Perform the following steps in the event that an Apple device is unenrolled from JumpCloud MDM and needs to be re-enrolled with its device record preserved.<\/p>\n\n\n\n
<\/p><\/div>
Preserving the device record ensures that re-enrollment will retain all JumpCloud associations originally on the device prior to unenrollment.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
<\/p><\/div>
While this article outlines the best method of retaining the device record, there are many variables in this process and there is no guarantee the device record will be retained. <\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
To identify devices that have been unenrolled from JumpCloud MDM and need to be re-enrolled, filter your list of devices.<\/p>\n\n\n\n
<\/p><\/div>
For a guided simulation, see Re-enroll a Mac in MDM with only a Standard User<\/a>. You will need to contact JumpCloud Support to access the script referenced in this simulation. <\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
<\/p><\/div>
If the device is active<\/strong> in the JumpCloud portal, but not enrolled in JumpCloud MDM, end users working on the device should complete MDM enrollment using the Mac MDM Enrollment Policy.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
<\/p><\/div>
If the device is inactive<\/strong> in the JumpCloud Portal but is known to be in active use by end users, then the MDM enrollment policy is not a candidate for MDM enrollment, and an MDM enrollment profile must be manually distributed and installed on the device.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
On macOS 15 Sequoia<\/strong>:<\/p>\n\n\n\n
<\/p><\/div>
This feature automatically binds the user account to the device that was used during the ADE enrollment process. If this account differs from the existing account on the device, then the user binding state associated with the device may be inadvertently modified.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
sudo profiles renew -type enrollment<\/code> <\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \nYou can run the command in different ways:<\/p>\n\n\n\n
\n- If the devices are active in the JumpCloud Admin console, run a JumpCloud command (run as root).<\/li>\n\n\n\n
- In the devices are offline, run the command locally using the Terminal.<\/li>\n<\/ul>\n <\/div><\/div><\/div><\/div>\n\n\n\n
\n- A Remote Management <\/strong>screen appears displays asking to confirm JumpCloud’s management of your device. Click Enroll<\/strong>.
<\/li>\n\n\n\n - Enter an administrator password and click Enroll<\/strong> to allow the enrollment installation to proceed.
<\/li>\n\n\n\n - On the enrollment wizard, click continue<\/strong>.
<\/li>\n\n\n\n - When the enrollment profile has finished installing, you will see an enrollment complete message. The device is now managed by JumpCloud. Click Quit<\/strong> to begin using your device.
<\/li>\n<\/ol>\n\n\n\nOn macOS 13 Ventura or macOS 14 Sonoma<\/strong>:<\/p>\n\n\n\n
\n- Log in to the JumpCloud Admin Portal<\/a>.<\/li>\n\n\n\n
- Go to DEVICE MANAGEMENT > MDM<\/strong>, then click the Apple<\/strong> tab. <\/li>\n\n\n\n
- (Optional) If you leverage Mac Zero-Touch Experience, temporarily disable User Authentication<\/strong> in the Zero-Touch Experience settings. \n
\n- In the Automated Device Enrollment Configuration <\/strong>section, click Configure MacOS<\/strong>. The Mac Zero-Touch Experience screen displays.
<\/li>\n\n\n\n - Scroll down to Step 4 User authentication<\/strong>, and disable user authentication.
<\/li>\n\n\n\n - Click Save<\/strong>. <\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \nThis feature automatically binds the user account to the device that was used during the ADE enrollment process. If this account differs from the existing account on the device, then the user binding state associated with the device may be inadvertently modified.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
\n- Run the following command on the device:
sudo profiles renew -type enrollment<\/code> <\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \nYou can run the command in different ways:<\/p>\n\n\n\n
\n- If the devices are active in the JumpCloud Admin console, run a JumpCloud command (run as root).<\/li>\n\n\n\n
- In the devices are offline, run the command locally using the Terminal.<\/li>\n<\/ul>\n <\/div><\/div><\/div><\/div>\n\n\n\n
\n- To allow JumpCloud to automatically enroll your device, on your Mac device go to System Preferences<\/strong> > Privacy & Security<\/strong>, and click Allow<\/strong>.
<\/li>\n\n\n\n - A message displays asking to confirm JumpCloud’s management of your device. Click Enroll<\/strong>.
<\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \n\n- For macOS versions 13 and later, browse to System Settings<\/strong> > Privacy & Security<\/strong> > Profiles<\/strong>. <\/li>\n<\/ul>\n\n\n\n
\n- For macOS versions 12 and earlier, browse to System Preferences<\/strong> > Profiles<\/strong>.<\/li>\n<\/ul>\n <\/div><\/div><\/div><\/div>\n\n\n\n
\n- Proceed through the rest of the prompts to complete the enrollment process. By proceeding with an Automated Device Enrollment, the enrollment profile will be locked on the device and all entitlements will be restored for supervision state on macOS version 10.15.<\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \nMake sure you are not trying to complete enrollment during a remote desktop session. Apple prevents enrollment from commencing over remote desktop connections.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Manually Enroll Devices<\/h3>\n\n\n\n
To manually download, distribute, and install a JumpCloud MDM enrollment profile on a device: <\/p>\n\n\n\n
\n- Log in to the JumpCloud Admin Portal<\/a>.<\/li>\n\n\n\n
- Go to DEVICE MANAGEMENT > MDM<\/strong>, then click the Apple<\/strong> tab. <\/li>\n\n\n\n
- Download the MDM enrollment profile from the JumpCloud admin console.\n
\n- In the APNs Configuration for MDM <\/strong>section, click Download Profile<\/strong>. The file
profile_jc.mobileconfig<\/code> should appear in your Downloads.
