Create a User Level macOS Install Certificate Policy

This policy lets you install a certificate for users on macOS devices so that the certificate is trusted by your organization.

Note:

This is a user level policy that applies to a user's profile across managed devices. You can bind this policy to individual users or user groups. For policies that apply system-wide to a device and all of its users, see Get Started: Policies and Learn More section of this article.

Prerequisites

  • Apple Mobile Device Management (MDM) must be configured for your organization and Mac computers must be enrolled in JumpCloud MDM. See Set up Apple MDM
  • This policy is supported on Mac computers running macOS 13 and later.
  • Target Mac computers must have an active network connection for this policy to take effect.

Considerations

  • The policy configuration settings are applied automatically and do not require a system restart.

Creating the Policy

To configure an Install Certificate policy for Mac computers, do the following:

Selecting the Policy Template

  1. Log in to the JumpCloud Admin portal.

Important:

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Device Management > Policy Management. The Policy Management page is displayed.
  2. On the Policy Management page, click +Add New.
  3. Select User Policy to assign the policy to users and users groups. On the New User Policy page:
    • Select the macOS tab.
    • Search and select the required policy and click Configure. The Details tab of the policy is displayed.
    • On the Details tab, configure the required policy configuration settings.
    • (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
    • (Optional) In the Policy Notes field, enter details such as creation date of the policy, and information on testing and deployment of the policy.

Configuring the Policy

  • Under Settings, select Certificate Type and choose the type of certificate you want for the policy.

Note:

The four certificate types available are: PEM, PKCS #1, PKCS #12, or root.

  • If you chose the PKCS #12 certificate type, enter the Passphrase for it.

Note:

The Passphrase field only displays after selecting the PKCS #12 certificate type.

  • In the Base64-Encoded Certificate field, click upload file. 
  • Select the certificate you want to deploy using this policy and click Open.
  • Select Set Payload Certificate Filename to type a filename for the certificate.

Applying the Policy

  • (Optional) Select the Policy Groups tab. Select one or more policy groups where you want to add this policy. 
  • Select the User Groups tab. Select one or more user groups where you want to apply this policy. For user groups with multiple OS member types, the policy only applies when a user logs into a supported Mac computer that is enrolled in Apple MDM.
  • Or, select the Users tab. Select one or more users to whom you want to assign this policy to.
  • Click Create Policy. A success message is displayed indicating the completion of policy creation.

Viewing Policy Status

  1. Select the Status tab.
  2. To see the last Result Log for a device where this policy is applied, click view.

Note:
  • If any errors occur, they're listed in Exit Status. If you have an Exit Status of 0, no errors occurred when applying or enforcing this policy.
Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case