Hey everyone, so a couple of months ago something I always wondered about finally happened. A former staff member saw her old school-issued laptop in her device list in her Apple ID and MDM locked it from her iCloud/Find My Mac because she did not recognize the name. In the past, we were not ensuring that staff signed out of their iCloud/App Store/etc. before we imaged the machine. The machine was completely reimaged, but obviously the iCloud control remained. We've honestly been slow to embrace MDM and DEP honestly, but with imaging gone we're onboard now. Nothing like having no choice to stimulate evolution of practices. ;)
My question is, is there any way in Config Profiles and whatnot to stop them from having this ability from the start? I see there are some disallow options for certain aspects of iCloud but am not sure what is tied to what, or if disabling them would impede any of our functionality. I've trained all IT staffers to ensure they log out of iCloud, App Store, and iTunes when they leave the district, but it would be nice if that ability just wasn't there for them.