<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \nThis profile is unique per organization but not per device and can be used to enroll any device into an organization’s configured MDM.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
\n- Distribute the MDM enrollment profile to end users working from inactive devices.\n
\n- Find and distribute the downloaded MDM enrollment profile, named
profile_jc.mobileconfig<\/code> to end users working on inactive devices.
<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \nThe profile can be attached to an email, sent via an attachment on a messaging platform, or transferred via a removable USB drive. The size of an enrollment profile is very small, less than 10 KB.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
\n- Install the MDM enrollment profile.\n
\n- On a Mac device that has the JumpCloud agent installed, but has been unenrolled from JumpCloud MDM, double-click on the MDM enrollment profile. This will queue the profile for approval in System Settings<\/strong>.
<\/li>\n<\/ol>\n<\/li>\n\n\n\n - Based on your macOS device version, continue the steps in the following sections.<\/li>\n<\/ol>\n\n\n\n
Install MDM Enrollment Profile on macOS 15 Sequoia<\/h3>\n\n\n\n\n- Go to System Settings<\/strong> > General<\/strong> > Device Management<\/strong>.<\/li>\n<\/ol>\n\n\n\n
<\/figure>\n\n\n\n\n- Double-click on the MDM Enrollment Profile<\/strong> to complete the enrollment process.\n
\n- You must have Administrator role permissions to approve the profile.<\/li>\n\n\n\n
- After approving the MDM Enrollment Profile, the device will be re-enrolled in JumpCloud MDM and receive all of the profiles associated with, it including the JumpCloud default profiles for the Agent, Remote Assist, Tray App, and MDM.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n
<\/figure>\n\n\n\nInstall MDM Enrollment Profile on macOS 13 Ventura & macOS 14 Sonoma Devices<\/h3>\n\n\n\n\n- Go to System Settings<\/strong> > Privacy & Security<\/strong>.<\/li>\n\n\n\n
- Scroll down to the Others <\/strong>section and click Profiles<\/strong>.
<\/li>\n\n\n\n - Double-click on the MDM Enrollment Profile to complete the enrollment process.
<\/li>\n<\/ol>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \nYou must have Administrator role permissions to approve the profile.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
<\/figure>\n\n\n\n
<\/p><\/div>
Note:<\/strong> \nAfter approving the MDM Enrollment Profile, the device will be re-enrolled in JumpCloud MDM and receive all of the profiles associated with, it including the JumpCloud default profiles for the Agent, Remote Assist, Tray App, and MDM.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n
Install MDM Enrollment Profile on MacOS 12 Monterey & Earlier Devices<\/h3>\n\n\n\n\n- Go to System Settings<\/strong> > Profiles<\/strong>.<\/li>\n\n\n\n
- Find the staged MDM Enrollment profile and click Install<\/strong>. After prompted, enter your account credentials from an account with administrator privileges.
<\/li>\n\n\n\n - Successful enrollment will be indicated by the subsequent delivery of the remaining configuration profiles.
<\/li>\n<\/ol>\n\n\n\nRe-Enroll an iOS or iPadOS Device into JumpCloud MDM<\/h3>\n\n\n\n
To re-enroll an affected iOS or iPadOS device back into JumpCloud MDM, follow the steps outlined in the help articles:<\/p>\n\n\n\n
\n- Add Personal Apple Devices to MDM with User Enrollment<\/a><\/li>\n\n\n\n
- Add Company-Owned Apple Devices to MDM with Device Enrollment<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"
Perform the following steps in the event that an Apple device is unenrolled from JumpCloud MDM and needs to be […]<\/p>\n","protected":false},"author":201,"featured_media":0,"template":"","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"support_category":[3136,3127],"support_tag":[],"coauthors":[2835],"acf":[],"yoast_head":"\n
Re-enroll Apple Devices With Their Device Record- JumpCloud<\/title>\n<meta name=\"description\" content=\"If your Apple device was unenrolled from MDM, follow these steps to re-enroll them in JumpCloud MDM with their previous device record intact.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Re-Enroll Apple Devices into JumpCloud MDM and Preserve the Device Record\" \/>\n<meta property=\"og:description\" content=\"If your Apple device was unenrolled from MDM, follow these steps to re-enroll them in JumpCloud MDM with their previous device record intact.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record\" \/>\n<meta property=\"og:site_name\" content=\"JumpCloud\" \/>\n<meta property=\"article:modified_time\" content=\"2025-01-27T20:50:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/08\/Mac-MDM-Devices-Impacted-by-Unenrollment--1024x463.png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"7 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"alexsnyder\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record\",\"url\":\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record\",\"name\":\"Re-enroll Apple Devices With Their Device Record- JumpCloud\",\"isPartOf\":{\"@id\":\"https:\/\/jumpcloud.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/08\/Mac-MDM-Devices-Impacted-by-Unenrollment--1024x463.png\",\"datePublished\":\"2023-08-03T20:09:59+00:00\",\"dateModified\":\"2025-01-27T20:50:24+00:00\",\"description\":\"If your Apple device was unenrolled from MDM, follow these steps to re-enroll them in JumpCloud MDM with their previous device record intact.