What is mobileactivationd on macOS?

Last updated: 2026-07-31

mobileactivationd is an Apple-signed macOS service that manages device activation, activation certificates, and Activation Lock on supported Macs. Its traffic should normally be low and intermittent, but Apple provides no supported way to disable it safely.

What it is

mobileactivationd is a background service built into macOS. The executable at /usr/libexec/mobileactivationd is signed by Apple, and its launch configuration identifies it as com.apple.mobileactivationd. Its central job is maintaining the Mac’s device-activation state and the certificates used in activation. On Macs that support Activation Lock, it also participates in that security mechanism.

The inspected Apple binary exposes interfaces related to DEP enrollment state, so mobileactivationd can be involved in the broader setup context for managed devices. That does not make “company enrollment service” a complete description. Device activation and Activation Lock also apply outside corporate management, and Apple publishes no component-level documentation that assigns every enrollment step or network request specifically to this daemon. Automated Device Enrollment is a workflow involving more than one macOS service.

Why it talks to the network

mobileactivationd needs the network when macOS must establish, recover, or update activation state. Initial activation is one trigger. Other likely occasions include activation after the Mac has been erased and recoveryOS requesting a new activation certificate. Activation-related work can also happen around installation, updating, or restoration.

The service may become active when Find My or Activation Lock state changes. Certificate refreshes, failed-request retries, and recurring maintenance jobs provide additional reasons for later connections, even when Setup Assistant was completed long ago. This is why seeing the process online after initial setup is not, by itself, evidence that anything is wrong.

Verified endpoint categories include Apple device-activation services and Apple certificate or trust services. Observed examples include albert.apple.com, humb.apple.com, tbsc.apple.com, and static.ips.apple.com. These examples should not be treated as a complete list of every destination the daemon could ever use.

Automated Device Enrollment may take place during the same setup period. However, Apple does not publicly establish that mobileactivationd itself contacts the organization’s assigned MDM service. Other macOS management components participate in enrollment, so a connection made during managed setup should not automatically be attributed to this daemon without process-level evidence.

How much traffic is normal

There is no independently verified exact byte or megabyte figure for normal mobileactivationd traffic. A specific allowance would therefore create false precision.

The expected pattern is low and intermittent. Normal work consists of short activation, state, certificate, or trust-related exchanges rather than continuous content transfer. It should ordinarily be much smaller than traffic generated by a regular app, a system update, or a media download.

Temporary bursts or repeated requests can occur during activation, erase, restore, recovery, or certificate renewal. Network failures can also cause retries. A short cluster of connections in one of those situations is different from sustained content traffic, but the public documentation does not define a universal threshold that separates normal from abnormal use.

Can you turn it off

Apple does not provide a supported switch for disabling mobileactivationd, so there is no System Settings path to follow. Unloading the daemon or blocking all of its connections is not a supported substitute.

Doing so may prevent the Mac from activating or recovering an activation certificate. It may also break Activation Lock checks and state changes, as well as activation-related parts of managed-device setup. The timing can make the damage easy to miss: a Mac that is already activated may initially continue working and only encounter a problem during a later update, erase, restore, recovery session, or ownership check.

The complete range of possible failures is not publicly documented. That uncertainty is another reason not to treat mobileactivationd as an optional optimization target. The appropriate default is to keep it available.

What people get wrong

Seeing what it actually used

If the question is about your own Mac, the next step is to measure the process rather than infer volume from its name or an internal job label. Bytetally’s per-process statistics can show how much network traffic mobileactivationd actually used and when the activity occurred. Compare those timestamps with activation, updating, erasing, restoring, recovery, certificate renewal, or network failures before deciding whether the pattern is unusual.

Related processes

Common questions

Is mobileactivationd malware?

No. /usr/libexec/mobileactivationd is a built-in, Apple platform-signed macOS system daemon.

Why is mobileactivationd connecting to the internet?

It contacts Apple for activation, activation certificates, Activation Lock state, recovery work, retries, and recurring maintenance.

Can I disable mobileactivationd?

Apple provides no supported switch for disabling it. Blocking or unloading it can interfere with activation, recovery, Activation Lock, and parts of managed-device setup.

How much data should mobileactivationd use?

No reliable exact volume has been verified. Normal activity is expected to consist of low, intermittent exchanges rather than continuous content transfer.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account