How to Remove a Malicious Configuration Profile From Your Mac

    Step-by-step removal of malicious macOS Configuration Profiles.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Step 1: Remove the profile

    1. System SettingsGeneralDevice Management
    2. Select the profile and click the (minus) button
    3. Authenticate with your Mac password when prompted
    4. Repeat for every profile you did not knowingly install

    Step 2: Remove rogue root certificates

    1. Open Keychain Access (search via Spotlight)
    2. Choose the System keychain → Certificates category
    3. Look for certificates with unfamiliar names or expiry dates far in the future
    4. Right-click → Delete any that you do not recognise (do not delete Apple-signed system certificates)

    Important

    If you are unsure whether a certificate is legitimate, search the issuer name online before deleting. Apple system certificates are required and should be left alone.

    Step 3: Reset browser settings

    1. Restart Safari/Chrome/Firefox
    2. Reset homepage and search engine to your preferred choice
    3. Confirm Chrome no longer shows Managed by your organization at the bottom of the menu

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Device Security