Hello All,
What I did that appears to have broken this one machine:
I was using this one student machine to create a new bootable external hard drive to be used in order to restore the ASR image. Naturally, the machine installed MacOS, booted to the external, and then tried to enroll. I thought "No, I don't want to enroll this time" since I was just creating a clean boot image. So I went into the "PreStage Enrollment Config" that this machine was assigned to and uncheck it's serial number. This allowed me to boot the machine a second time and not be grabbed by the PreStage so I could continue to customize my boot image - Good.
Once stratified, I used the boot image to restore the ASR image onto the local hard drive and re-checked the machine with it's corresponding PreStage.
The Machine booted and did the normal "There is a configuration for this machine" thing and it created the new user and logged into the desktop like normal.
However, I noticed that the machine was not completing enrollment and the computer name in JSS was remaining "DEP - C02SXXXXXQWM" and not changing to the FLastname - C02SXXXXXQWM convention set by a policy triggered by enrollment. "Sudo jamf" indicated it didn't have the binary. and that is where the machine stays. Nothing more... no Self-Service loaded or Profiles inside System Preferences.
What I have tried:
Since we have been moving away from an old server over the past four months, we still have the old server up and running.
First, I unchecked the serial number from the "Student PreStage profile" the machine was governed by on the new JSS so that it would become unassigned.
Next, I went to Apple School Manager and pointed the serial number to the old JSS so that Apple would not direct the machine to the new JSS anymore. I "refreshed" the DEP Enrollment Program profile (if you will) and watched the "Computers Assigned" count drop one machine - as expected.
Next, I went back to Apple School Manager and re-assigned the serial number back to the new JSS and clicked "refresh" once again - the "Computers Assigned" counter increase one machine - also as expected.
Next, I went back into the "Student PreStage profile" to reclaim the serial number, expecting to find the machine serial listed again but unchecked. However, it WAS checked despite the option "Automatically assign new devices" is left uncheck in all of our PreStage profiles.
Lastely, I tried enrollment again after reformating the hard drive and ASR restoring from any bootable external and the same thing happens. A computer ID is created in JSS but the machine doesn't fully DEP enroll, deploy Self-Service, or add the MDM Profile or JAMF binary to the machine.
In summery, I was most worried that I broke the server from being able to DEP enroll any and all machines but so far based on my testings, it is only this one machine that misbehaves.
Thoughts on this? I have hundreds of other machines to turn my attention to and this particular MacBook Air can sit on a shelf but I'm one that needs to figure things like this out otherwise "I'm proud of something I raised to adulthood but it now has that one little thing that annoys you."
Thank you for taking the time to read all of this... hope my situation comes through correctly.