Skip to main content
Question

Macs enrolled through ADE lose all Configuration Profiles

  • January 16, 2026
  • 2 replies
  • 35 views

Forum|alt.badge.img+6

Hello!

In the last 2 years, I have had some Macs lose all configuration Profiles (including the MDM profile) when they try to renew the MDM Certificate (and fail for some reason)

Mostly that could be fixed cancelling the “Renew MDM Certificate”-Pending task in the Management-Tab and then have the User run “profiles renew -type enrollment”. 
But it surely seems like a bug, when the (non-removable) MDM profile is gone.
Has anybody seen something similar and a fix for it?

Bye, Frido.

 

2 replies

thebrucecarter
Forum|alt.badge.img+15

Not the same issue, but in the same vein, we have had the supposedly automatically renewing MDM profile not renew, then expire, causing a fair amount of problems...


h1431532403240
Forum|alt.badge.img+3

Hi Frido,

I've encountered this exact issue before. The root cause is typically related to how macOS handles MDM profile renewal failures - when the renewal process fails mid-way, macOS may end up removing the MDM profile entirely, which cascades to all dependent configuration profiles being removed as well.

What worked for me:

  1. Cancel the pending "Renew MDM Certificate" task in the Management tab (as you mentioned)
  2. Have the user run:
sudo profiles renew -type enrollment
  1. If that fails, check the device's network connectivity to your Jamf Pro server and Apple's MDM endpoints (albert.apple.comdeviceenrollment.apple.com)

Prevention tips:

  • Monitor your Built-in CA and Push Certificate expiration dates proactively
  • Create a Smart Group to identify devices with "MDM Profile Renewal Pending" status and address them before they fail
  • Ensure devices check in regularly - long-dormant devices are more prone to this issue

This does behave like a bug where the MDM profile removal shouldn't happen on renewal failure. I'd recommend opening a support case with Jamf to document this behavior - the more reports they receive, the more likely it gets addressed.

Reference: MDM Profile Settings - Jamf Pro Documentation