Configuration Profiles and MDM: macOS Managed Settings
macOS configuration profiles and MDM enrollment records show which policies, certificates, VPNs, TCC grants and extensions were pushed to a Mac, and when.
- Location
- /private/var/db/ConfigurationProfiles/
- Proves
- Which profiles and payloads (certificates, proxies, VPN, TCC/PPPC, system extensions, login items) were installed, by MDM or manually, and when
- Timestamps
- Install dates in the profile store (plist dates); Unified Log entries in UTC
- Access
- root; the profile store is SIP-protected on current releases, read it from an image or with profiles(1) live
- Retention
- Profiles persist until removed; install events follow Unified Log rotation
- Collection
- Aftermath, log collect, sysdiagnose, Disk image
Tools
Compare all tools- profilesCLI · built into macOS
- logCLI · built into macOS
- plutilCLI · built into macOS
- macos-UnifiedLogsLibrary · open source
What it is
A configuration profile (.mobileconfig) is a signed or unsigned plist carrying one or more payloads: Wi-Fi, VPN, proxy, root certificates, restrictions, Privacy Preferences Policy Control (PPPC, pre-approved TCC grants), allowed system extensions, managed login items, and more. Profiles arrive through Mobile Device Management (MDM), Automated Device Enrollment (ADE, formerly DEP) or manual installation by a user.
For an investigator they cut both ways: legitimate MDM explains many settings that look suspicious, and a malicious profile is a powerful, quiet persistence and interception mechanism (a rogue root certificate plus a proxy is enough to read TLS traffic).
Where it lives
| Source | Path | Notes |
|---|---|---|
| Profile store | /private/var/db/ConfigurationProfiles/Store/ | Installed profiles and metadata (file names vary by release) |
| Enrollment state | /private/var/db/ConfigurationProfiles/Settings/ | Includes ADE/DEP activation records and markers such as .cloudConfigHasActivationRecord on many releases |
| Managed preferences | /Library/Managed Preferences/ and /Library/Managed Preferences/<user>/ | Effective settings from profiles, readable plists |
| PPPC / TCC overrides | /Library/Application Support/com.apple.TCC/MDMOverrides.plist | Pre-approved privacy grants |
| MDM client events | Unified Logs, subsystem com.apple.ManagedClient, process mdmclient | Installs, removals, check-ins |
| Downloaded profiles | ~/Downloads/*.mobileconfig, quarantine events | Manual installs start here |
Since macOS 11 Big Sur, profiles install from the command line no longer installs profiles silently: a user must approve them in System Settings, or they must come through MDM. Older attack write-ups that rely on profiles -I do not apply to current releases.
What it proves
- Which profiles are installed, their identifiers, display names, organisation, signer and payload types.
- Whether the Mac is MDM-enrolled, by which server, and whether enrollment came from ADE (supervised, often non-removable).
- Specific effects: trusted root certificates, forced proxies or VPN, PPPC grants that bypass user prompts, allowed kernel or system extensions, managed login items.
- The installation source for recent events: Unified Log messages from
mdmclientrecord "Installed configuration profile" with aSource:value (for exampleManual).
Key fields
profiles show -output stdout-xml (or the older profiles -C -o stdout-xml) returns, per profile:
| Key | Meaning |
|---|---|
ProfileIdentifier, ProfileUUID | Stable identifier chosen by the issuer |
ProfileDisplayName, ProfileOrganization | What the user saw |
ProfileInstallDate | Install time |
ProfileItems → PayloadType | For example com.apple.security.root, com.apple.vpn.managed, com.apple.TCC.configuration-profile-policy, com.apple.system-extension-policy |
ProfileVerificationState | Signed and verified or not |
ProfileRemovalDisallowed | Locked profile |
profiles status -type enrollment reports enrollment and ADE status; profiles show -type enrollment shows the ADE configuration where available.
Timestamps
ProfileInstallDate is a date string in local or UTC form depending on output format; normalise it. Unified Log entries are UTC instants. Birth times of plists under /Library/Managed Preferences show when a managed setting first applied.
Retention
- Profiles remain until removed by the user, by MDM or by un-enrollment.
- Removal leaves little on disk; Unified Log events of the removal follow log rotation.
- A sysdiagnose archive includes profile and MDM state and may already exist on the Mac or in the MDM console.
Collection
sudo profiles show -output stdout-xml > ./case/profiles.xml
sudo profiles status -type enrollment > ./case/enrollment.txt
sudo ditto "/Library/Managed Preferences" ./case/ManagedPreferences
sudo log collect --output ./case/host.logarchive
Aftermath saves profiles -C -o stdout-xml and runs a Unified Log predicate for manual profile installs (mdmclient, category MDMDaemon, "Installed configuration profile:" with "Source: Manual").
Parsing
# Profile installs, with their source
log show --archive host.logarchive --timezone UTC --style syslog \
--predicate 'subsystem == "com.apple.ManagedClient" AND process == "mdmclient"
AND eventMessage CONTAINS "Installed configuration profile"'
# Payload types at a glance
plutil -p ./case/profiles.xml | grep -E 'PayloadType|ProfileDisplayName|ProfileInstallDate'
Investigator tips
- Ask the organisation for its MDM profile list first. Anything not issued by their MDM is a lead.
- Hunt for
com.apple.security.rootpayloads that add unknown CAs, andcom.apple.proxy.http.globalor VPN payloads that route traffic to unknown hosts. - PPPC payloads explain why an app holds Full Disk Access with no prompt in TCC.db; check
MDMOverrides.plist. - Managed login items and background tasks appear in Background Task Management with an MDM flag.
- A
.mobileconfigin Downloads with a matching quarantine record and a "Source: Manual" install event reconstructs a social-engineering chain end to end.