After DEP enrollment of some iOS 12 devices (Manually using Apple Configurator) and then adding in ASM and eventually JAMF pre-enrollment, it seems any end user can remove the MDM profile.
Once set up, JAMF cloud shows the MDM Profile Removable as "No", but I can navigate to settings > general > profiles and remove the MDM profile (and proceeds to erase the device and removes it from ASM).
I went to the moved Parental Controls section under Screen Time and added a restrictions password. While this stops the user from erasing the device under general > reset, I can still erase the device by deleting the MDM profile (which triggers an erase).
Anyone have any pointers if I'm doing something wrong or is this a new issue?
Question
MDM Profile removable in iOS 12
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
