In Apple's ecosystem, configuration profiles are XML files which define a wide array of settings and enable streamlined configuration of macOS, iOS or tvOS devices. Apple's Mobile Device Management (MDM) technology relies on configuration profiles to push settings to fleets of enrolled devices remotely, and Apple Configurator uses them to configure mobile devices locally.
Most MDM vendors such as Jamf or Simple MDM provide a simplified configuration interface and translate the desired settings into one or more configuration profiles behind the scenes. But in many cases, working directly with configuration profiles may be necessary:
You can create and edit configuration profiles with ease using the iMazing Profile Editor app for macOS and Windows. The app contains definitions for all of Apple device configuration options and for a large number of third party apps as well, which it displays in a friendly graphical user interface.
Here's summary of how to create or edit configuration profiles for iOS, macOS, or tvOS:
Download and install iMazing Profile Editor, a desktop application for macOS High Sierra (version 10.13.6) and later and Windows 7 SP1 and later. It can be downloaded from the following link and installed by opening the DMG file and dragging the app icon to the Applications folder.
A new configuration profile window will be created when you launch the app, or when you click on New in the File menu. This can also be achieved by pressing ⌘N on the keyboard.
You can select a profile file (.mobileconfig) to open in the app when launching the file-open dialog by clicking Open... in the File menu, or by pressing ⌘O on the keyboard.
iMazing Profile Editor is made up of a sections sidebar, and a main area displaying preference pages.
The sidebar shows all of the available Apple configuration domains for iOS, macOS, and tvOS, as well as many third party domains for macOS.
Configuration domains are a way to split all of the available settings into related groups, such as Restrictions, Wi-Fi, and Notifications. Third party apps which are configurable via profiles on macOS have each their own configuration domain too.
The main display area is where most of the work is done. It shows the various available fields for the selected configuration domain, and provides the place to select the right settings and enter the configuration data.
The first section on the sidebar, General, is the place for defining settings for the profile itself. These settings have no effect over any preference on an Apple device, but instead influence how a profile is installed, removed, and what information is displayed about it to the user.
💡 Note: The identifier field is automatically filled for you. The device on which the profile is installed will rely on this identifier to determine whether or not it should replace an existing profile. For this reason, it may be useful to change the identifier, when you duplicate a profile to use it as a template for example.
For every domain that you want to configure with a profile, the relevant preferences are added within a domain-specific payload.
Profiles can contain multiple payloads, however multiple payloads of the same domain are only supported for a small number of domains. These are usually ones that do not define global settings (it would be contradictory to define those more than once on a device), but those that define settings that can coincide like mail accounts, calendar accounts, Wi-Fi networks, and so on.
To add a payload, select the section for the domain that you want to add a payload of, and click Add Configuration Payload to add it to the current profile. You can also press ⇧⌘A on the keyboard.
On domains that support multiple payloads, add additional ones by clicking the + (plus) button that will appear on the top, or press the same key combination.
💡 Tip: You can rename payloads that you have added to profiles. This is especially helpful in domains that support multiple payloads. For example, you can add different payloads for different calendars, and give each a meaningful name rather than "Calendar #1" and so on. To rename a payload, simply click on the payload name.
For each payload that you are configuring, fill in the settings information that's relevant for you or check the necessary checkboxes.
💡 Tip: Fields that you leave empty (or set to 'No Value' in the case of drop-down boxes) will not be written to the profile, and by default, fields that are set to their system default values will not be written either.
If you require more information about the available settings, please visit Apple's payload keys documentation for respective Apple domains.
For third party app configuration domains, the best place to find information is the community of Apple system administration experts on the MacAdmins Slack. Members of the community compile the third party app definitions, and the community channels are an incredible resource for learning about Apple device configuration and for posting questions on the topic.
Removing a configuration payload from a profile can be done by pressing the - (minus) button at the head of the payload, or by pressing ⇧⌘R on the keyboard.
Before saving, make sure that there are no validation errors on the profile. Those are shown in the sections sidebar as numbered red badges that count the number of errors per section. A red badge will become green once all of the errors in the section are resolved. Note that though it is possible to save a profile which still contains validation error, it isn't advisable to do so.
When you are done, save the profile to your drive by clicking Save in the File menu, or by pressing ⌘S on the keyboard. The resulting .mobileconfig file is a standard configuration profile which conforms to Apple's specification and is compatible with any conformant software.
For an additional layer of trust and security, you can digitally sign the profile with a certificate stored in your macOS Keychain or Windows Certificate Manager.
To do so, select a signing identity from the Sign profile with: drop-down box on the file-save sheet.
💡 Tip: If the file is already saved without a signature, you can bring up the file-save sheet again by clicking Save As... in the File menu, or by pressing ⇧⌘S on the keyboard.
The configuration profile file that you created is now ready for use on an iOS, macOS, or tvOS device. You can install it locally using iMazing, iMazing Configurator, Apple Configurator or via a supporting MDM service.
For more information about using iMazing Profile Editor, head over to our Getting started with iMazing Profile Editor guide.