hey gang! I have another question. I just manually...
# fleet
b
hey gang! I have another question. I just manually onboarded a mac to our Fleet instance this afternoon and noticed that the MDM enrollment dialog has changed. It appears that you can no longer manually download the mobileconfig file to enroll in Fleet MDM. The instructions on the enrollment page are as follows: 1. From the Apple menu in the top left corner of your screen, select System Settings or System Preferences. 2. In the sidebar menu, select Enroll in Remote Management, and select Enroll 3. Enter your password, and select Enroll. 4. Close this window and select Prefetch on your My device page to tell your organization that MDM is on. But the issue is that there is no such option that I am seeing in System Settings called "Enroll in Remote Management" and browsing to the profiles section shows that there are no profiles waiting to be approved. Am I missing something here? Mac is running macOS 14.7.1
r
Could you please send a link to the instructions you are following?
b
I cannot, they are the instructions presented to me when I click "Turn on MDM" I can send a screenshot though
r
A screenshot would be great, thanks!
Here are our latest docs for setting up MacOS MDM. https://fleetdm.com/guides/macos-mdm-setup
b
Screenshot 2024-11-05 at 11.29.37 AM.png
Screenshot 2024-11-05 at 11.29.37 AM.png
r
I would advise trying to follow the steps in the MDM Setup guide I just linked. Let me know if you have any issues with it.
Thank you for the screenshot as well. My team will want to take a look and make any necessary updates.
b
I do already have MDM setup and enabled for my whole org.
I see this note in here:
If your certificate expires, you will have to turn MDM off and back on for all macOS hosts.
I renewed my certificate yesterday when we were troubleshooting the automatic enrollment (the certificate was not expired). Would this affect this? Would I need to disable and re-enable MDM for the whole organization
r
You should not need to toggle MDM on/off when renewing APNs certificates, only when the cert expires. I will look more into this issue and get back to you.
Just ruling out other issues, but did you use the same Apple ID when renewing your APNs cert?
b
Yup!
r
I think it would be worth a try to run the uninstall script on the host and remove from Fleet server side. Then create a new package for it. https://github.com/fleetdm/fleet/blob/main/orbit/tools/cleanup/cleanup_macos.sh