So we are having an issue with our configuration profiles not pushing over our network, and we, with the help of JAMF support, have tracked the issue down to SCEP. Computers without SCEP can receive new profiles and changes to profiles, but computers that have SCEP are stuck with whatever configuration profiles were scoped to the machines when they were enrolled. In essence, we can test the issue by performing a sudo jamf removemdmprofile then sudo jamf mdm.
We have attempted applying some exclusions within SCEP, but they don't seem to work after a restart.
We install SCEP in unmanaged mode straight from the .pkg.
I'm curious to know if anyone has had issues like this with SCEP. We've opened a support ticket with Microsoft but aren't hopeful.
