Looking for advice on how to get from user-initiated to DEP enrolled for existing device population and fix Activation Lock on personal accounts.
After one of our ex-employees was able to prove that he could remote manage his old device (erased, rebuilt and issued to a new user), we need to switch from user initiated enrolment to DEP. The ex-employee had used a personal Apple iCloud ID to manage the device and it was still showing in their "Find My" of iCloud. They could play a tune or worse lock or wipe the device.
So question is how do you get existing population of devices from user initiated enrolment to DEP without needing to rebuild every machine?
A long discussion with Apple suggests the following:
- They recommend a "best practice" of using DEP but realistically this is a Mandatory Practice
- Still have no way to bring retail purchased devices under DEP
- Users using their own iCloud accounts may "Activation Lock" the device and link it to their personal account.
- Apple will only consider revoking such activations if you provide specific proof of purchase (which for us is 00's of machines across several countries)
Have others hit this issue and how did you resolve?
