Using #ZENworks to Distribute MacOS Management Profiles


Over the last little while I’ve had several questions about whether you can use ZENworks to deploy MacOS profiles. While it’s true that at this time ZENworks doesn’t yet support the native MDM-based deployment method for applying management profiles, it is possible to distribute profiles in another fashion. This solution looks at how to use the built-in ‘profiles’ command in conjunction with the free ‘profilecreator’ tool and ZENworks to build profiles and then deploy them with ZENworks. Moving forward, we still intend to extend the MDM capabilities we’ve introduced for iOS to the MacOS platform, but it's going to take some time. As such, those who need a solution for profile management today,  may find this solution useful.

    1. You will first need to create the MacOS Management Profile that you wish to enforce on the device. There are several ways that you can do this, but I’ve found the easy way is with a great community tool called ProfileCreator (available at While this solution is currently in beta I’ve had good success with it creating profiles. To use Profile Creator:

        1. Download the ProfileCreator tool from the github link above.

        1. Mount the DMG and drag ProfileCreator to the Applications folder on your administrative device.

        1. Launch ProfileCreator. The following screen is displayed:

        1. Click the button in the application.

        1. In the Name field, enter the name that you want to give to the profile.

        1. In the Description field, enter a description that the user will see if they view the installed profiles.

        1. In the Organization field, enter your organization’s name.

        1. In the Payload Identifier field, change the starting part of the name from com.github.erikbergland.ProfileCreator to something specific to your organization like com.zenguru.zenworks, leave the GUID portion to ensure it is unique. The payload properties should now look something like this: 

        1. Next, you can add one or more payload keys to the profile. In this example, we are going to set the Desktop Background. To do this browse to and click the Desktop Picture option in the Payloads list on the left side column. The following screen is displayed:

        1. Click the sign next to Lock Desktop Picture to enable this key; then click the checkbox to the right of the plus.

        1. Click the sign next to Desktop picture path to enable this key.

        1. In the text field enter $PWD/.profiles/wallpaper.png. Your screen should now look like this:

        1. Click the Add button in the upper right-hand corner of the screen to Add this payload to the profile.

        1. At this point, you could add any other MacOS or App Payloads that you wanted to set as part of this profile. When you are done, select File > Save…


    1. Next, you will need the .mobileconfig file that was just created so you can distribute with ZENworks. To do this, select File > Export… and then save the file somewhere on your filesystem. If you have a signing certificate installed on the device you can optionally choose which certificate should be used to sign the profile. Click Save.


    1. Have acces to the wallpaper you want to deploy so that it can be made part of the bundle.


    1. Next, we need to create a ZENworks bundle that deploys the MobileConfig profile to set the Desktop Wallpaper using the built-in profiles command. To do this:

        1. Launch ZCC and log in as a user with rights to create a Bundle. This can be done from your Mac or a Windows device.

        1. Browse to the folder where you want to create the bundle.

        1. Select New > Bundle…

        1. Select Mac Bundle; then click Next.

        1. Select Empty Bundle; then click Next.

        1. Enter a descriptive name and description text; then click Next.

        1. Click Finish.

        1. Click the Install tab so that you can configure Install action set properties.

        1. Select Add > Create/Delete Directory.

        1. Change the Action Name to Create Profiles Folder.

        1. In the Directory Name field, enter /Users/${ZENUSER}/.profiles

        1. Set Execution Security level to Run as logged in User. This is important because in order to use the wallpaper or other files the user will need to be able to read the file and the directory they are in.

        1. Click OK.

        1. Select Add > Install File(s).

        1. Change the action name to Install Wallpaper.

        1. Click Add.

        1. Click Add.

        1. Click Choose File…

        1. Browse to the wallpaper you want the profile to enforce and click Choose.

        1. Click OK.

        1. In the Destination folder enter /Users/${ZENUSER}/.profiles

        1. Change the Copy Option to Copy If Newer so you can update the wallpaper later on if desired.

        1. Click OK.

        1. Click the link to the file you just added.

        1. Change the filename so that it is wallpaper.png or whatever you used in the profile. The action details should now look similar to this:

        1. Click OK twice to return to the Install action set.

        1. Select Add > Edit Text File.

        1. Change the action name to Create Profile.

        1. Set the File Name field to /tmp/<mobileconfig file> where this is the name of the mobile config file.

        1. Click the magnifying glass next to Import contents from file and browse to the .mobileconfig file you created earlier.

        1. Expand the Contents of the File by pulling the lower right-hand corner.

        1. Replace the $PWD reference in the profile with /Users/${ZENUSER}. This resolves to the username of the ZENworks user currently logged into to the system. This should match the user’s home directory as long as their eDir/AD login name matches their MacOS username.

        1. Check the box that says, Create file, if does not exist. This should now look something like the picture below:

        1. Click OK.

        1. Click Add > Launch Mac Executable.

        1. Change the Action Name to Enforce Profile.

        1. Set the executable name to /usr/bin/profiles

        1. Set the command line parameters to -I -F /tmp/<mobileconfig filename> where you replace the last value with the name of the mobileconfig file you created.

        1. Set Executable Security Level to Run as root

        1. Select the When action is complete option. Your action properties should now look like this:

        1. Click OK.

        1. Click Apply.


    1. Test the bundle by assigning the new bundle to a test device in the zone.

        1. Select Relationships.

        1. Under Device Assignments, click Add.

        1. Browse to the devices that you want to be added.

        1. Click OK.

        1. Uncheck the Application Window checkbox, then click Next.

        1. Check the Distribution Schedule checkbox, then click Next.

        1. Leave the schedule set to Refresh, and then check the Install immediately after distribution checkbox.

        1. Click Next.

        1. Click Finish.

        1. Refresh the device you assigned the bundle to so that it is deployed. The wallpaper should be updated to be the one in the profile.

        1. Right click on the Desktop and select Change Wallpaper. Notice that regardless of the wallpaper you select it stays the same.

If you have users such as the helpdesk where you want them to be able to override the profile, you can create a simple bundle that executes the ‘/usr/bin/profiles -D -f’ command which will remove all of the profiles. Just be sure to execute as root, and ensure that they either reapply the profiles before they leave or ensure that the profile bundle is set to automatically apply frequently.


New Release-Feature
Comment List
Parents Comment Children