PI-004201 Intermittent site membership failures on DEP enrollment

jross
New Contributor

We've been battling an intermittent issue since upgrading to 9.99.0 where computers enrolled via DEP are not always enrolled in the site prescribed by the PreStage Enrollment configuration. The computers still enroll, but they appear in the top level "None" site. Consequently, any site-level management doesn't happen, such as post-enrollment policies, configuration profiles, smart group enrollment, etc.

Jamf support has identified this behavior as PI-004201: MacOS DEP Enrollment assigned to an enrollment site, intermittently delete the device from Site Membership. The PI is still in discovery phase, but Jamf has been able to reproduce it internally and have assigned it to a product specialist for investigation. No resolution timeline at this point.

Jamf's workaround is to manually move computers into the desired site after enrollment. I've created a smart group in our environment to watch for computers enrolled via any PreStage ("Enrollment Method: PreStage enrollment" like "<blank>") AND no site membership.465600cab7814d778fee500ba6596a40

The "Site Affiliation" criteria is an extension attribute that queries the computer's JSS record for its site membership and writes back via the API, similar to this one: https://www.jamf.com/jamf-nation/feature-requests/1365/smart-computer-groups-based-on-site#responseChild14212.

0 REPLIES 0