This guide explains how to identify and fix configuration profile delivery failures for EPM macOS when installed through an MDM software.
This profile is responsible for enabling background services and applying the necessary permissions for the agent to function properly. Without it, EPM cannot start correctly.
Requirements
- EPM macOS agent installed via MDM. More information in How to install the EPM macOS agent via MDM.
- Configuration profile.
- Access to the macOS Terminal.
How to identify profile delivery failure
- The issue occurs when the profile was not delivered or activated by the MDM.
- The end-user cannot manually fix this because administrative privileges are not available.
- Without the active profile, the background service of EPM does not start.
How to request profile re-delivery
- Contact the support team responsible for managing the MDM tool.
- Request that they resend the profile via the MDM tool.
- Re-sending forces the delivery of the configuration profile to the device.
How to verify in macOS settings
- Go to System Settings > Profiles.
- Confirm whether the EPM macOS profile is listed.
- If it is not listed, it means the profile was not delivered correctly.
How to check system extension via terminal
- Open terminal and run: systemextensionsctl list
- Check if the extension Segura EPM Endpoint Security Extension appears active and functional.
- Absence of this extension indicates the profile was not applied.
How to inspect profile-triggered activations
When delivered correctly, the profile automatically enables configurations such as:
- Enabled Endpoint Security extensions.
- Configured Login Items.
- Background execution permissions for the EPM client.