Skip to main content
Question

Expired MDM Profile on iPhone

  • May 13, 2024
  • 6 replies
  • 195 views

Forum|alt.badge.img+3

Hey everyone,

A device in our fleet recently stopped communicating. I checked and sure enough:

 
Last Enrollment: 21/03/2022 at 12:52 PM
MDM Profile Expiration Date: 21/03/2024 at 12:52 PM
 
We have the default renew 180 days before expiry so was a bit confused. Check logs and see Failed Command:
Command: Renew MDM Profile 
Error: The Device is locked
 
Any thought on why this may have happened? Guessing only solution is to wipe and re-enrol?
 
TIA.

6 replies

mvu
Forum|alt.badge.img+20
  • Jamf Heroes
  • May 13, 2024

Happened to me suddenly for a chunk of iOS devices. Not sure why. I added a smart group to check MDM Profile Expiration in less than 30 days, and to send an email.


Yes, I had to wipe and re-enroll for Supervised devices.


Forum|alt.badge.img+12
  • Contributor
  • May 13, 2024

Was the APNS certificate in Jamf Pro renewed with another Apple ID since enrollment of this device? Then you would have to restore to defaults and enroll at setup again.


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • May 13, 2024

Happened to me suddenly for a chunk of iOS devices. Not sure why. I added a smart group to check MDM Profile Expiration in less than 30 days, and to send an email.


Yes, I had to wipe and re-enroll for Supervised devices.


Good advice, glad it isn't just me! 


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • May 13, 2024

Good question. We did have an issue with the APNS lapsing, was only for a couple of days before I managed to resolve it. It is entirely possible this was one of a few devices that got enrolled under the wrong Apple ID. 

User is not going to be happy but wipe and re-enrol it is! 


Forum|alt.badge.img+12
  • Contributor
  • May 13, 2024

If it was a short time, then re-enrolling the affected devices(hopefully not that many) is easier than the other option, to start a case with Apple Support.  They can help migrate the APNS certificate to a new Apple ID, usually applicable to large number of devices and migration to new domain. This issue can take some time to resolve.

Advise the customer to store as much content to the cloud as possible, as restoring from backup might bring the same issue back.

Advise the customer to store as much content to the cloud, maybe they'll


AJPinto
Forum|alt.badge.img+26
  • Legendary Contributor
  • May 13, 2024

Apple does not play with these certificates. If they expire, the device needs to be reenrolled or wiped if the MDM Profile is non-user removable (which should be most cases).