Skip to main content
This guide applies to Mac computers

About user channel profiles

On a Mac, some configuration profiles install on the user channel. A user channel profile applies only to MDM-enabled users. A Mac can have more than one MDM-enabled user. A profile that installs on the device channel applies to the Mac, not to one local user. It does not depend on whether a local user is MDM-enabled. These rules apply to every Library Item that installs on the user channel, including Safari Extensions.

Device MDM status and MDM-enabled users

Whether MDM is enabled for the Mac is not the same as whether a local user is MDM-enabled. A Mac can have MDM enabled when a specific local user is not MDM-enabled. To confirm both, check the Mac and the local user separately. On a device record Details tab:
  • MDM > MDM Enabled is the MDM status of the Mac.
  • Users > MDM-enabled is the MDM status of that local user. Yes means that user can receive user channel profiles.
In Prism:
  • Devices > MDM Enabled is the MDM status of the Mac.
  • Local Users > MDM Enabled is the MDM status of each local user. Sort or filter it by Yes, No, Blank, or Is not blank.

Considerations

Automated Device Enrollment

Leave Make auto admin the MDM enabled user off in the Automated Device Enrollment Library Item. When it is on, the account the user creates during Setup Assistant is not MDM-enabled and cannot receive user channel profiles. Turning the option off applies to future enrollments. For a Mac that already enrolled with it on, see Sign in to the auto admin account.

Passport with Automated Device Enrollment

A local account created when someone logs in at the Passport login window after Automated Device Enrollment is not MDM-enabled. That account cannot receive user channel profiles until it becomes MDM-enabled. See Renew the MDM profile for a user.

Passport with manual enrollment

The user who manually enrolls the Mac is MDM-enabled. If that user later logs in at the Passport login window and selects Link my existing account, Passport links to that local user, and the Passport user is MDM-enabled.

Troubleshooting

A user channel profile is not applying

A local account receives a user channel profile only when that account is MDM-enabled. Confirm the user before you troubleshoot the Library Item.
1

Check the user on the device record

Open the device record and select the Details tab. Under Users, find the local account and review MDM-enabled. MDM > MDM Enabled is the MDM status of the Mac, not the status of that user. See Device Record Details.
2

Check the user in Prism

In Prism, open the Local Users category and review the MDM Enabled column for that account. Devices > MDM Enabled shows whether MDM is enabled for the Mac.
3

Check how the Mac enrolled

On the device record Details tab, look in the Automated Device Enrollment section and review Automated Device Enrolled. If it is Yes, the Mac enrolled through Automated Device Enrollment. If Make auto admin the MDM enabled user was on for that enrollment, follow Sign in to the auto admin account. Otherwise, follow Renew the MDM profile for a user.

Sign in to the auto admin account

Use these steps for a Mac that enrolled while Make auto admin the MDM enabled user was on. Turning the option off prevents the issue for future enrollments, but the account the user created during Setup Assistant on an already-enrolled Mac may still not be MDM-enabled.
1

Sign in to the auto admin account

At the Mac login window, sign in to the auto admin account with the physical keyboard. Enter the auto admin user name and password.
2

Sign in to the Setup Assistant account

Sign out of the auto admin account, then sign in to the account the user created during Setup Assistant. That account can then register as MDM-enabled.

Renew the MDM profile for a user

Follow these steps to make a user MDM-enabled on a Mac enrolled through Automated Device Enrollment. On the Mac, log in as the user you want to make MDM-enabled. That user must be an administrator on the Mac because the command requires elevated privileges.
1

Open Terminal

Open Terminal.
2

Renew the MDM profile

Run the following command:
Enter that user’s password when prompted. A prompt about the profile appears at the top right of the screen.
3

Update Device Enrollment

Open System Settings, select General, then select Device Management. When Update Device Enrollment appears, select Update. Enter the user’s password again, then confirm. The MDM profile is renewed, and that local user is MDM-enabled.

Device Record Details

Review Users > MDM-enabled for each local account on a Mac

Prism Data Analytics

Check Local Users > MDM Enabled to see which accounts are MDM-enabled

Configuring Apple Enrollment

Leave Make auto admin the MDM enabled user off during Automated Device Enrollment

Safari Extensions

Example of a Library Item that installs on the user channel

User experience with Passport

See the Passport login window and how a user links an existing local account