̽»¨´óÉñ policies can help you customize, manage, and secure macOS or iOS devices that are enrolled in MDM. If you need a policy that isn’t available as a ready-to-use policy in the ̽»¨´óÉñ Admin Portal, you can create an MDM custom configuration profile policy to help you distribute payloads and policies to devices.
A custom configuration profile is an XML file with an extension of .mobileconfig. You can use GUI tools like Ìý´Ç°ùÌý, or a manual tool like  to create the custom configuration profile. To see available payloads you can include in a configuration profile, use the  maintained by the MacAdmins community.
Considerations:
- The custom MDM configuration profile is automatically installed to all users on a device. ̽»¨´óÉñ signs the custom configuration profiles that are uploaded to the policy and modifies the following attributes within the profile:
- PayloadIdentifier
- PayloadUUID
- PayloadRemovalDisallowed
- MacOS devices with M1 chips require additional considerations if you are deploying kernel extensions as part of a custom MDM profile .mobileconfig payload. See and consider using system extensions instead.
Prerequisites:
- MDM is configured for your organization. For more information, see Manage Apple Devices with MDM.
- Your devices are enrolled in MDM.
To create a macOS or iOS MDM Custom Configuration Profile policy:
- Log in to the .
- Go to DEVICE MANAGEMENT > Policy Management.
- In the All tab, click (+).
- On the New Policy panel, select the Mac or iOS tab.
- Select MDM Custom Configuration Profile from the list, then click configure.
- (Optional) Edit the Policy Name to enter a new name for the custom configuration profile policy or keep the default.
- Under Settings, click upload file.
- Select the .mobileconfig file you want to upload and click Open.Ìý
°Õ³ó±ðÌý.mobileconfig file lets you upload and distribute MDM custom configuration profiles to macOS or iOS devices that are enrolled in ̽»¨´óÉñ MDM.

- (Optional) Select the Device Groups tab, then select one or more device groups on which to apply the policy.
- (Optional) Select the Devices tab, then select one or more devices on which to apply the policy.
- Click save.