Posted on 02-07-2023 04:45 AM
I've deleted a mac 3 times and it re-enroll after a new installation every time.
From the GUI I've removed MDM and deleted it.
What could cause it to re-join and can I stop this from happening?
Thanks,
Posted on 02-07-2023 04:49 AM
Re-enrollment of a Mac after deletion could be caused by several factors, including:
Automated device management: If your Mac is enrolled in an MDM solution, it could be re-enrolling automatically upon activation.
Configuration profile: A configuration profile installed on your Mac may be triggering the re-enrollment.
Directory services: If your Mac is bound to a directory service such as Active Directory, the re-enrollment could be triggered by the settings stored in the directory.
To prevent re-enrollment, you can try the following:
Disconnect from the network: Disconnect your Mac from the network to prevent it from re-enrolling automatically.
Remove the configuration profile: Use the Configuration Profile Editor to remove the profile that could be causing the re-enrollment.
Unbind from the directory service: If your Mac is bound to a directory service, unbind it to prevent the settings stored in the directory from triggering re-enrollment.
Reinstall macOS: Reinstalling macOS can also help clear any settings or configurations that could be causing the re-enrollment.
Posted on 02-07-2023 05:49 AM
2. Configuration profile: A configuration profile installed on your Mac may be triggering the re-enrollment.
how would this work? if the Mac is deleted from Jamf it would need re-enrollment of some kind? By deleting the device it can no longer communicate with the jamf instance.. confused.. 🤔
Not sure about 3 and 4 won't help if its in ABM / Pre-stage..
Posted on 02-07-2023 06:28 AM
This wouldn't work. Your hunch is right, the device is caught up in Automated Device Enrollment. To be honest Jays steps to attempt to prevent reenrollment are not "wrong", they just wont work with Automated Device Enrollment in place. As far as the Configuration Profiles and Directory Services stuff, that is unrelated or incorrect depending on which item he is mentioning.
I have a gut feeling OP bought a Mac from a reseller that was not removed from DEP, or its a Stolen Mac based on the information provided.
Posted on 02-07-2023 05:24 AM
If you are a Mac Admin the Mac needs to be released in Apple Business or School Manager.
If you are someone who bought a used Mac:
Posted on 02-07-2023 07:50 AM
You indicated you deleted the Mac record in Jamf. How about the profiles that exist on the mac? Also, you stated that "after a new installation" it re-enrolls. Can you please expand what you mean by that? Are you factory resetting the mac and go through the setup process?
Posted on 02-07-2023 10:38 AM
It would seem that the unit wasn't removed from ABM/ASM and is thusly auto populating back into your JSS - where your pre-stage enrollment policies are taking over.
If you visit your prestage enrollment groups and 'uncheck' the unit and save - then complete an erase/install to it - it shouldn't 're-enroll', so to speak. It'll still be listed in the JSS and MDM - but it won't pull updates/changes/policy/etc.
Posted on 02-08-2023 04:22 AM
Sign in to Apple Business Manager with your management AppleID.
Click Devices.
Search for the serial number of this device.
Click Release from Organization.