Approving MDM is an essential part of the MDM enrollment process in Addigy. This article will walk you through what Approved MDM Profiles as well as how to approve MDM as an end-user on Catalina and Big Sur 11.0+ starting from the moment the Device Enrollment link is pasted into a browser.
What are Approved MDM Profiles
In macOS 10.13.4, Apple introduced a new type of Mobile Device Management (MDM) Profile. MDM Profiles are now split into two categories: approved profiles and not-approved. While not-approved profiles can still perform many of MDM's capabilities, Apple is continually adding to the features that can only be achieved through an approved profile.
In macOS 10.13.4, the only feature which is limited to approved profiles is kernel extension whitelisting, but Apple continues to add features to this list with every major release. In macOS Mojave, Apple introduced new Privacy Controls that can only be managed using an approved profile.
Below is an example of an MDM Profile that has not yet been approved:
Please ensure the device you are enrolling meets Addigy's system requirements. If the device does not meet the requirements, we cannot guarantee that the enrollment will work or that the device will properly communicate with Addigy. More information here: Addigy System Requirements
Further, please make sure that you have a push certificate configured and assigned to the policy that the device is, or will be enrolled into. More information on push certificates can be found here: Overview: MDM Apple Push Certificates
How to Approve MDM Profiles
The moment you connect to the link pasted into the browser, you will be given the following prompt. Click Allow.
Once you click Allow, System Preferences will open and you will be presented with the following window. Click Install.
After clicking Install, you will be prompted for your user password. Enter your password and click "OK".
Once the password is entered, the MDM enrollment profile will be approved and all profiles will be installed on the device.
Big Sur 11.0-Monterey 12.0
The moment you connect to the link pasted into the browser, the enrollment profile will be downloaded onto the device and you will receive a prompt similar to the below from System Preferences to review the profile.
- Open System Preferences and select Profiles.
- Once you select Profiles, you will be presented with the enrollment profile as well as an option to "Ignore" or "Install" it. Click Install.
- Once you click Install, you will be prompted for confirmation to install the profile. Click Install.
- After clicking Install, you will be prompted for your user password. Enter your password and click "Enroll".
- Once the password is entered, the MDM enrollment profile will be approved and all profiles will be installed on the device.
Ventura (macOS 13.0)
On macOS Ventura, the process is slightly different after the profile is downloaded.
Navigate to System Settings > Privacy & Security > Profiles to approve the profile.
- Click on the Profiles menu and select the downloaded profile:
- Once you click on the profile, a new pane will appear and prompt you to Enroll or Ignore the MDM enrollment profile.
- After clicking "Enroll", an admin must enter their credentials to install the profile:
Once the enrollment profile is approved, the MDM configurations will begin to install and there will be a message saying the device is supervised and managed:
Checking if a Profile Has Been Approved
To verify if any devices have an approved profile head over to the Devices page and check out our latest device fact Has MDM Profile Approved. This device fact will reflect if a device has User Approved MDM even after it goes offline.
This device fact will show success if the MDM Profile is approved or if the device is on an older version of macOS that does not support profile approval, and it will fail if the MDM Profile has not yet been approved.
If you need additional help creating a table view like the one above, check out our KB article: Customizing the Devices Table.
When managing devices with MDM, there are a few key device facts that are critical to monitor as an admin. Those device facts are as follows:
Has MDM Profile Approved - will reflect if the MDM Enrollment Profile has User Approval
Has MDM - will reflect if you have Addigy MDM
Installed Profiles - will list all installed MDM profiles on the device
Additionally, all device facts available to you in our Devices page can also be seen on a per-device-basis through GoLive.
If you have issues with approving your MDM Profiles after reviewing these two methods, please reach out to Addigy Support for further assistance.