MDM connection lost with non-removable MDM profile

j_meister
Contributor

Hi,

every now and then I come across a Mac which stopped communicating with the Jamf server and Apple's MDM.

As our MDM profile is non-removable I have the question how to uninstall it? Sending the MDM-removal command obviously will not work nor jamf removeMDMProfile.

Any ideas?

6 REPLIES 6

garybidwell
Contributor II

I assume its not stolen and still in possession of an employee, just remote so you don't have hands on to it?

As if you can still get command line access to the device (SSH or via Jamf Binary/Self Service)? as you could use the profiles command to try to refresh the MDM profile on the device

sudo profiles renew -type enrollment

Hi Gary,

thanks for your reply.

It is a MacBook Pro which uses one of our employees. I did an AnyDesk session with that employee earlier this day and had access to the Terminal.
The Mac seems pretty messed up, the Jamf Framework does not work any more and "jamf recon" quits with a 404 error. The MDM commands sent via Jamf Pro do not work too and the device did not check in and update inventory since August 18th.

I tried a

 

sudo profiles renew -type enrollment

 

but that did nothing. Also "jamf manage" or "jamf mdm" did not help and "jamf removeMDMProfile" does not work as the profile is non-removable.

The only way out of this seems a reinstallation of macOS but that cannot be the solution, right?

 

By the way, of course I ran all commands with "sudo". 😉

sdagley
Honored Contributor II

@j_meister  A nuke & re-pave might be extreme, but if it gets the user back up and running (they do have their files backed up right?) then it's a trivial process to follow either with Monterey's Erase All Contents and Settings, or with @grahamrpugh's erase-install script for Catalina or Big Sur.

dlbrabb
New Contributor III

I have also seen this on a few of our Mac's lately and do not have a solution.  I have tried all the "jamf" terminal commands, but nothing works.  Ours are actually running jamf policy and recon, profiles just can't be removed or added.

junjishimazaki
Contributor III

This is the guide I used to remove a non-removable MDM profile and re-enroll. 

http://www.whoopis.com/core/mac-related/removing-a-non-removable.html

Basically you have to boot the mac to recovery mode, open terminal and follow the guide.

But, I did a much simpler and somewhat automated approach. I create a bash script that ran all these commands, made the script executable, change the extension from .sh to .command and packaged it. Then on the mac boot the mac to recovery mode, go to terminal, disable sip (csrutil disable), reboot the mac, run the script (this requires a reboot for it to complete the mdm removal and to re-enable SIP). That should remove the MDM profile and all config profiles. Then I would run sudo jamf removeframework in terminal to remove the Jamf binary. Then I would sudo profiles renew -type enrollment. 

mschroder
Valued Contributor

We recently had a case like this. Try to add a new admin account and see whether that can remove the framework and enroll again.