Hi @amelia,
The MDMDeviceEnrollment:103 error usually means macOS cannot find a valid Automated Device Enrollment configuration for that Mac. Before running the command, confirm the full ADE chain is complete:
- In Apple Business, verify that the Mac is present.
- Confirm that the Mac is assigned to the Hexnode MDM server in ABM.
- In Hexnode, go to Admin > Apple Business Manager > ADE > Devices and run Sync all devices.
- Confirm that the Mac appears in the ADE device list.
- Associate the correct ADE enrollment profile with the device.
- Confirm that the profile status shows Assigned.
- Run the command from an administrator account:
sudo profiles renew -type enrollment
If the Mac is not actually present in Apple Business, or if no ADE profile is associated with it, macOS can return MDMDeviceEnrollment:103. Removing the MDM profile from macOS does not release a device from Apple Business; release must be done from Apple Business. However, if the Mac was never in Apple Business or was not assigned correctly, the ADE renewal command will not work as expected.
For the Unenroll button concern, there are two ways to reduce removal risk:
– For ADE enrollments, edit the ADE enrollment profile and make sure Allow MDM profile removal is unchecked.
– For already-enrolled Macs that cannot be re-enrolled right now, configure a UEM profile password. You can do this globally for new enrollments under Admin > Enrollment > Security, or per device from Manage > Devices > select device > Device Info > Security Info > UEM profile password.
A UEM profile password helps prevent users from removing the management profile without authorization.
Regards,
Sienna Carter
Hexnode UEM