Manually Remove MDM Profile and Re-Enroll
In the event that you get the error update to MDM profile contains a different server URL when attempting to renew an MDM profile using sudo profiles renew -type enrollment, you can manually remove the profile after disabling SIP in recovery and removing the directory holding the profiles.
Please note: You will need the help of the Izzy team to remote in and provide credentials to rebind to JAMF/MDM, as well as link it back to Izzy once renewed.
Caution: This is not a fully supported option and is somewhat of a last-ditch/at-your-own-risk process. It should only be used if rebuilding is not possible. It can cause data loss, so be sure to complete a backup of the machine before attempting.
Source
Process
Removing the MDM Profile
- Just to be safe, make a backup of the device using IzzyStor
- Boot the Mac into Recovery Mode (hold down command+R during startup)
- Enter credentials to unlock the disk
- Go to the Utilities menu and open Terminal and type:
csrutil disable- This will disable SIP (System Integrity Protection).
- Reboot into the OS
- Open the integrated terminal and type the following:
cd /var/db/ConfigurationProfiles rm -rf * mkdir Settings touch Settings/.profilesAreInstalled
- Reboot and enter recovery again by holding command+R
- Go to the Utilities menu and open Terminal and type:
csrutil enable- This will re-enable SIP
- Reboot into the OS and check the profiles in System Settings – there should be none
Re-Enrolling
- Open terminal under the UM-Support account
- Run the command
sudo jamf enroll -prompt - Connect with an Izzy team member who can enter credentials to re-enroll the device over bomgar or Remote Desktop
- Once enrolled, run the following:
sudo profiles renew -type enrollment - At this point some profiles will begin to load, but not all – the Izzy team member will need to re-link the device with Izzy
- You may also need to run the following two commands:
sudo jamf recon sudo jamf policy
- At this point you should let the computer sit for 5-10 minutes before checking for software updates in Managed Software Center444
Non-removable MDM profiles cannot officially removed without doing a full system wipe. This is a problem when you restore a system from Time Machine after you enrolled it into the MDM, as the MDM will break, leaving you unable to re-enroll the machine.
Here's how to remove a non-removable MDM profile
- Boot the Mac into Recovery Mode (hold down command+R during startup).
- Go to the Utilities menu and open Terminal and type:
csrutil disable. This will disable SIP (System Integrity Protection). - Reboot into the OS.
- Open the integrated terminal and type:
cd /var/db/ConfigurationProfiles
rm -rf *
mkdir Settings
touch Settings/.profilesAreInstalled
- Reboot.
- Boot the Mac into Recovery Mode (hold down command+R during startup).
- Go to the Utilities menu and open Terminal and type:
csrutil enable. This will re-enable SIP. - Reboot into the OS.
The profile will be now removed and you will be able to re-enroll the Mac to your MDM.
إرسال تعليق