Import Apple profiles into Sophos Mobile: configuration or app provisioning?
Short answer: Under Policies > iOS & iPadOS or Policies > macOS, you can import an Apple configuration profile using Create > Import policy. An entry in the policy list does not mean the profile is installed on a device. An app provisioning profile is a different file type for custom-developed iPhone/iPad apps; it is unavailable on devices with Apple User Enrollment. Distinguish the file and delivery route before assigning anything.
Before importing: check the file and target devices
Check the tenant and role first: The tenant must have an active MDM-capable Sophos Mobile license for the target platform (Sophos Mobile Device Management or Sophos Mobile with MDM included); Sophos Mobile Threat Defense alone does not grant MDM rights. The person performing the import must be able to create and manage imported Mobile policies with their actual tenant role and, separately, be permitted to assign the policy for the pilot. Sophos Mobile distinguishes administrator, helpdesk, and read-only access; custom Sophos Fusion roles may restrict policy management and assignment differently. Check permissions and available actions in your own tenant rather than assuming a particular role name or set of permission labels. Import/Save creates a policy; only a separate assignment can deliver the configuration to target devices. Neither creation nor assignment proves that a device received it or that it took effect.
- File type and approval: A configuration profile has the
.mobileconfigextension and may come from Sophos Fusion, Apple Configurator, or a trusted third party. Sophos Mobile does not accept encrypted configuration profiles. Decrypting one does not justify an uncontrolled upload: establish the file’s origin, approved version, reviewer, certificates/identities, secrets, and secure storage beforehand. For an app provisioning profile for iPhone/iPad,.mobileprovisionis the relevant extension to look for; downloaded provisioning profiles may also use.provisionprofile, but that does not establish suitability for import into iOS/iPadOS. A filename extension alone verifies neither contents nor signature. - Target: For each payload in the specific configuration profile, check the OS version, device or user channel, enrollment type, supervision where applicable, and whether duplicates are allowed against Apple’s payload rules. The presence of an upload option does not mean every setting is available on User Enrollment devices.
- Conflicts: Compare the profile-level
PayloadIdentifierand the identifiers of individual payloads in the existing and proposed profiles. Identifiers alone are not enough: Also check payload types and the actual setting keys and values in already assigned profiles and the new file for overlap. Different profile identifiers do not prevent settings conflicts. Within a configuration profile, each individual payload must have a uniquePayloadIdentifier; iOS/iPadOS 15 and macOS 12.0.1 or later enforce this rule. A profile with the same top-levelPayloadIdentifieris treated as an update on installation; when the values differ, two profiles may coexist if the payload type allows it. When replacing a profile, macOS matches payloads byPayloadUUIDand removes payloads no longer included; iPhone and iPad match them by theirPayloadIdentifier. When updating the same payload, retain itsPayloadUUIDto minimize interruptions where possible; this guarantees neither freedom from conflicts nor an interruption-free transition. None of this establishes a blanket precedence rule for overlapping settings; in particular, Sophos’s most-restrictive-setting rule for native macOS device, user, and declarative policies is not established as a general precedence rule for imported profiles. If the effect is unclear, do not assign the profile; test the specific combination in an approved pilot instead.
Import an Apple configuration profile (.mobileconfig)
- In Sophos Mobile, open Policies > iOS & iPadOS or Policies > macOS, as appropriate for the target file.
- Select Create > Import policy.
- Enter a meaningful name and description, such as the purpose and intended pilot group. These are freely chosen details, not settings that determine the profile’s effect.
- Under Upload a file, select the reviewed
.mobileconfigfile and click Save. - Check that the new policy appears under Policies - iOS & iPadOS or Policies - macOS. This confirms only the import.
Then assign selectively and observe. Once the payload and enrollment mode have been approved, go to Policies > [device platform], open the blue triangle beside the imported policy, select Assign, choose a pilot device or pilot group, and finish with Finish. Scheduling appears only for certain policy types; neither scheduling nor a separate update task should be assumed for an import. Sophos Mobile distinguishes synchronized policies from policies installed through tasks; the import alone does not reliably establish the delivery mode of the specific file. In the pilot, therefore, check the assignment, synchronization or task status where applicable to the actual type, and receipt on the device; do not infer a universal update or uninstall procedure.
Special case: app provisioning profile (.mobileprovision) for iOS/iPadOS
An app provisioning profile here is for a custom-developed iPhone/iPad app, not for general device configuration. The development team creates it beforehand; this profile type is not available for Apple User Enrollment. Under Policies > iOS & iPadOS > Create > Import policy, enter a name and description, then use Upload a file and Save. The imported policy can then be assigned to devices. Separately, the Install provisioning profile and Uninstall provisioning profile task types exist for iOS/iPadOS task bundles; the installation task selects an app provisioning profile that has already been imported and is also unavailable for User Enrollment devices. Do not treat both delivery routes as mandatory successive steps. Test the appropriate route and its rollback in an authorized pilot for your own tenant; neither the separate task nor its removal is equivalent to installing or removing an ordinary configuration profile.
Clarify with the app owners in advance whether the profile will be installed separately or embedded in the .ipa. Check the app signature, app ID, entitlements, permitted devices, and expiration date separately against the signed app and its provisioning profile; an arbitrary .mobileconfig does not give the app signing rights. If the provisioning profile has expired or app services have been enabled or disabled, the app owners must regenerate the profile and re-sign the app with it; separately test any re-import or replacement in Sophos and the subsequent effect on devices in the pilot. Successful policy assignment proves neither that the app was installed nor that it can launch.
Pilot checks and rollback
Before the pilot, document existing profiles, the relevant function, and an alternative management/network access path. The reviewer records at least: the approved file and version, approvers, test device with enrollment type and OS, initial state, chosen delivery route and target assignment, and synchronization/task status where applicable. Then determine separately: (1) Is the assignment in place? (2) Is delivery still pending, or has an error been reported? (3) Is the expected profile, with the matching identifier, present on the device? (4) Does the specific setting work in the intended workflow—or can the intended app be installed and launched? A completed task alone does not answer the last two questions; if the expected effect is absent, check enrollment type, payload suitability, and profile conflicts before importing more profiles.
Rollback depends on the actual policy and profile type: Uninstall policy in Sophos Mobile is limited to Android device, Knox container, and iOS device policies; for other policy types, the product guidance points to updating or assigning another policy. For iOS User Enrollment, the separate Unassign iOS user policy task is provided for user policies. The separate iOS/iPadOS Uninstall provisioning profile task concerns app provisioning profiles, not imported configuration profiles in general, and is unavailable for User Enrollment. A safe uninstall procedure for a specific imported policy cannot be inferred without checking it in the tenant. Removing a configuration profile may remove managed accounts or network access; removing a provisioning profile may disrupt a custom app. Removing a configuration profile can also remove associated apps and data; whether any are associated depends on the particular profile. Before any removal, inventory affected profiles, settings, apps, and data, and ensure that at-risk data has an approved backup and a tested recovery path; otherwise, do not remove the profile. Document pilot removal and restoration of necessary access and functions, and obtain sign-off from the responsible change owner. Recommendation: Do not authorize broad deployment without observed effects on devices and a confirmed rollback path; the precise approval process depends on your organization. This guide documents no device or tenant testing performed.