Trying to get a handle on what might have happened to one of our laptops. We had a machine that went through pre-stage enrollment this afternoon. The inventory record shows a local user account that was created plus our standard management account. There also appears to have been a local printer that was set up. Still, the current status for the device is "unmanaged."
The management history logs show our configuration profiles being installed and then show them being removed 2 minutes later. This begs the question how the profiles were removed. The local user account did not have admin rights. Does this mean the user must have had the password for our management account? Just trying to get some idea of how these profiles could have been removed.
