Unauthorized MDM and potential DEP abuse on Apple devices

I’m experiencing whats best described as unauthorized MDM (Mobile Device Management) and as well DEP maybe involved as well on my iOS device and spans my entire Apple ecosystem. These profiles are not visible within the OS by design, yet they are clearly using Apple’s own iOS frameworks and system-level functions to control the device.


Because the operating system treats these instructions as “normal,” antivirus and security tools will not detect this. In practice, the phone behaves exactly as if it’s functioning properly, while in reality all web traffic is silently routed through attacker-controlled servers. This creates an ongoing vector for additional payloads and compromises.


What makes this especially concerning is that Apple Support does not seem equipped to handle this type of abuse, and the invisibility of the profiles means end users have no way to verify whether their device is enrolled in unauthorized management. If a user suspects their microphones or cameras are active without consent, this could very well be occurring silently at the OS level.


The only current defensive step I can recommend to other users is running a network packet capture to see whether their device traffic is being diverted or proxied in ways they didn’t authorize.


Finally, I’d like to raise a red flag: nearly every discussion thread about this topic in Apple’s forums has been locked or closed without resolution. That lack of transparency does not add up and leaves those of us experiencing this abuse without answers or recourse.


[Re-Titled by Moderator]

Original Title: Unauthorized MDM

iPhone 15 Pro, iOS 18

Posted on Aug 17, 2025 09:40 PM

Reply
5 replies

Aug 19, 2025 04:14 AM in response to Unauthorizedmanagement

Hi, I have the same thing going on. I found a profile called attwifi.mobileconfig. It was not viewable on vpn and profiles. It has the name att on the title, but the organization is Apple Inc. There is no trust signature. I have spoken to Apple about this and they have forwarded my case to Apple security. It is not apples file. I called ATT, it is not their file. I removed the profile and it came back after an OTA update.


I got tired of everyone calling me crazy and bought a MacBook to diagnose. I extracted an imazing backup and found a lot of things in my logfiles. Create a sysdiagnose file. See if you can find the mobileconfig file and save it to a thumb drive to air gap it. Please email me at d****a@gmail.com




[Edited by Moderator]

Aug 19, 2025 04:52 AM in response to Unauthorizedmanagement

Unauthorizedmanagement wrote:

I’m experiencing whats best described as unauthorized MDM (Mobile Device Management) and as well DEP maybe involved as well on my iOS device and spans my entire Apple ecosystem.

No. You are not.

If you're actually having a problem, then describe the symptoms and what you've done to troubleshoot the problem.


Your assessment of what's wrong is nothing but a paranoid fantasy.

Aug 20, 2025 11:00 AM in response to Unauthorizedmanagement

There is no such thing as an unauthorized MDM. To install MDM, you either

  1. Must purchase the device from Apple or an authorized reseller and have it added to Apple Business/School Manager and have an MDM connected for automated device enrollment
  2. Someone must have physical access to your device and must have your passcode/password.
  3. Someone must have physical access to your device, your iCloud password (assuming you've set that up), and be in a trusted location (or wait for an hour, again, assuming you set iCloud up), then they have to wipe your device and add it to Apple Business/School Manager manually.

Option 1 cannot be removed by you because you don't own the device.

Option 2 can be removed in Settings > General > VPN & Device Management.

Option 3 can also be removed in Settings > General > VPN & Device Management if it has been less than 30 days since the device was enrolled. You would likely notice if this one was the case as again, at a minimum, it requires the device to be wiped.


These are the only options.

Unauthorized MDM and potential DEP abuse on Apple devices

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.