Is there a way to block older operating systems from enrolling? For instance, I'd like to set a policy that devices must be running Mojave or higher in order to be permitted to enroll.
I couldn't find a setting for this, but was wondering if someone had a script that could be run at enrollment to effectively check, un-enroll if necessary, and display a message to the user to upgrade first?
Solved! Go to Solution.
There could be older devices that don't support the newer operating systems.
Blocking vs remediating is ideal in a BYOD scenario where we can only set a policy "you must be this OS or better to enroll". It would be up to the user to determine whether or not they want to meet that policy. Other MDMs have this functionality built-in and we use it extensively for iOS.
Thanks for the suggestion on the script. Do you know of the best way to force that script to run before other policies?