\",\"breadcrumb\":{\"@id\":\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#primaryimage\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2023\/08\/Mac-MDM-Devices-Impacted-by-Unenrollment-.png\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2023\/08\/Mac-MDM-Devices-Impacted-by-Unenrollment-.png\",\"width\":1876,\"height\":848},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jumpcloud.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Support\",\"item\":\"https:\/\/jumpcloud.com\/support\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Re-Enroll Apple Devices into JumpCloud MDM and Preserve the Device Record\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jumpcloud.com\/#website\",\"url\":\"https:\/\/jumpcloud.com\/\",\"name\":\"JumpCloud\",\"description\":\"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.\",\"publisher\":{\"@id\":\"https:\/\/jumpcloud.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jumpcloud.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/jumpcloud.com\/#organization\",\"name\":\"JumpCloud\",\"url\":\"https:\/\/jumpcloud.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"contentUrl\":\"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png\",\"width\":598,\"height\":101,\"caption\":\"JumpCloud\"},\"image\":{\"@id\":\"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Re-enroll Apple Devices With Their Device Record- JumpCloud","description":"If your Apple device was unenrolled from MDM, follow these steps to re-enroll them in JumpCloud MDM with their previous device record intact.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record","og_locale":"en_US","og_type":"article","og_title":"Re-Enroll Apple Devices into JumpCloud MDM and Preserve the Device Record","og_description":"If your Apple device was unenrolled from MDM, follow these steps to re-enroll them in JumpCloud MDM with their previous device record intact.","og_url":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record","og_site_name":"JumpCloud","article_modified_time":"2025-01-27T20:50:24+00:00","og_image":[{"url":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/08\/Mac-MDM-Devices-Impacted-by-Unenrollment--1024x463.png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"7 minutes","Written by":"alexsnyder"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record","url":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record","name":"Re-enroll Apple Devices With Their Device Record- JumpCloud","isPartOf":{"@id":"https:\/\/jumpcloud.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#primaryimage"},"image":{"@id":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#primaryimage"},"thumbnailUrl":"https:\/\/jumpcloud.com\/\/wp-content\/uploads\/2023\/08\/Mac-MDM-Devices-Impacted-by-Unenrollment--1024x463.png","datePublished":"2023-08-03T20:09:59+00:00","dateModified":"2025-01-27T20:50:24+00:00","description":"If your Apple device was unenrolled from MDM, follow these steps to re-enroll them in JumpCloud MDM with their previous device record intact.","breadcrumb":{"@id":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#primaryimage","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2023\/08\/Mac-MDM-Devices-Impacted-by-Unenrollment-.png","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2023\/08\/Mac-MDM-Devices-Impacted-by-Unenrollment-.png","width":1876,"height":848},{"@type":"BreadcrumbList","@id":"https:\/\/jumpcloud.com\/support\/re-enroll-apple-devices-into-mdm-and-preserve-device-record#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jumpcloud.com\/"},{"@type":"ListItem","position":2,"name":"Support","item":"https:\/\/jumpcloud.com\/support"},{"@type":"ListItem","position":3,"name":"Re-Enroll Apple Devices into JumpCloud MDM and Preserve the Device Record"}]},{"@type":"WebSite","@id":"https:\/\/jumpcloud.com\/#website","url":"https:\/\/jumpcloud.com\/","name":"JumpCloud","description":"Daily insights on directory services, IAM, LDAP, identity security, SSO, system management (Mac, Windows, Linux), networking, and the cloud.","publisher":{"@id":"https:\/\/jumpcloud.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jumpcloud.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/jumpcloud.com\/#organization","name":"JumpCloud","url":"https:\/\/jumpcloud.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/","url":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","contentUrl":"https:\/\/jumpcloud.com\/wp-content\/uploads\/2021\/01\/jc-logo-brand-2021.png","width":598,"height":101,"caption":"JumpCloud"},"image":{"@id":"https:\/\/jumpcloud.com\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/support\/95248"}],"collection":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/support"}],"about":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/types\/support"}],"author":[{"embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/users\/201"}],"version-history":[{"count":2,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/support\/95248\/revisions"}],"predecessor-version":[{"id":120438,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/support\/95248\/revisions\/120438"}],"wp:attachment":[{"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/media?parent=95248"}],"wp:term":[{"taxonomy":"support_category","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/support_category?post=95248"},{"taxonomy":"support_tag","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/support_tag?post=95248"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/jumpcloud.com\/wp-json\/wp\/v2\/coauthors?post=95248"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}