences/Library/Managed Preferences/ and /Library/Managed Preferences/<user>/Effective settings from profiles, readable plists
PPPC / TCC overrides/Library/Application Support/com.apple.TCC/MDMOverrides.plistPre-approved privacy grants
MDM client eventsUnified Logs, subsystem com.apple.ManagedClient, process mdmclientInstalls, removals, check-ins
Downloaded profiles~/Downloads/*.mobileconfig, quarantine eventsManual installs start here

Since macOS 11 Big Sur, profiles install from the command line no longer installs profiles silently: a user must approve them in System Settings, or they must come through MDM. Older attack write-ups that rely on profiles -I do not apply to current releases.

What it proves

  • Which profiles are installed, their identifiers, display names, organisation, signer and payload types.
  • Whether the Mac is MDM-enrolled, by which server, and whether enrollment came from ADE (supervised, often non-removable).
  • Specific effects: trusted root certificates, forced proxies or VPN, PPPC grants that bypass user prompts, allowed kernel or system extensions, managed login items.
  • The installation source for recent events: Unified Log messages from mdmclient record "Installed configuration profile" with a Source: value (for example Manual).

Key fields

profiles show -output stdout-xml (or the older profiles -C -o stdout-xml) returns, per profile:

KeyMeaning
ProfileIdentifier, ProfileUUIDStable identifier chosen by the issuer
ProfileDisplayName, ProfileOrganizationWhat the user saw
ProfileInstallDateInstall time
ProfileItems → PayloadTypeFor example com.apple.security.root, com.apple.vpn.managed, com.apple.TCC.configuration-profile-policy, com.apple.system-extension-policy
ProfileVerificationStateSigned and verified or not
ProfileRemovalDisallowedLocked profile

profiles status -type enrollment reports enrollment and ADE status; profiles show -type enrollment shows the ADE configuration where available.

Timestamps

ProfileInstallDate is a date string in local or UTC form depending on output format; normalise it. Unified Log entries are UTC instants. Birth times of plists under /Library/Managed Preferences show when a managed setting first applied.

Retention

  • Profiles remain until removed by the user, by MDM or by un-enrollment.
  • Removal leaves little on disk; Unified Log events of the removal follow log rotation.
  • A sysdiagnose archive includes profile and MDM state and may already exist on the Mac or in the MDM console.

Collection

sudo profiles show -output stdout-xml > ./case/profiles.xml
sudo profiles status -type enrollment > ./case/enrollment.txt
sudo ditto "/Library/Managed Preferences" ./case/ManagedPreferences
sudo log collect --output ./case/host.logarchive

Aftermath saves profiles -C -o stdout-xml and runs a Unified Log predicate for manual profile installs (mdmclient, category MDMDaemon, "Installed configuration profile:" with "Source: Manual").

Parsing

# Profile installs, with their source
log show --archive host.logarchive --timezone UTC --style syslog \
  --predicate 'subsystem == "com.apple.ManagedClient" AND process == "mdmclient"
               AND eventMessage CONTAINS "Installed configuration profile"'

# Payload types at a glance
plutil -p ./case/profiles.xml | grep -E 'PayloadType|ProfileDisplayName|ProfileInstallDate'

Investigator tips

  • Ask the organisation for its MDM profile list first. Anything not issued by their MDM is a lead.
  • Hunt for com.apple.security.root payloads that add unknown CAs, and com.apple.proxy.http.global or VPN payloads that route traffic to unknown hosts.
  • PPPC payloads explain why an app holds Full Disk Access with no prompt in TCC.db; check MDMOverrides.plist.
  • Managed login items and background tasks appear in Background Task Management with an MDM flag.
  • A .mobileconfig in Downloads with a matching quarantine record and a "Source: Manual" install event reconstructs a social-engineering chain end to end.

See also