There should not need to be an alert for this. Also the moment the MDM profile is removed, Jamf Protect loses all of its permissions. I'm not sure if it could reliably report on this event.
My suggestion, ensure you are using Automated Device Enrollment and check the box to disallow removal of the MDM profile. Once you do this not even an Admin can remove the MDM profile.
Another suggestion is to look in to an Endpoint Permissions Tool to handle elevated access situations, remove admin access from users and write policies with the tool to auto escalate the function they need to perform and nothing else.
There should not need to be an alert for this. Also the moment the MDM profile is removed, Jamf Protect loses all of its permissions. I'm not sure if it could reliably report on this event.
My suggestion, ensure you are using Automated Device Enrollment and check the box to disallow removal of the MDM profile. Once you do this not even an Admin can remove the MDM profile.
Another suggestion is to look in to an Endpoint Permissions Tool to handle elevated access situations, remove admin access from users and write policies with the tool to auto escalate the function they need to perform and nothing else.
Yes, but we had problems with profiles from time to time, so the IT must have a possibility to remove them manually without deleting the device.