Learn how Mac device management really works
Apple ships a device management framework capable of content filtering that actually holds — and almost nobody has written about applying it this way. These guides teach you how, start to finish, so you can do it yourself.
Why this exists
Consumer filtering tools were never built to stay installed
Most content filters live inside a single browser or a single app. They can be uninstalled in under a minute, bypassed with a second browser, or quietly disabled in a moment of weakness. For anyone genuinely trying to protect their attention and their integrity, a control that disappears on demand is not a control at all.
Apple already ships the answer. The same framework that schools and enterprises use to configure thousands of Macs can be applied, at any scale, to enforce filtering that persists across browsers, user accounts, and restarts. Hardly anyone teaches it this way.
What managed configuration changes
- Policy applies at the OS level, not inside one browser
- Supervised profiles cannot be silently removed by the user
- Restrictions survive restarts, new accounts, and new browsers
- Software updates and security settings are enforced centrally
- Every applied profile stays visible in System Settings
The curriculum
Seven guides, in order
Start with Foundations — those cover the concepts everything else depends on.
What Mobile Device Management actually is
The plain-English version of how Apple's management framework works, what a configuration profile is, and why it behaves differently from an app you install.
Read guide→Why content filters get removed, and what stops it
Supervision is the single technical difference between a filter that can be uninstalled in thirty seconds and one that cannot. Here is what it is and how a device gets it.
Read guide→What Mac device management can actually cover
Six areas the framework handles well — filtering, tamper resistance, reporting, hardening, multi-device policy, and maintenance — and the boundaries worth refusing to cross.
Read guide→Content filtering on macOS: the options compared
DNS filtering, the built-in content filter payload, Screen Time restrictions, and third-party services — what each one actually covers and where each one leaks.
Read guide→Do you need Apple Business Manager?
What Apple Business Manager is for, what Automated Device Enrollment gets you, and the honest answer for a family with two Macs already sitting on a desk.
Read guide→Planning a deployment, step by step
Working out what you need, writing it down before you install anything, enrolling with consent, verifying it actually works, and reviewing it as circumstances change.
Read guide→How to talk about managed devices with your family or congregation
The technical work is the easy half. This is about consent, disclosure, and the difference between accountability and surveillance — in the conversation, not just the config.
Read guide→The view underneath
Accountability, not surveillance
The same tools can support someone's own commitment or be used to monitor a person who never agreed to it. The technology is often identical; the difference is consent and disclosure. Every guide here is written from that position, and says so.
- Management belongs only on devices whose user knows about it and agreed to it.
- Write down what a configuration does before installing it, even for yourself.
- Collect the least data that accomplishes the goal, and say plainly what is collected.
- A managed device should always disclose that it is managed.
- Every setup needs a clean, documented way out.
Common questions
Before you dive in
What is this site?
A free set of written guides teaching how Apple's device management framework works and how to apply it to content filtering and accountability on macOS. There is remarkably little published on this specific use of MDM, so this is an attempt to write it down properly.
Does any of this apply to iPhone and iPad?
Much of it does. Apple's management framework covers iPhone and iPad as well as Mac, and the concepts — configuration profiles, supervision, enrollment — are shared across all three. These guides focus on macOS because that is where the gap in available writing is widest, but the general shape carries over.
Why use MDM instead of a browser extension or a single app?
Extensions and standalone apps generally run inside one browser and can be removed by the person using the computer. MDM configuration profiles apply at the operating-system level across browsers and user accounts, and on a supervised device they cannot be silently removed. That durability is the entire point when the goal is accountability.
Does this involve monitoring everything someone does?
No, and the guides argue against that approach. Apple's MDM framework does not provide keystroke logging, screen recording, or camera access at all. What it provides is configuration — filtering, restrictions, update policy — plus, if someone chooses it, summary reporting of blocked attempts to a person they named.
Do I need to be technical to follow these?
The Foundations guides assume no background beyond ordinary comfort with a Mac. The Technical guides get more specific, but they explain concepts rather than assuming you already know them. Start at the top and read in order.
Is any of this specific to a particular religion?
The guides are written to be useful to anyone configuring a Mac for content filtering, whatever their reason. Some reference churches and ministries because that is the context this work came out of, but nothing in the technical material depends on it.
Found a mistake?
Corrections are the most useful thing you can send. Apple changes its platforms constantly and no write-up stays accurate on its own. I read everything that comes in and will get back to you as soon as I can.