a week ago
We have all our managed iOS devices in Jamf Pro. We have most of these also in Jamf Security Cloud but need to remove some of them from there. What is the proper order to remove them from Security Cloud so the device is still usuable for the end user without any interaction on their part? We have the Jamf Trust app pushed out through Jamf Pro as well as a configuration profile containing the certificate, JamfSecurityCA.crt, and content filters and DNS settings are specified for Security Cloud and I can easily remove that app and configuration profile from the device, but I don't think that will remove the content filtering or data usage policies from the device that are setup in Security Cloud.
Friday
A bit of an overkill, but have you tried to restart or restore the device after removing from the trust scoping? Without user input the VPN might still be active until at least a restart, possibly restore.