We have an interesting situation.
Last year we discovered an issue where about 630 of our devices never renewed their mdm profile, and they are now unable to get any management commands or profile updates. We have a decent solution that takes about 5 min per device to turn of csrutil and then remove the profiles and then re-enroll, however we have also found that one of the profiles is causing issues for testing that is currently going on. The profile in question adjusts the "Parental Controls" to try to block adult websites with its content blocker. We turned this one on back in 2020 and it originally allowed parents of students to use the screen time function. This appears to no longer be necessary since you dont now need this feature on to turn on screen time, but now since the mdm is expired we cannot remove or adjust this setting without many steps.
Im hoping someone in the community can tell me a way to write the plist or a defaults command that can supersede the non-removable profile settings so we can turn this feature off and get our testing back on track without having to totally reenroll the machine (after 3 restarts).
