We have about 120 computers in our instance (1600 computers) that show the primary MDM profile isn't verified (via EA). Between the "Renew MDM" command, and the "trustjss" command, we've fixed probably 130 (we started with probably 250), but we're now down to 120 or so that refuse to play along.
Support indicates our fix is "removeMDMprofile" then "mdm" to get the machine to reinstall the management profile. For User initiated this is annoying since it's gonna prompt users, so we'll need to bomgar to remediate probably.
For the ADE machines, though, this isn't an option. I have NO idea how it broke on the ADE machines (thankfully it's only about , but for those 8, the fix is to disable sip, rip out MDM, then "profiles renew -type enrollment".
Has anyone else seen this? Anyone have better solutions? COVID makes remediation pretty difficult...