We have been using Jamf for some time and have all our current computers successfully enrolled. At this point the overwhelming majority of Macs are running Mojave. The Macs have all been enrolled used a QuickAdd package.
We are now preparing to allow Catalina. Some of these Macs have T2 chips and with Catalina will therefore be able to support the new Activation Lock feature. (Which sadly Jamf have yet to support themselves.)
The only method to escrow recovery keys for Activation Lock requires the Macs be enrolled via DEP rather than any other method. I therefore wish to re-enrol the T2 Macs via DEP.
Obviously this means removing the enrolment profile on the Mac itself and re-enrolling via DEP. What I would like clarifying is the best way to handle the following.
The Macs being already enrolled already have a jamfmanager account both on the Mac and in their Jamf computer record with the password synced between them. If I simply remove the enrolment profile the record remains in Jamf. Furthermore there is also already a FileVault recovery key escrowed to the Jamf record and there is also a local admin account with its password stored as an encrypted extension attribute. Therefore merely deleting the computer record to start completely from scratch would definitely not be desirable.
I also want to avoid wiping the Mac, building it encrypting it etc. etc. all again, this approach would obviously work and ensure all the above is correctly re-recorded in Jamf.
So what is the most effective way to re-enrol without losing all that information?
For what its worth we have not used DEP to start with because -
1. When I joined DEP was not setup with Apple due to a registration problem which I have since solved
2. As a result of the original registration problem some computers have been bought before DEP was setup and cannot ever be DEP enrolled
Fortunately as I did sort out DEP registration when I joined, even though it has not so far been used all the T2 equipped Macs are registered to Apple for DEP so we can now do so.
