This guide applies to Mac computers
About user channel profiles
On a Mac, some configuration profiles install on the user channel. A user channel profile applies only to MDM-enabled users. A Mac can have more than one MDM-enabled user. A profile that installs on the device channel applies to the Mac, not to one local user. It does not depend on whether a local user is MDM-enabled. These rules apply to every Library Item that installs on the user channel, including Safari Extensions.Device MDM status and MDM-enabled users
Whether MDM is enabled for the Mac is not the same as whether a local user is MDM-enabled. A Mac can have MDM enabled when a specific local user is not MDM-enabled. To confirm both, check the Mac and the local user separately. On a device record Details tab:- MDM > MDM Enabled is the MDM status of the Mac.
- Users > MDM-enabled is the MDM status of that local user. Yes means that user can receive user channel profiles.
- Devices > MDM Enabled is the MDM status of the Mac.
- Local Users > MDM Enabled is the MDM status of each local user. Sort or filter it by Yes, No, Blank, or Is not blank.
Considerations
Automated Device Enrollment
Leave Make auto admin the MDM enabled user off in the Automated Device Enrollment Library Item. When it is on, the account the user creates during Setup Assistant is not MDM-enabled and cannot receive user channel profiles. Turning the option off applies to future enrollments. For a Mac that already enrolled with it on, see Sign in to the auto admin account.Passport with Automated Device Enrollment
A local account created when someone logs in at the Passport login window after Automated Device Enrollment is not MDM-enabled. That account cannot receive user channel profiles until it becomes MDM-enabled. See Renew the MDM profile for a user.Passport with manual enrollment
The user who manually enrolls the Mac is MDM-enabled. If that user later logs in at the Passport login window and selects Link my existing account, Passport links to that local user, and the Passport user is MDM-enabled.Troubleshooting
A user channel profile is not applying
A local account receives a user channel profile only when that account is MDM-enabled. Confirm the user before you troubleshoot the Library Item.1
Check the user on the device record
Open the device record and select the Details tab. Under Users, find the local account and review MDM-enabled. MDM > MDM Enabled is the MDM status of the Mac, not the status of that user. See Device Record Details.
2
Check the user in Prism
In Prism, open the Local Users category and review the MDM Enabled column for that account. Devices > MDM Enabled shows whether MDM is enabled for the Mac.
3
Check how the Mac enrolled
On the device record Details tab, look in the Automated Device Enrollment section and review Automated Device Enrolled. If it is Yes, the Mac enrolled through Automated Device Enrollment. If Make auto admin the MDM enabled user was on for that enrollment, follow Sign in to the auto admin account. Otherwise, follow Renew the MDM profile for a user.
Sign in to the auto admin account
Use these steps for a Mac that enrolled while Make auto admin the MDM enabled user was on. Turning the option off prevents the issue for future enrollments, but the account the user created during Setup Assistant on an already-enrolled Mac may still not be MDM-enabled.1
Sign in to the auto admin account
At the Mac login window, sign in to the auto admin account with the physical keyboard. Enter the auto admin user name and password.
2
Sign in to the Setup Assistant account
Sign out of the auto admin account, then sign in to the account the user created during Setup Assistant. That account can then register as MDM-enabled.
Renew the MDM profile for a user
Follow these steps to make a user MDM-enabled on a Mac enrolled through Automated Device Enrollment. On the Mac, log in as the user you want to make MDM-enabled. That user must be an administrator on the Mac because the command requires elevated privileges.1
Open Terminal
Open Terminal.
2
Renew the MDM profile
Run the following command:Enter that user’s password when prompted. A prompt about the profile appears at the top right of the screen.
3
Update Device Enrollment
Open System Settings, select General, then select Device Management. When Update Device Enrollment appears, select Update. Enter the user’s password again, then confirm. The MDM profile is renewed, and that local user is MDM-enabled.
Related articles
Device Record Details
Review Users > MDM-enabled for each local account on a Mac
Prism Data Analytics
Check Local Users > MDM Enabled to see which accounts are MDM-enabled
Configuring Apple Enrollment
Leave Make auto admin the MDM enabled user off during Automated Device Enrollment
Safari Extensions
Example of a Library Item that installs on the user channel
User experience with Passport
See the Passport login window and how a user links an existing local account