I've been struggling to find out what's going on with our 802-1x WiFi Configuration profile. The profile imports our root cert, intermediate, then downloads an AD cert, then configures WiFi network.
We currently have a profile configured that installs at first login that works 100% of the time. The certificates are expiring in a week, and when we update the cert, and choose to distribute to all, more than half of our machines are failing with the error "Cannot replace profile '04D1878B-BD77-4593-BAA4-4EB5AAE99304' because it was not installed by the MDM server <MDMClientError:96>"
As a workaround, I'm thinking of cloning the policy and pushing to all clients. The only issue with this is that we'll have two identical policies and I'm not sure how this will affect our environment in the future. In my testing, deleting the original profile will also remove the wifi network, meaning we'll have to manually reconfigure everyone's WiFi again.
Any advice is appreciated.

