If a Mac device is enrolled via the Apple Device Enrollment Program, the administrator can disallow removal of the MDM profile.
Prevent MDM profile removal
To prevent users from removing the MDM profile, enroll the devices via Apple DEP. On the DEP policy (Admin > Apple Business/School Manager > Apple DEP > DEP Policy), there is an option to “Allow MDM profile removal”. Disabling this option helps you prevent profile removal. Associating this DEP policy with the enrolling devices will prevent the end-users from removing it from Management.
- On your Hexnode MDM portal, navigate to Admin > Apple Business/School Manager > Apple DEP.
- Select DEP Policy > +Add Policy.
- Disable the option Allow MDM Profile Removal.
- Click Save.
Selecting this profile as the Default Policy while configuring the DEP account associated with your devices will make MDM profile non-removable on Mac devices.