What is teslad on Mac, and why is it using the network?
Last updated: 2026-08-05
teslad is Apple’s on-demand daemon for Automated Device Enrollment, formerly called DEP. Its brief network activity usually checks device assignment or retrieves enrollment configuration; it is not an iCloud sync service or the complete MDM client.
What it is
teslad is an Apple-provided device-enrollment daemon that macOS starts on demand. Its main job is to participate in Automated Device Enrollment, or ADE—the system previously known as the Device Enrollment Program, or DEP. ADE is used by businesses, schools, and other organizations to connect eligible Macs to a device-management service.
During that process, teslad helps determine whether Apple Business Manager or Apple School Manager has assigned the Mac to a management service. It also assists with obtaining the configuration needed to enroll the device. On the verified system, the executable is /usr/libexec/teslad, its code-signing identifier is com.apple.devicemanagementclient.cloudconfigd, and launchd manages it as com.apple.devicemanagementclient.teslad.
That naming history can make the process look more mysterious than it is. References to cloudconfigd, the DEP client, or the ADE client can point to the same enrollment-related role. Here, “cloud configuration” means configuration for device-management enrollment, not iCloud storage.
teslad is not the whole macOS MDM client. It handles a focused part of cloud configuration and enrollment. Broader, ongoing communication with a management service—including the continuing receipt of management commands—primarily belongs to /usr/libexec/mdmclient.
Why it talks to the network
teslad connects when macOS needs to ask Apple about device enrollment or obtain enrollment material. One expected trigger is Setup Assistant on a new or erased Mac. Another is a Mac that has been registered for ADE but has not completed enrollment and needs to check its status again. It can also become active after an Apple push notification reports an update to the device’s enrollment configuration.
Verified Apple destinations include deviceenrollment.apple.com, used over HTTPS for DEP/ADE provisional enrollment, and iprofiles.apple.com, used for enrollment profiles. If Apple reports that the Mac has been assigned to a management service, later steps in the enrollment flow can contact the organization’s designated MDM server.
The local teslad binary also contains operations related to push-token synchronization, enrollment migration, and cancellation of provisional enrollment. Apple has not published the complete trigger matrix for those operations, so it would be unsafe to assume exactly when each one runs or which request it produces.
Seeing one of these connections does not, by itself, prove that the Mac is continuously managed or that teslad is receiving routine MDM commands. The connection may only be an enrollment-status check. The device’s actual management state depends on its assignment and the enrollment configuration involved.
How much traffic is normal
Normal teslad traffic is generally zero to low, with occasional short bursts. Its verified work is closer to a small number of HTTPS API requests, device-enrollment metadata, and configuration profiles than to large system updates, cloud-drive transfers, or media synchronization.
On an unmanaged personal Mac, teslad may remain inactive for long periods because launchd starts it when enrollment work is needed. A managed or not-yet-fully-enrolled Mac may contact the relevant services when its enrollment state needs checking or updating.
Apple has not published a normal byte range for this process. There is therefore no verified megabyte threshold that separates expected traffic from a problem. Exact traffic totals, request fields, and a universal connection frequency remain unverified and should not be presented as fixed limits.
Can you turn it off
The practical recommendation is to keep teslad. Apple does not provide a supported System Settings switch for turning off this daemon, so there is no settings path to follow.
Terminating teslad or blocking the Apple endpoints it needs can prevent ADE status checks, enrollment-profile retrieval, re-enrollment, or migration between management services. On an organization-owned Mac where enrollment is mandatory, interference may leave the device stuck in the Remote Management flow or cause that flow to appear repeatedly.
Disabling the process also does not legitimately remove the Mac from Apple Business Manager, Apple School Manager, or the organization’s MDM service. Those systems hold the device-assignment records. Blocking communication merely makes the check or enrollment fail, potentially leading to retries and further enrollment prompts.
What people get wrong
- “teslad is syncing my iCloud files.” It is not an iCloud Drive, Photos, or CloudKit synchronization process. The “cloud configuration” in its signing identifier refers to device-management enrollment configuration.
- “teslad continuously uploads my browsing history or every file.” There is no reliable evidence for that claim. Its verified duties involve exchanging device identity, enrollment status, configuration, and enrollment profiles. Apple has not published every request field, so a more detailed inventory of transmitted data remains unverified. The capabilities an organization receives after MDM enrollment depend on the installed management profile and policies; they should not all be attributed to
teslad.
- “Every personal Mac should disable teslad to save bandwidth or make the system faster.”
tesladis launched on demand and is usually idle on unmanaged devices. There is no evidence that disabling it provides a noticeable traffic or performance improvement.
- “Killing teslad or blocking deviceenrollment.apple.com permanently removes MDM.” Device assignment is recorded in Apple Business Manager, Apple School Manager, and the organization’s management service. Blocking the connection can make enrollment fail, but it does not erase that assignment. It may instead produce retries or recurring enrollment prompts.
- “teslad is the entire macOS MDM client.” That is too broad.
tesladconcentrates on ADE/DEP cloud configuration and enrollment, while/usr/libexec/mdmclienthandles wider MDM communication and configuration-profile work.
- “DEP is only for large companies.” DEP is the former name of Automated Device Enrollment. ADE is also used by schools and other organizations, so describing
tesladas exclusively a large-company process is outdated and too narrow.
Seeing what it actually used
If you need to decide whether a particular burst was expected, the next step is to inspect teslad rather than estimate from total Mac traffic. Use Bytetally’s per-process statistics to see how much data teslad actually transferred, then compare the timing with setup, enrollment, or registration activity. Because Apple publishes no normal byte range, your own process history provides the most useful baseline.
Related processes
Common questions
What is teslad on my Mac?
teslad is an Apple-provided daemon that participates in Automated Device Enrollment by checking whether a Mac is assigned to a management service and helping retrieve its enrollment configuration.
Why is teslad connecting to the internet?
It may be checking the Mac’s enrollment status, retrieving an enrollment profile, responding to an enrollment configuration update delivered through Apple push, or continuing enrollment with an organization’s MDM server.
Can I disable teslad?
Apple provides no supported switch for disabling teslad. Terminating it or blocking its endpoints can break enrollment checks, profile retrieval, re-enrollment, or management-service migration.
Is teslad spyware or an iCloud process?
There is no reliable basis for claiming that teslad continuously uploads browsing history or every file, and it is not an iCloud file-sync process. Its verified role concerns device identity, enrollment status, configuration, and enrollment profiles.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account