How to Spot a Malicious Configuration Profile on Mac

    Audit System Settings → Device Management for unauthorised macOS profiles.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Configuration Profiles are intended for companies and schools to manage Macs at scale. Adware and scam apps abuse them to lock browser settings, install root certificates, and prevent you from changing things back.

    Important

    If you do not work for an MDM-managed organisation, you should have zero Configuration Profiles installed. Anything present is suspicious by default.

    Step 1: Open Device Management

    1. System SettingsGeneralDevice Management
    2. On older macOS this is System PreferencesProfiles
    3. If the section is missing entirely, you have no profiles installed — that is the safe default

    Step 2: Read each profile

    • Profile name and signer — does it match a company you work for?
    • What it controls (browser homepage, search engine, certificates, restrictions)
    • When it was installed
    Common malicious names include AdminPrefs, Chromium, generic developer IDs ending in .com.adobe.xyz impersonating Adobe, or anything tied to your hijacked search engine.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security