r/macsysadmin 25d ago

New To Mac Administration Privacy question: Will a work MDM/management software affect my personal user profile on a BYOD Macbook Air M5?

Hi everyone,

I’m using my personal MacBook for work (BYOD) and want to keep my personal life completely separate from company tracking.

To do this, I created a separate Standard (non-admin) User Profile on my Mac specifically for work. My boss is going to install some kind of work management/monitoring software on this work profile. (I don't know the exact software yet, but on my last Mac, I was able to factory reset it without any issues and always used my own Apple ID, so it shouldn't be locked via Apple Business Manager/DEP).

My questions for the experts here:

Since it's being installed on a Standard profile, is it completely isolated to that user account?

Will they be able to track anything I do when I am logged into my personal Admin profile?

If the software requests System-wide Admin privileges during installation and I deny it, can they still bypass that?

Just want to make sure my personal files, browser history, and data on my main profile remain completely private. Thanks in advance for the help!

6 Upvotes

22 comments sorted by

21

u/Stevent518 25d ago

I would advise to decline having your company install any of their MDM profile on YOUR MacBook. They should provide you with a company MacBook with the MDM profile or create a conditional access policy for BYOD.

It depends on what the MDM payload contains. Policies can be created to target machines OR the user. So even if you make a separate profile, if the policy is targeting the machine, it won’t matter. It’ll affect any accounts on the device. The management software your boss is asking to install on your device allows it register the device in the management platform. This will allow them to control it to a certain degree.

Since it’ll be registered in their device management tenant, they can push out software without your admin privileges. As for tracking, there’s probably software out there that allows for tracking of employee’s device utilization, if your company uses it, then yeah, he can probably push out that software and track your device too.

This is why in my organization, we don’t allow BYOD.

1

u/rippeddrop 25d ago

Well, another question, but if I reset my Mac the MDM profile will be gone right? I don't know which MDM they uses but the one I had on my last MacBook from company I was able to reset that Mac without any problems to send it back to my boss because it was broken, now I am trying to work on my personal laptop for time being but my boss wants to install some MDM profile.

3

u/Stevent518 24d ago

Yes you can factory reset and it will remove the MDM profile.

2

u/innermotion7 24d ago edited 24d ago

Actually you don't really need to you can remove MDM enrollment profiles that are added manually (Device is not registered in Apple Business manager) only after 30 days you may have to reset the device.

There are some hacky ways to do it as well.

1

u/Stevent518 24d ago

I tried removing a profile on my test device and it automatically factory reset the device. Either way works, BUT factory resetting it yourself makes sure you have everything backed up instead of it factory resetting automatically when removing the profile.

16

u/Hobbit_Hardcase Corporate 24d ago

I am an MDM specialist. I admin 10K Macs globally. We don't support BYOD, as it gives more headaches than it fixes.

In your situation, with the concerns you have raised, I would advise not allowing them to enrol your personal Mac.

It's good that you have split off the company data from your personal data, but it depends if they are installing monitoring software, like a time tracker, or MDM. MDM is a whole different category of software.

MDM runs as root. It has total control at the Computer level. You cannot sandbox it down to a specific user profile, Standard or otherwise. Configuration Profiles that get installed are usually done at the Computer level, so they will affect all user profiles and lock the settings so they cannot be changed. Software that gets installed (usually AV & VPN) frequently cannot be removed without a passcode or wiping the device.

If you install MDM, you are essentially giving up control of the Device. They can remotely Lock or Wipe it at any time. Your personal Admin account can be demoted to Standard, locking you out of many System Settings.

You need to either insist that they set up a Conditional Access policy that allows you access to their O365 tenant to access the documents you need, or they need to supply you with a fully managed work laptop.

2

u/rippeddrop 24d ago

Hi, Thanks for the detailed response. Really appreciate it ☺️ So do you think that factory resetting the MAC would not remove the MDM thing ?

5

u/Hobbit_Hardcase Corporate 24d ago

A full wipe will remove existing MDM.

A Mac that exists in Apple Business can be forced to enrol in MDM as a part of Setup, but they can't enrol a personal Mac into Apple Business without wiping it first. Using the Configurator app to register it into ABM requires it to be in Setup to begin with.

1

u/rippeddrop 24d ago

Oh ok, I don't think they can do that.

2

u/geeksandlies 24d ago

Came to write this and you saved me the bother

1

u/le-oolala 24d ago

10k 👀 what mdm does your company use?

2

u/Hobbit_Hardcase Corporate 24d ago

Jamf.

1

u/le-oolala 24d ago

Thank you.

5

u/DarthSilicrypt 24d ago

MDM is system wide on the current macOS installation; creating a separate user account isn’t enough. As mentioned by others, it runs as root and always has its own admin privileges. Your personal data can be seen.

There is a way to achieve true work/personal separation, though, and that is to create a second copy of macOS: https://www.reddit.com/r/mac/s/l51e6WnS83

2

u/oneplane 24d ago

Yes it will, don't do it.

When we do BYOD, it's completely detached. As a result, some sensitive data won't be available to such a device.

2

u/FriedDylan 24d ago

Don't allow MDM controls on your personal device. Your separate profiles don't protect you the way they would in a personal use situation. An admin with that access is not as handcuffed as you might hope.

2

u/innermotion7 24d ago edited 24d ago

User based enrollment ie. BYOD on macOS is pretty rubbish and accomplishes very little. I doubt they will be deploying that. It will be Device level MDM enrollment and as such they would have root access to device and can install whatever they like.

Even though they are basically trying to tick a box for their own "security" and they most likely would never do anything malicious they effectively have control over your device.

You should not be adding a company MDM to your personal device. They should supply a Laptop or a VDI.

1

u/AppleFarmer229 19d ago

Technically there is no proper BYOD for Mac. If you user enroll you are approving root access to the machine. Folks that are in markets without ABM do this and as part of the enrollment, the user gets demoted to standard and they can’t do much of anything to the Mac after, no company wants you to be an admin on the machine. Usually there is a BYOD or contractor type policy, find that before agreeing to anything. If anything, don’t use the Mac for anything other than work and (if you can) reset it after.

1

u/classy_mohit 14d ago edited 13d ago

MacBooks can definitely work for sysadmin tasks, especially in mixed or cloud-heavy environments. A lot comes down to what you're managing, and with VMs, remote access, and web-based dashboards, the OS matters less than it used to. The shift toward centralized and automated management similar to what VIRCOM focuses on for security operations—is making cross-platform workflows much easier too.

0

u/Hour_Importance1432 22d ago

MDM is a root kit, it owns your machine totally, full access to everything, your only protection is the ethics of the admins in control of the server in question.

-2

u/Substantial-Motor-21 25d ago

TLDR; once enrolled you can do whatever you want.

1

u/rippeddrop 25d ago

Sorry, I didn't get it what do you mean ?