Unauthorized MDM of MacBook Pros

I have been facing security issues since I became aware that a former associate who had access to all my devices and credentials had compromised them. And despite my best efforts, It seems like every day, I am finding a new vulnerability.

Several MacBook Pros, and some iOS devices are compromised, because they all shared a unique Apple ID at some point. You all can imagine the possible damages when someone with bad intention gets his hand on that iCloud account.

Factory reset the devices was the very last solution, I wanted to use, so I kept trying to patch the issues when I was able to identify them. And recently while looking into the directories (was looking to unhide a hidden user), I found Users in local/default such as "Device Manager" "Remote Desktop" "Mobile Assets User" and while investigating further, I realized that several processes in Activity Monitor were related to RemoteManagement and several Activities and Processes with Launchd RemoteManagementAgent/ _rmdUser/ [com.apple. ManagedClient:ManagedClient] CloudConfig: Activation record cache/ 'com. apple.RemoteDesktop.PrivilegeProxy.plist etc...

I decided to wipe the devices and reinstalled the OS while making sure to create new Apple IDs to start from scratch, not install any previous online accounts etc...

Unfortunately, upon checking, the same processes were back in Activity Monitor, Service Stubs related to MDM were starting at boot, etc... I blocked all processes related to RMD in Activity Monitor, kill all related PIDs, My firewall is locked, all sharing and remote access are turned off in System Preferences, but it feels like it's not enough.

If anyone has a constructive, helpful, respectful, polite contribution, please!

I look forward hearing from you.

MacBook Pro 13″, macOS 13.2

Posted on Mar 18, 2023 1:51 PM

Reply

Similar questions

There are no replies.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Unauthorized MDM of MacBook Pros

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.