Skip to main content
Question

Jamf Configuration Profiles Stuck Pending

  • November 11, 2021
  • 57 replies
  • 1349 views

Forum|alt.badge.img+3

I am having a handful of systems with Configuration Profiles stuck in pending state. Does anyone know of a fix for this?

 

These systems are all Automatic Device Enrolled, they are checking regularly to jamf. I have tried having them reboot, sending blank push from management commands. 

 

These commands have been pending for months.

 

57 replies

Forum|alt.badge.img+9
  • Contributor
  • November 12, 2021

@dthompson1  you can troubleshoot MDM from client side with log command. 

log stream --info --predicate 'processImagePath contains "mdmclient" OR processImagePath contains "storedownloadd"'

 

Immediately after clicking on "Send Blank Push" the client should return a log.


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • November 12, 2021

@dthompson1  you can troubleshoot MDM from client side with log command. 

log stream --info --predicate 'processImagePath contains "mdmclient" OR processImagePath contains "storedownloadd"'

 

Immediately after clicking on "Send Blank Push" the client should return a log.


@spotmac thanks I will give that a go.

 


Forum|alt.badge.img+6
  • Contributor
  • January 14, 2022

Did you find a solution for this? I am also running into the same issue with a few of my devices. 


Forum|alt.badge.img

We are experiencing the same issue with around 20 laptops in our environment across 4 different profiles. Anyone found any workarounds? 


Forum|alt.badge.img+6
  • Contributor
  • February 4, 2022

We are experiencing the same issue with around 20 laptops in our environment across 4 different profiles. Anyone found any workarounds? 


Is it pending only on some devices or all of your devices? 


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • February 4, 2022

Is it pending only on some devices or all of your devices? 


For mine it is only some. About 8 out of 175 systems. All are checking into jamf with no issues. Just config profiles are stuck in pending.

They are all Automatic Device Enrollment but not all ADE systems are having the issue.

Forum|alt.badge.img+3
  • New Contributor
  • February 4, 2022

I am having this problem too.


Forum|alt.badge.img+6
  • Contributor
  • February 4, 2022
For mine it is only some. About 8 out of 175 systems. All are checking into jamf with no issues. Just config profiles are stuck in pending.

They are all Automatic Device Enrollment but not all ADE systems are having the issue.

yeah, I had that issue too. its possible one of your other config profiles is causing the issue? In my case, removing all profiles and running the profiles renew command did the trick. 


Forum|alt.badge.img+3
  • New Contributor
  • February 4, 2022

yeah, I had that issue too. its possible one of your other config profiles is causing the issue? In my case, removing all profiles and running the profiles renew command did the trick. 


Is the profiles renew command sudo jamf policy?


Forum|alt.badge.img+6
  • Contributor
  • February 4, 2022

Is the profiles renew command sudo jamf policy?


No. Once you remove all profiles, it will also remove the MDM profile. You will basically need to re-enroll the computer. This article goes into more details about it -- https://docs.jamf.com/jamf-now/documentation/Re-enrolling_a_Computer_Using_Automated_Device_Enrollment.html 
Please make sure you read the requirements carefully before removing the profiles. 


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • February 4, 2022

No. Once you remove all profiles, it will also remove the MDM profile. You will basically need to re-enroll the computer. This article goes into more details about it -- https://docs.jamf.com/jamf-now/documentation/Re-enrolling_a_Computer_Using_Automated_Device_Enrollment.html 
Please make sure you read the requirements carefully before removing the profiles. 


I think I asked jamf about this before and they said only way to re-enroll a device that was joined with Automatic Device Enrollment was to wipe the system and setup again.

Forum|alt.badge.img+3
  • New Contributor
  • February 4, 2022

No. Once you remove all profiles, it will also remove the MDM profile. You will basically need to re-enroll the computer. This article goes into more details about it -- https://docs.jamf.com/jamf-now/documentation/Re-enrolling_a_Computer_Using_Automated_Device_Enrollment.html 
Please make sure you read the requirements carefully before removing the profiles. 


My problem ended up being with the keychain.  I deleted too many keychains troubleshooting another issue.  I did sudo jamf removeFramework command and reenrolled.  My Profiles are coming down now. Not ADE on this test system.


whiteb
Forum|alt.badge.img+9
  • Valued Contributor
  • July 26, 2022

I am having this problem too.


This might sound dumb, but I had the same issue and what it ended up being with me was that even though the computers that had Config Profiles stuck on 'Pending' were online and actively checking-in, they didn't have people logging into them (I work in K-12 so we have the majority of staff gone for the summer). Every computer that showed 'Pending' that I remoted into, then logged into, the commands all installed. My thinking was that it shows it checked-in recently, it should get the config profiles... nope. A user has to be logged into the computer to get them.
 
On your computers that have stuck pending profiles, look up one (or a couple) and go to History > Application Usage Logs. Is there anything there? If not, no one is using the computer, so that's actually expected behavior.
 
If Application Usage Logs are populated after the config profile tried to get pushed and it's still pending... that does sound like an issue.

