Hi Jamf nation
For user level configuration profile to get applied, is required that the account is MDM-enabled User.
We no longer bind our Macs to the active directory, instead we use local admin account with Apple SSO Extension for the connectivity to the AD.
Using ADCS, we were able to deploy certificates in computer-level configuration profile and everything works smooth and flawlessly.
As most of our users still have incorrect MDM-Capable user, is a reenrollment to fix this issue not an option for us.
Did someone find any solution for fixing the MDM-Capable user?
Any other ideas to fix this without reenrolling the device?