Join our Newsletter — 33% off our NHI Course
Authentication, Authorisation & Trust

Mobile Account

← Back to Glossary
By NHI Mgmt Group Updated September 28, 2026 Domain: Authentication, Authorisation & Trust

A mobile account is a local Mac user account that can retain a user’s files and preferences while the device is connected to a directory service. It is used when admins want directory-based authentication without forcing all user data to remain dependent on network access.

What a Mobile Account Is in macOS

A mobile account is a local Mac user account that can continue to work when the computer is away from the directory service, while still carrying the user’s files, settings, and login experience with it.

The key idea is resilience: the account is created to give users a consistent desktop on a managed Mac without making everyday use depend on constant network connectivity. That makes it useful in offices, on travel, or anywhere directory access may be intermittent.

How Mobile Accounts Work

On a connected Mac, a mobile account is tied to directory-based authentication at first, then cached locally so the user can sign in even when the directory source is unavailable. The local profile remains on the device, so the user keeps preferences, app state, and documents that are stored on the Mac itself.

Because the account is both local and directory-linked, it sits between two worlds: centralized identity management and offline usability. In practice, this means the Mac must reconcile the local record with the directory record, including the username, group membership, and password state when the user later reconnects.

This design is different from a purely local account because the identity relationship still matters, but the day-to-day login path can survive a temporary loss of directory connectivity.

Security Implications of Mobile Accounts

Mobile accounts reduce dependence on the network, but they also create a second copy of user state on an endpoint. That increases the importance of endpoint hardening, password policy, and account lifecycle hygiene, because the device can continue to accept the user’s credentials even when it is disconnected from central control.

They also create the usual risks of any cached or locally persisted login path: if the Mac is compromised, an attacker may gain access to the local profile, the stored preferences, or any data saved on the machine. For that reason, macOS account caching should be treated as a convenience with security trade-offs, not as a substitute for directory governance.

Mobile accounts can also complicate troubleshooting and access review. When a directory account changes, the local account may not immediately reflect the same state, so administrators need to understand where the authoritative record lives and how quickly changes propagate.

When Mobile Accounts Are Used

Mobile accounts are most useful where users need a consistent Mac login but cannot rely on uninterrupted network access. They are common in environments that want central authentication for managed devices, yet still need local usability for laptops, field work, or travel.

They are less attractive where strict central control is the priority and offline persistence adds too much operational risk. In those environments, organisations may prefer other account models or tighter endpoint management so that local state does not drift too far from the directory source.

For readers comparing account types, the practical question is not whether the account is local or directory-backed, but whether the organisation is prepared to own the security and lifecycle implications of keeping a usable local identity on the machine.

Risk and Threat Considerations

Mobile accounts can widen the exposure window on a Mac because a valid local login path may remain usable after the device leaves the directory-controlled environment. That is valuable for availability, but it also means offline access, cached credentials, and local profile data deserve the same level of scrutiny as any other endpoint trust boundary.

Failure mechanism: If the local account, password cache, or endpoint is compromised, an attacker may use the retained login state to access the user session or local data without needing live directory access.

Impact: The result can be unauthorized access to files, preferences, and application state on a managed Mac, plus greater difficulty revoking access immediately when central identity changes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Mobile accounts still rely on user authentication and cached login state.
IA-5 — Authenticator ManagementThe account depends on password and credential lifecycle management across offline and directory-linked states.
AC-6 — Least PrivilegeA retained local account can preserve access beyond directory availability, making privilege minimization material.
Recommendation — Apply IA-2 to control how managed users authenticate on Macs. Use IA-5 to manage password change, storage, and reuse rules for mobile accounts. Apply AC-6 to limit what a mobile account can access on the Mac.
ISO/IEC 27001:2022A.5.15 — Access controlMobile accounts are an access-control pattern that balances directory authentication with local persistence.
Recommendation — Define access-control rules for when cached local Mac accounts are allowed.
CIS Controls v8CIS-5 — Account ManagementThe term concerns how user accounts are created, used, and controlled on endpoints.
Recommendation — Use CIS-5 to govern the lifecycle of Mac accounts that persist offline.

Practitioner Guidance

Why practitioners should care: Mobile accounts are a usability feature with identity and endpoint-security consequences. Treat them as part of the device trust model, not as a neutral convenience setting.

Governance implication: Administrators should define when offline local accounts are allowed, how password changes propagate, and what happens when a device falls out of directory contact for an extended period. The important decision is whether local persistence is an accepted business requirement or an avoidable control exception.

Practitioner takeaway: Use mobile accounts only when offline usability is genuinely needed, and make sure the surrounding endpoint, directory, and access-review processes are designed for that persistence.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org