Unerollment vs Unmanaged vs removeFramework

Swordfish
New Contributor II

Hello, 

Can someone please answer, which I'm sure is an elementary question?

Some of out Macs will need to be unenrolled and enrolled in Intune (don't ask!)

What happens when you unenroll the Mac?

What happens when you unmmage the Mac?

What happens when you remove the MDM profile and framework?

Self Service was removed, our VPN client does not work but all of the Office apps and Teams still work and have access to company data, including our company homepage?

 

Is there a way to remove everything? Once we unmanaged or remove the mdm profile we can't access it.

I'm confused. I thought doing all of the above would cut the ties. I don't know.

 

1 REPLY 1

AJPinto
Honored Contributor III

I wont ask, I will just apologize to you for having to move devices to intune.

 

Unenrolling, unmanaging, and removing the MDM profile are functionally all the same thing. You lose all control and visibility over the device. Any software on the device (such as Selfservice, Office, or security clients) will remain as well as all user data and corporate data. However, the configuration profiles that allow your security clients to function will be removed, and the security clients will stop functioning as expected. The users will also receive pop up’s about anything that a configuration profile is approving. 

 

Office applications still functioning will depend on your Azure Conditional access settings, but I would assume they would still work in most situations. Your homepage is set by a configuration profile, that would be unmanaged as the configuration profiles are removed.

 

There is not a hands off way to move a device from one MDM to another, and Apple very strongly suggests wiping and reinstalling the OS which is honestly the best way to do it. I strongly suggest you testing this out yourself, a lot before trying this on any production devices.