We just discovered that the portion of our fleet still running macOS Mojave (10.14.6) are no longer checking in, updating their inventory, or of course executing any policies or receiving any patches.
When manually triggering a policy check-in or recon, we get this error:
There was an error.
Device Signature Error - A valid device signature is required to perform the action.
This appears to have happened to all of these machines around the same time, all showing a last check-in/update on Friday 8/12 or Monday 8/15. It doesn't appear to be happening on any of our machines on 10.15 or later.
The computers all still show they are managed, supervised, enrolled, and have MDM profile expiration dates far in the future.
Initial spot testing using the Jamf binary self-heal with Jamf API seems to get it reenrolled successfully. Unfortunately we're unsure if this will stick since we have no idea what the cause was, nor do we know if there will be any other ill effects from this error or from the self-heal. Hoping to figure out what is going on so we can be confident in a solution and a plan moving forward.
(Note that we have macOS upgrades for all of these machines planned for the coming weeks to get away from these old versions of macOS, but we now need to solve this to be able to roll them out!)
I spent some time on a call with Jamf support this morning and have an open case with them, but wanted to see if anyone else has experienced this and may have some insight while they try to track down a cause.
