Skip to main content
Question

Can macOS Admin users bypass Jamf Configuration Profiles?


connorb
Forum|alt.badge.img+4

When testing an app uninstallation, I deleted a PLIST containing the app's Managed Settings that were originally pushed down by a Configuration Profile.

The profile pushed down after the next Inventory Update, but the Managed Settings did not take effect again until I rebooted my computer.

My main question is, can other Configuration Profile types be bypassed by similar means? Restrictions, Managed Login Items, Passcode settings, etc?

3 replies

jamf-42
Forum|alt.badge.img+17
  • Esteemed Contributor
  • 744 replies
  • April 15, 2024

no, ish.. a local admin can effect some config in the current session, but config profiles from JAMF are immutable. More details on what and where you uninstalled the app would be useful.


AJPinto
Forum|alt.badge.img+26
  • Legendary Contributor
  • 2725 replies
  • April 15, 2024

You can have MDM Configured to allow Admins to remove Configuration Profiles in your Prestage. Aside of that, no, Configuration Profiles are protected by System Integrity Protection and cannot be tampered with.


easyedc
Forum|alt.badge.img+16
  • Esteemed Contributor
  • 623 replies
  • April 15, 2024
jamf-42 wrote:

no, ish.. a local admin can effect some config in the current session, but config profiles from JAMF are immutable. More details on what and where you uninstalled the app would be useful.


No, ish is a fair statement.  There are some ways that you can bypass configuration profiles by deleting the directory that the profiles are stored in. Changes can then be made, though upon any reboot would get reverted back to whatever setting is pushed down from Jamf.  That doesn't prevent users from doing some decent damage while things are in limbo.  There's also the classic remove Jamf outright.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings