Firewall Profile Blocking Mac Access to Shared Drive

Randahl Thomas 60 Reputation points
2026-04-14T18:05:00.44+00:00

I recently built a Mac from the image of a different Mac. Unknown to me during, the original Mac was being managed by a profile. Recently, this profile has started to block shared drive access for one account on the device. Other accounts can access the drives

I have been unable to remove the profile from the Mac side, but was curious to see if the profile can be corrected on the Microsoft side and re-pushed to the device.

Microsoft Security | Intune | Microsoft Intune MacOs
0 comments No comments

2 answers

Sort by: Newest
  1. Catherine Kyalo 3,180 Reputation points Microsoft Employee
    2026-04-21T16:27:03.6833333+00:00

    Since the profile is MDM-managed, only the Intune administrator can modify or remove it. They need to:

    • Identify the device in the Intune admin center (Devices > macOS)
    • Review assigned Firewall and Network configuration profiles under Endpoint Security > Firewall
    • Check if the blocking profile is assigned to a user group (which would explain why only one account is affected)

    Because the Mac was cloned from another managed device, the cleanest fix is to re-enroll properly:

    1. In Intune admin center: The admin should locate the device and select Retire or Wipe to remove the management profile
    2. On the Mac: After the management profile is removed, go to System Settings > General > Device Management to confirm it's gone
    3. Re-enroll: Have the user sign into the Company Portal app and re-enroll the device fresh — this creates a clean enrollment record

    3. Quick fix — adjust the profile (if re-enrollment isn't feasible)

    The Intune admin can:

    • Go to Endpoint Security > Firewall in the Intune admin center
    • Find the macOS firewall policy affecting this device
    • Check if "Block all incoming connections" is enabled — this blocks SMB file sharing
    • Add exceptions for the file sharing service, or adjust the policy assignment to exclude the affected user
    • Sync the device: In Intune, select the device > Sync, then on the Mac open Company Portal > Check status

    4. Verify no conflicting device records

    Since the Mac was cloned, the admin should check for:

    • Duplicate device records in Intune with the same serial number
    • Delete the stale record from the original imaged Mac if it exists

    Reference Documentation

    Was this answer helpful?


  2. AI answer

    2026-04-14T18:05:24.16+00:00

    The profile can be corrected and re-pushed from the Microsoft side, but only by the Intune (or other MDM) administrator that manages the device. It cannot be removed or changed locally on the Mac if it is an MDM-managed configuration profile.

    To address the issue from the Microsoft/Intune side, the Intune admin should:

    1. Identify the managing MDM and profile
      • On the Mac, open System Settings > Privacy & Security > Profiles (or Profiles in older macOS versions) and note:
        • The MDM/management profile name (for example, “Management profile”, “Intune MDM”, or similar).
        • Any Firewall, Network, or Security configuration profiles that could affect network or file sharing access.
      • This confirms which MDM tenant/profile is controlling the device.
    2. Review Intune firewall and network-related policies for macOS In the Intune admin center, the admin should check for policies that could block SMB/file share access for certain users:
      • Endpoint security > Firewall (macOS firewall profile)
        • Go to Endpoint security > Firewall and look for macOS firewall policies assigned to this device or its user group.
        • In the macOS firewall profile, review:
          • Enable Firewall: If set to Yes, check:
            • Block all incoming connections – if set to Yes, this can block sharing services and may affect access patterns.
            • Firewall apps rules – verify that there is no app rule that blocks the process used for file sharing or VPN/agent needed for shared drive access.
          • Adjust the policy if it is overly restrictive and then save the changes.
      • Other macOS configuration profiles
        • In Devices > Configuration, filter by Platform: macOS and review:
          • Any Custom profiles (for example, .mobileconfig imports) that might contain network filters, proxies, or restrictions.
          • Any Network filter or Microsoft Defender network protection policies that could be blocking SMB or the specific shared drive host.
    3. Confirm assignment scope (why only one account is affected)
      • In each relevant policy (Firewall, Defender, Custom profiles), check the Assignments:
        • See if the policy is assigned to a user group that includes only the affected account.
        • Other accounts on the same Mac may be in different groups or excluded from the policy.
      • If needed, either:
        • Remove the affected user from that group, or
        • Adjust the policy so it no longer blocks the required shared drive access.
    4. Re-push (reapply) the corrected profile
      • After editing the policy, Intune will automatically re-apply it to targeted devices.
      • To speed this up:
        • In Intune, go to Devices > select the Mac > Sync.
        • On the Mac, open Company Portal (if installed) and trigger a Check status / Sync.
    5. If the profile must be removed instead of corrected
      • In Intune, the admin can:
        • Unassign the problematic profile from the affected user/device group, or
        • Delete the profile entirely if it is no longer needed.
      • Once removed, sync the device from Intune and from the Mac (Company Portal) to clear the settings.
    6. If the Mac was cloned from another managed Mac
      • Because the Mac was built from an image of another managed Mac, its management state and serial/identity may be inconsistent with the current tenant configuration.
      • The Intune admin should verify that:
        • The Mac’s serial number is correctly enrolled and associated with the correct user.
        • There are no conflicting device records for the same serial in Intune.
      • If necessary, the admin can:
        • Remove the old device record from Intune.
        • Wipe or unenroll the Mac properly and then re-enroll it so it receives a clean, correct set of profiles.

    In summary, the profile cannot be removed from the Mac side if it is MDM-managed, but it can absolutely be corrected or removed in Intune and then re-pushed. The Intune admin should focus on macOS firewall and network-related profiles and their assignments, then sync the device so the updated configuration takes effect.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.