Allow users to remove MDM profile on manually enrolled macOS devicesSolved

Participant
Discussion
5 days ago Aug 18, 2026

I’m managing a few macOS devices in Hexnode and want users to be able to delete the MDM profile themselves. These Macs were enrolled manually, not through Automated Device Enrollment. Where do I enable permission for users to remove the MDM profile?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
5 days ago Aug 18, 2026
Marked SolutionPending Review

Hey @maevee,

For manually enrolled macOS devices, users can remove the MDM profile by default from the Mac settings.

On newer macOS versions, the user can go to:

System Settings > General > VPN & Device Management

On older macOS versions, the path is usually:

System Preferences > Profiles

From there, they can select the MDM profile and remove it.

If the user is blocked by a password prompt while removing the profile, check the macOS restriction policy associated with the device in Hexnode:

  1. Go to Policies.
  2. Edit the macOS policy applied to the device.
  3. Navigate to macOS > Restrictions > Security Settings.
  4. Disable Ask for password when removing policy.
  5. Save the policy and make sure it is associated with the target devices.

After the updated policy is applied, users should be able to remove the manually enrolled MDM profile without being asked for the removal password.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Hexnode Expert
5 days ago Aug 18, 2026
Marked SolutionPending Review

Does the same setting apply if the Mac was enrolled through Apple Business Manager / DEP? I have a mix of manually enrolled Macs and ADE-enrolled Macs.

Marked SolutionPending Review
Hexnode Expert
5 days ago Aug 18, 2026
Marked SolutionPending Review

No @maevee, ADE-enrolled Macs work differently. For devices enrolled through Automated Device Enrollment, profile removal is controlled from the DEP configuration profile.

To allow MDM profile removal for ADE-enrolled Macs:

  1. Go to Admin > Apple Business/School Manager > Apple DEP.
  2. Open DEP Configuration Profiles.
  3. Edit the DEP profile used for the Mac.
  4. Enable Allow MDM profile removal.
  5. Save and associate the DEP profile with the required devices.

Important: If the Mac was already enrolled with profile removal restricted, changing this ADE setting will not immediately update the existing enrollment state. The device must be erased and re-enrolled for the updated DEP profile setting to take effect.

Regards,
Isabel Lora
Hexnode UEM

Save