> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# MDM-enabled users and user channel profiles

> Learn how user channel profiles apply to MDM-enabled users on a Mac, how to confirm that status, and what to check when a profile is missing.

<Callout icon="apple" color="#B84A7A" iconType="regular">This guide applies to Mac computers</Callout>

### About user channel profiles

On a Mac, some configuration profiles install on the user channel. A user channel profile applies only to MDM-enabled users. A Mac can have more than one MDM-enabled user.

A profile that installs on the device channel applies to the Mac, not to one local user. It does not depend on whether a local user is MDM-enabled.

These rules apply to every Library Item that installs on the user channel, including [Safari Extensions](/en/endpoint/library/library-items-profiles/configure-the-safari-extensions-library-item).

### Device MDM status and MDM-enabled users

Whether MDM is enabled for the Mac is not the same as whether a local user is MDM-enabled. A Mac can have MDM enabled when a specific local user is not MDM-enabled.

To confirm both, check the Mac and the local user separately.

On a [device record](/en/endpoint/devices/device-record-management/device-record-details) **Details** tab:

* **MDM > MDM Enabled** is the MDM status of the Mac.
* **Users > MDM-enabled** is the MDM status of that local user. **Yes** means that user can receive user channel profiles.

In [Prism](/en/iru/iru-ai/prism-data-analytics):

* **Devices > MDM Enabled** is the MDM status of the Mac.
* **Local Users > MDM Enabled** is the MDM status of each local user. Sort or filter it by **Yes**, **No**, **Blank**, or **Is not blank**.

### Considerations

#### Automated Device Enrollment

Leave **Make auto admin the MDM enabled user** off in the [Automated Device Enrollment](/en/endpoint/enrollment/apple/configuring-apple-enrollment) Library Item. When it is on, the account the user creates during Setup Assistant is not MDM-enabled and cannot receive user channel profiles. Turning the option off applies to future enrollments. For a Mac that already enrolled with it on, see [Sign in to the auto admin account](#sign-in-to-the-auto-admin-account).

#### Passport with Automated Device Enrollment

A local account created when someone logs in at the Passport login window after Automated Device Enrollment is not MDM-enabled. That account cannot receive user channel profiles until it becomes MDM-enabled. See [Renew the MDM profile for a user](#renew-the-mdm-profile-for-a-user).

#### Passport with manual enrollment

The user who manually enrolls the Mac is MDM-enabled. If that user later logs in at the Passport login window and selects **Link my existing account**, Passport links to that local user, and the Passport user is MDM-enabled.

### Troubleshooting

#### A user channel profile is not applying

A local account receives a user channel profile only when that account is MDM-enabled. Confirm the user before you troubleshoot the Library Item.

<Steps>
  <Step title="Check the user on the device record">
    Open the device record and select the **Details** tab. Under **Users**, find the local account and review **MDM-enabled**. **MDM > MDM Enabled** is the MDM status of the Mac, not the status of that user. See [Device Record Details](/en/endpoint/devices/device-record-management/device-record-details).
  </Step>

  <Step title="Check the user in Prism">
    In [Prism](/en/iru/iru-ai/prism-data-analytics), open the **Local Users** category and review the **MDM Enabled** column for that account. **Devices > MDM Enabled** shows whether MDM is enabled for the Mac.
  </Step>

  <Step title="Check how the Mac enrolled">
    On the device record **Details** tab, look in the **Automated Device Enrollment** section and review **Automated Device Enrolled**. If it is **Yes**, the Mac enrolled through Automated Device Enrollment. If **Make auto admin the MDM enabled user** was on for that enrollment, follow [Sign in to the auto admin account](#sign-in-to-the-auto-admin-account). Otherwise, follow [Renew the MDM profile for a user](#renew-the-mdm-profile-for-a-user).
  </Step>
</Steps>

#### Sign in to the auto admin account

Use these steps for a Mac that enrolled while **Make auto admin the MDM enabled user** was on. Turning the option off prevents the issue for future enrollments, but the account the user created during Setup Assistant on an already-enrolled Mac may still not be MDM-enabled.

<Steps>
  <Step title="Sign in to the auto admin account">
    At the Mac login window, sign in to the auto admin account with the physical keyboard. Enter the auto admin user name and password.
  </Step>

  <Step title="Sign in to the Setup Assistant account">
    Sign out of the auto admin account, then sign in to the account the user created during Setup Assistant. That account can then register as MDM-enabled.
  </Step>
</Steps>

#### Renew the MDM profile for a user

Follow these steps to make a user MDM-enabled on a Mac enrolled through Automated Device Enrollment. On the Mac, log in as the user you want to make MDM-enabled. That user must be an administrator on the Mac because the command requires elevated privileges.

<Steps>
  <Step title="Open Terminal">
    Open Terminal.
  </Step>

  <Step title="Renew the MDM profile">
    Run the following command:

    ```bash theme={null}
    sudo profiles -N
    ```

    Enter that user's password when prompted. A prompt about the profile appears at the top right of the screen.
  </Step>

  <Step title="Update Device Enrollment">
    Open **System Settings**, select **General**, then select **Device Management**. When **Update Device Enrollment** appears, select **Update**. Enter the user's password again, then confirm. The MDM profile is renewed, and that local user is MDM-enabled.
  </Step>
</Steps>

### Related articles

<CardGroup cols={2}>
  <Card title="Device Record Details" icon="desktop" href="/en/endpoint/devices/device-record-management/device-record-details">
    Review **Users > MDM-enabled** for each local account on a Mac
  </Card>

  <Card title="Prism Data Analytics" icon="chart-column" href="/en/iru/iru-ai/prism-data-analytics">
    Check **Local Users > MDM Enabled** to see which accounts are MDM-enabled
  </Card>

  <Card title="Configuring Apple Enrollment" icon="apple" href="/en/endpoint/enrollment/apple/configuring-apple-enrollment">
    Leave **Make auto admin the MDM enabled user** off during Automated Device Enrollment
  </Card>

  <Card title="Safari Extensions" icon="puzzle-piece" href="/en/endpoint/library/library-items-profiles/configure-the-safari-extensions-library-item">
    Example of a Library Item that installs on the user channel
  </Card>

  <Card title="User experience with Passport" icon="right-to-bracket" href="/en/endpoint/library/passport/user-experience-with-passport">
    See the Passport login window and how a user links an existing local account
  </Card>
</CardGroup>
