Skip to main content
Question

Removing MDM Profile

  • June 2, 2026
  • 5 replies
  • 41 views

Forum|alt.badge.img+3

We’re about to sell roughly 600 of our old Macs, and I need to offboard them by removing the MDM profile before releasing them from ASM.

Doing them one by one isn't practical, so I’m looking for the best way to handle this in bulk. I already have all the machines grouped into a Smart Group. I remember hearing that I need to completely strip this group out of the scope of all active Policies and Configuration Profiles first so nothing breaks or re-applies.

I ran into some issues the last time I tried a mass offboarding a few years back, so I want to make sure I get it right this time. What is the safest, most seamless way to push the bulk "Unenroll" or profile removal command to a whole group at once?

5 replies

red_beard
Forum|alt.badge.img+8
  • Valued Contributor
  • June 2, 2026

How about unassigning them from an MDM server in Apple School Manager, then sending them a bulk erase/wipe commands as they are still currently enrolled until you wipe them so they can receive commands.

once you’ve successfully done that then you could release them from ASM when it makes sense for your resale.


PaulHazelden
Forum|alt.badge.img+13
  • Jamf Heroes
  • June 3, 2026

I agree, Unassign in ASM, and then send a Wipe to them.

Pull all of your serials into a csv, and copy and paste into the Devices search in ASM. Not sure if it will take all 600 in one go, you might need to split the list down a bit. Once in ASM, the list will show the individual devices, plus one group of all devices - thats the one to set as unassigned, it will do them all at once.
This is how I do it, and once the company picking them up shows up to take them, I then go back in to ASM and remove them. Its easy the second time round, because you have the csv of the serials.


Corey-Ribble
Forum|alt.badge.img+3
  • Contributor
  • June 3, 2026

What red_beard and PaulHazelden said would be the best way to complete you what you trying todo. Unless for some reason you are selling them not reset. 


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • June 3, 2026

Appreciate the replies.  We are selling them back to a reseller and are not being reset in-house.   We met yesterday, and I removed the MDM Profile and then released 1 from ASM and they did their check again and it was fine.  These devices are currently in bags and most are “dead”.   From their advice and steps, remove the MDM profile and then release from ASM.  Are the ways you recommended doing the same thing since they will reset them all at their warehouse?


PaulHazelden
Forum|alt.badge.img+13
  • Jamf Heroes
  • June 3, 2026

If the reseller is going to do the reset and provide you with feedback that it is done, then simply unassigning them in ASM, and or removing them from ASM is sufficient. Essentially the reseller is sending a wipe, it may be simply plugging them in and manually erasing them, or they may have a tool that will send a new copy of the OS to them.

For me I tend to Unassign and send the wipe to the devices, because I then know there is no chance of any data being compromised. Our reseller, who takes the equipment back, provides us with certification that an erase has been done. I have to trust this for any dead devices. But anything I have out in use, I prefer to wipe myself, I have trust issues. My method also tells me that I have actually unassigned them properly. Anything that rebuilds itself, or fails to wipe, can be investigated. 

 

Unassigning in ASM, will stop them after a wipe from connecting to your MDM server, they will reinstall OSX / IOS as if there is no MDM available. They will however still be in your ASM, and could be assigned again to your MDM. Removing them from ASM removes them completely, and will allow someone else to add them to their ASM.