Skip to main content
Question

Macs losing their MDM capability

  • August 28, 2018
  • 39 replies
  • 264 views

Show first post

39 replies

scottb
Forum|alt.badge.img+18
  • Valued Contributor
  • August 29, 2018

Thanks, @mconners - re-imaging, etc. is not an option at all for us.
I really hope that there are some dedicated brain cells allocated at Jamf for this.


Forum|alt.badge.img+16

@scottb I can't remember the exact steps, but support did mention steps about removing the MDM profile when it is not allowed in your PreStage. Found this blog that talks about disabling SIP and then being able to remove the profiles, might be your only other option.


Forum|alt.badge.img+10
  • Valued Contributor
  • August 29, 2018

Just to throw my hat into the ring. We are moving to a provisioning workflow with DEP. I have a campus that provisioned a lab of computers, reassigned them to the static group. The appropriate profiles were applied life is beautiful. Then the tech changed the building in a mass action from Jamf. All of the computers disappeared from the static group. After investigating the computers were unmanaged, MDM capability no and User approved MDM No. The profiles were still on the computer even though they were no longer in the static group that the profile was scoped to. The MDM was verified and approved on the machine.


Forum|alt.badge.img+20
  • Author
  • Valued Contributor
  • September 5, 2018

Hello All, it appears we have run into a critical product issue, PI-004892 - Enabling User Level MDM on 10.13.2+ Removes 'User Approved MDM Enrollment' Approval. Talking with Jamf this morning, they have identified as being the case.

Well it certainly makes me feel better to know this wasn't anything I could have controlled. It is still upsetting knowing I don't have a work around.

From Jamf this morning, The language is slightly different from the exact behavior we're seeing, but from the logs it's definitely the same cause. Right now the issue is marked as critical, and there's no workaround aside from the two we did talk about (manually touching each machine with an erase or temporarily turning off SIP).

Unfortunately that leaves us stuck where we are until this product issue is resolved.

I think as I run into these computers, I will have to touch them one way or another. I also expect after the fix is in place, I will still have to touch them. Going to be a rocky start to the semester.


Forum|alt.badge.img+7
  • Contributor
  • April 11, 2019

We are now running into this issue.


Forum|alt.badge.img+1
  • New Contributor
  • September 30, 2019

Same here. It's alarming since it's more than a year ago that it was discovered according to this thread. We are soon handing out about 350 new MacBooks...


coachdnadel
Forum|alt.badge.img+12
  • Jamf Heroes
  • September 30, 2019

We are also starting to see this issue. I have had to wipe 3 computers in the last week.


Forum|alt.badge.img+20
  • Author
  • Valued Contributor
  • September 30, 2019

After seeing your updates @miwe01 and @coachdnadel I looked and guess what, I am too seeing this on a couple of Macs. I don't get how this is happening. These are showing up the majority are faculty computers so I can't do much in the way of wiping these to reset back to MDM yes. So we will have to wait this out until they have issues or we find a fix.


akamenev47
Forum|alt.badge.img+10
  • Valued Contributor
  • November 7, 2019

same here, starting seen this issue


Forum|alt.badge.img+6

This has been happening for us as well, multiple older computers that were not "imaged" via the New way or via the MDM enroll via the Prestage Enrollment will have this. when i looked at this month ago , the only SOLID way to shake this is to "reimage" the mac completely and re-install the os with all Prestage enrollment stuff already setup, they will install the JAMF binary via the "supported" way and MDM will not be an issue going forward.

For me this is a huge headache, as we can't "Yank out" older 2-4 year old machines just to correct this issue. , on a filp side they are still checking in and are not going 'DARK" But this "RED" MDM is really Vexing.


mani2care
Forum|alt.badge.img+7
  • Contributor
  • March 19, 2021

The perfect solution is without doing the action

sudo jamf mdm -userLevelMdm
sudo Jamf manage

MDM Capability: Yes will be changed


eos_bebu
Forum|alt.badge.img+1
  • New Contributor
  • February 9, 2022

Did you check your ports for Apple Push Notifications (APNs) ? 
If your Apple devices aren't getting Apple push notifications - Apple Support


Forum|alt.badge.img+10
  • Contributor
  • February 11, 2022

The perfect solution is without doing the action

sudo jamf mdm -userLevelMdm
sudo Jamf manage

MDM Capability: Yes will be changed


Hi, when I run 

sudo jamf mdm -userLevelMdm

I get: The mdm verb is not available on this version of macOS.


whiteb
Forum|alt.badge.img+9
  • Valued Contributor
  • June 9, 2023

We have a very small handful of machines like this. They still have all of our profiles installed and are checking in, but no management commands available in Jamf + MDM Capability shows 'No'.

sudo profiles renew -type enrollment

Running the above, even with an existing MDM Profile installed, fixed the issue.

I tried a sudo jamf enroll -prompt to re-enroll first, which completed without issue, but still MDM Capability 'No' and no management commands for the computer in Jamf.

Only after running the profiles renew command and accepting the little message that pops-up did the computer get fixed. This computer was an M1 iMac on 13.2.1.

Appears some computers lose their MDM Capability for no apparent reason.