hardware is the top trust rung. It is Apple’s statement that this provider identity belongs to one genuine, well-configured Mac. The caller grants it. You never claim it.
The installer and mifr start walk you into enrollment after the node registers. The provider is already serving at transparent before you click, so skipping the profile does not block install. Callers who require hardware (the hosted API does, by default) will not pick an un-enrolled Mac.
What you install
Enrollment writes a configuration profile to~/Downloads/mifr-hardware.mobileconfig and opens it. Install it from System Settings: Profile Downloaded, or General then Device Management. Approve with your password.
The profile grants three inspect rights only: profiles, device information, and security information. No erase, no lock, no wipe, no app management. Remove it at any time to withdraw.
macOS allows one MDM per device. If this Mac is already managed by another profile, the installer reports that and skips. It never silently claims you are enrolled. Remove the other profile, then enroll again.
What Apple signs
Apple Managed Device Attestation signs a certificate chain for this Mac. The leaf carries serial number and UDID. Callers can fetch the chain and check it. Completions at the hardware floor name the serial. The posture the caller requires: SIP on, Secure Bootfull, ARV on, and a SecurityInfo sidecar at most 25 hours old.
Do not enroll a Mac whose serial must stay private.
Apple issues a fresh attestation at most once per device per 7 days. If another MDM attested this Mac inside that window, the first publication waits until Apple’s cache reopens. The service retries on its own.