RyanMilliron
Forum|alt.badge.img+6
  • New Contributor
  • August 11, 2022

My problem ended up being with the keychain.  I deleted too many keychains troubleshooting another issue.  I did sudo jamf removeFramework command and reenrolled.  My Profiles are coming down now. Not ADE on this test system.


I was able to resolve the issue on one of the effected computers by doing the sudo jamf removeFramework and then using a User-Initiated Enrollment to re-deploy the MDM framework.  It is a less than Ideal solution for a larger group of users, but was helpful in getting the device in front of me resolution.


BCPeteo
Forum|alt.badge.img+11
  • Contributor
  • November 3, 2022

Having the same issue on about 40 systems. All are checking in fine and most have users logged in. I have tried Jamf recon, launchctl kickstart -k system/com.apple.softwareupdated, renew MDM profile. No of these worked. Rather not have to re-enroll these systems, also sudo profiles renew -type enrollment forces user interaction which is also not ideal. Anyone find why this happens? Seems to be ongoing and happening randomly.


krbbass
Forum|alt.badge.img+1
  • New Contributor
  • November 11, 2022

Seeing the same thing here, over 75 devices.  Checking in, user logged in, MDM Profile Healthy and approved.  Varying OS's. 

Seems to just be more recent profiles that are stuck in pending, but these same profiles have gone out to hundreds of other devices just fine.

Surely someone has a better solution than re-enroll?


whiteb
Forum|alt.badge.img+9
  • Valued Contributor
  • November 14, 2022

Having the same issue on about 40 systems. All are checking in fine and most have users logged in. I have tried Jamf recon, launchctl kickstart -k system/com.apple.softwareupdated, renew MDM profile. No of these worked. Rather not have to re-enroll these systems, also sudo profiles renew -type enrollment forces user interaction which is also not ideal. Anyone find why this happens? Seems to be ongoing and happening randomly.


There is a different way to re-enroll using the API that requires 0 interaction.

https://www.modtitan.com/2022/02/jamf-binary-self-heal-with-jamf-api.html

I've used that to fix a few computers that were not checking-in. The only requirement is the devices still need to be capable of getting MDM commands, which do get send the same way config profiles do I believe, but still worth trying. Definitely fixed a few for me. 


BCPeteo
Forum|alt.badge.img+11
  • Contributor
  • November 14, 2022

There is a different way to re-enroll using the API that requires 0 interaction.

https://www.modtitan.com/2022/02/jamf-binary-self-heal-with-jamf-api.html

I've used that to fix a few computers that were not checking-in. The only requirement is the devices still need to be capable of getting MDM commands, which do get send the same way config profiles do I believe, but still worth trying. Definitely fixed a few for me. 


Thanks. Yeah the binary on these systems is fine, they are checking in and doing inventory updates. They are not getting MDM commands that is the issue.


BCPeteo
Forum|alt.badge.img+11
  • Contributor
  • November 16, 2022

Seeing the same thing here, over 75 devices.  Checking in, user logged in, MDM Profile Healthy and approved.  Varying OS's. 

Seems to just be more recent profiles that are stuck in pending, but these same profiles have gone out to hundreds of other devices just fine.

Surely someone has a better solution than re-enroll?


I'm working with Jamf on this, will post if we find a solution 


Forum|alt.badge.img+3
  • Author
  • New Contributor
  • November 16, 2022

Seeing the same thing here, over 75 devices.  Checking in, user logged in, MDM Profile Healthy and approved.  Varying OS's. 

Seems to just be more recent profiles that are stuck in pending, but these same profiles have gone out to hundreds of other devices just fine.

Surely someone has a better solution than re-enroll?


The only resolution we found was wiping the system(s) and setting it backup. Even trying to re-enroll the system in jamf did not work.

I also worked with Jamf on our issues.

Dan Thompson
Systems Engineer
HealthStream, Inc.
500 11th Ave. North - Suite 1000
Nashville, TN 37203
Daniel.Thompson@healthstream.com

pgy_jamf_help
Forum|alt.badge.img+1
  • New Contributor
  • February 21, 2023

We have this issue with about 200\\1000 devices. Policy and checking are working but configuration profiles are showing as Pending.


Forum|alt.badge.img

In my case, the only thing that works is to restart the computer.


BCPeteo
Forum|alt.badge.img+11
  • Contributor
  • April 26, 2023

In my case, the only thing that works is to restart the computer.


Restarting does not seem to work on a lot of these. Some of them we need re-enroll with the sudo profiles renew -type enrollment which is a pain as the user needs to click on the enrollment notification and approve  


Forum|alt.badge.img+3

Restarting does not seem to work on a lot of these. Some of them we need re-enroll with the sudo profiles renew -type enrollment which is a pain as the user needs to click on the enrollment notification and approve  


Any update on this issue? We're experiencing this exact same problem and I need to make sure if it's a problem with Jamf or if it could be an issue with ABM that we could fix ourselves.


Forum|alt.badge.img
  • New Contributor
  • June 23, 2023

We're seeing the same issue as well. We primary use UIE and see no issues with those computers. We're currently experiencing issues with our PreStage computers not receiving commands.