Configuration profiles

Deploy and remove reviewed Apple or Windows settings through your workspace’s management engine.

On this page

Configuration profiles deliver operating-system settings to enrolled devices. Beam accepts Apple .mobileconfig files and Windows .xml profiles through the Configuration profiles section of Device management. Owners and administrators can manage profiles; security managers and auditors can inspect MDM read-only.

Understand the target group

Profiles created here apply to matching Apple or Windows devices in the Fleet engine's Unassigned group. Existing Fleet groups retain their own profiles. Beam does not expose a group-targeting editor or per-device assignment picker for this workflow.

Deploy a profile

  1. Prepare a reviewed profile using your platform's configuration tools. Confirm that the payload supports the target OS and enrollment type.
  2. Open Device management → Configuration profiles.
  3. Under Deploy a configuration profile, choose the .mobileconfig or .xml file. The maximum is 500 KB.
  4. Read the confirmation describing the engine's Unassigned group and submit Deploy profile.
  5. Record the operation ID and check the resulting status in Operation history.
  6. Verify profile delivery on a representative device and in the provider console.

A provider's acceptance only establishes that it accepted the request. Devices can apply settings later when they check in. Beam does not inspect every operating-system effect of an arbitrary profile.

Remove a profile

Find the existing profile by name and platform, choose Remove profile, and review the confirmation. Check the assigned devices after they check in. Removing a profile can remove restrictions or settings your organization relies on, so coordinate the change with the policy owner.

The listing may show only the first 100 profiles. Use the provider console to inspect a larger configuration set before assuming a profile does not exist.

Diagnose delivery failures

Check enrollment, platform compatibility, group assignment, and last check-in. If the request outcome is unknown, inspect the provider before retrying. Keep profile content out of support tickets when it contains private certificates, network settings, or credentials; share the operation ID and a redacted description instead.

Explore the docs