Device Security
How to Remove a Malicious Configuration Profile From Your Mac
Delete unauthorised profiles, remove rogue certificates and restore your browser settings.
6 min read · Beginner friendly
Step 1: Remove the profile
- System Settings → General → Device Management
- Select the profile and click the − (minus) button
- Authenticate with your Mac password when prompted
- Repeat for every profile you did not knowingly install
Step 2: Remove rogue root certificates
- Open Keychain Access (search via Spotlight)
- Choose the System keychain → Certificates category
- Look for certificates with unfamiliar names or expiry dates far in the future
- Right-click → Delete any that you do not recognise (do not delete Apple-signed system certificates)
If you are unsure whether a certificate is legitimate, search the issuer name online before deleting. Apple system certificates are required and should be left alone.
Step 3: Reset browser settings
- Restart Safari/Chrome/Firefox
- Reset homepage and search engine to your preferred choice
- Confirm Chrome no longer shows Managed by your organization at the bottom of the menu
Tags:
Mac Security