Home
%3CLINGO-SUB%20id%3D%22lingo-sub-325357%22%20slang%3D%22en-US%22%3EResolved%3A%20Follow-up%20to%20IT172124%20%E2%80%93%20Can%E2%80%99t%20renew%20macOS%20Profiles%20running%2010.14%20and%20higher%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-325357%22%20slang%3D%22en-US%22%3E%3CP%20style%3D%22line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EFully%20resolved.%20Update%20to%2010.14.4%20which%20is%20now%20available.%20This%20fixes%20the%20known%20issue.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22line-height%3A%20150%25%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22line-height%3A%20150%25%3B%22%3E%3CEM%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EWe%20recently%20posted%20MC172422%20%E2%80%93%20the%20text%20of%20which%20is%20listed%20below.%20There%E2%80%99s%20a%20known%20issue%20for%20macOS%20running%20version%2010.14%20and%20higher%20where%20MDM-enrolled%20macOS%20devices%20may%20fail%20to%20renew%20their%20management%20profile.%20The%20only%20workaround%20is%20to%20un-enroll%20and%20re-enroll%20the%20device%20prior%20to%20the%20certificate%20expiration.%20We%20have%20been%20working%20with%20Apple%20and%20Apple%20has%20confirmed%20that%20they%20need%20to%20take%20a%20fix%20on%20their%20side.%20Apple%20expects%20to%20ship%20the%20fix%20in%20their%20next%20OS%20beta%20update.%20We%20have%20tested%20the%20fix%20in%20beta%20and%20it%20addresses%20the%20issue.%20Please%20adopt%20the%20next%20OS%20update%20for%20macOS.%20%3CSTRIKE%3EOnce%20we%20test%20the%20fix%2C%20we'll%20update%20this%20post.%20%3C%2FSTRIKE%3E%3CSPAN%20style%3D%22text-decoration%3A%20line-through%3B%22%3EUnfortunately%2C%20at%20this%20time%2C%20there%E2%80%99s%20no%20action%20Intune%20can%20take.%20Intune%20has%20a%20ticket%20filed%20with%20Apple%20and%20we%20will%20keep%20you%20posted%20if%20we%20have%20any%20updates.%26nbsp%3B%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FEM%3E%3C%2FP%3E%0A%3CP%20style%3D%22line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22line-height%3A%20150%25%3B%22%3E%3CSTRONG%3EH%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3Eere%E2%80%99s%20the%20%3CA%20href%3D%22https%3A%2F%2Fportal.office.com%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EM365%20Message%20Center%3C%2FA%3E%20post%3A%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%20style%3D%22line-height%3A%20150%25%3B%22%3E%3CSTRONG%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%20style%3D%22text-indent%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSTRONG%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EMC172422%20-%20Prevent%20or%20Fix%20Issues%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EPublished%20On%3A%20January%2022%2C%202019%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EAs%20described%20in%20IT172124%2C%20there%E2%80%99s%20a%20known%20issue%20where%20Intune-enrolled%20macOS%20devices%20may%20fail%20to%20renew%20their%20management%20profile.%20Typically%2C%20devices%20attempt%20to%20renew%20their%20management%20profile%20upon%20every%20check-in%20starting%20at%2028%20days%20before%20the%20profile%20expires.%20We%E2%80%99re%20working%20with%20Apple%20to%20fix%20the%20bug%2C%20but%20there%E2%80%99s%20no%20estimate%20on%20the%20timing%20for%20the%20fix.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSTRONG%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EHow%20does%20this%20affect%20me%3F%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EThis%20issue%20has%20been%20seen%20in%20devices%20running%20OS%20version%2010.14%20or%20higher%20enrolled%20in%20Intune.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSTRONG%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EWhat%20action%20do%20I%20need%20to%20take%3F%3C%2FSPAN%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3EUntil%20this%20bug%20is%20fixed%2C%20you%20can%20either%20choose%20to%20not%20update%20to%20macOS%20Mojave%20(version%2010.14)%20or%20you%20can%20run%20the%20script%20linked%20to%20in%20Additional%20Information%20to%20identify%20the%20devices%20that%20could%20have%20a%20management%20profile%20expire%20and%20then%20re-enroll%20them%20into%20Intune%20when%20they%20get%20close%20to%20their%20expiration%20date.%20The%20management%20profile%20is%20valid%20for%20a%20year%20and%20re-enrolling%20these%20devices%20would%20allow%20them%20to%20stay%20managed.%20We%20will%20remove%20this%20post%20when%20a%20solution%20is%20rolled%20out.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%20.5in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FIT172124_script%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2FIT172124_script%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%200in%3B%20line-height%3A%20150%25%3B%22%3E%3CSPAN%20style%3D%22color%3A%20%23333333%3B%22%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20style%3D%22margin-left%3A%200in%3B%20line-height%3A%20150%25%3B%22%3EUpdated%20this%20post%3A%3C%2FP%3E%0A%3CUL%20style%3D%22list-style-position%3A%20inside%3B%22%3E%0A%3CLI%20style%3D%22line-height%3A%20150%25%3B%22%3EFeb%206%2C%202019%20with%20info%20that%20the%20fix%20is%20in%20Apple's%20next%20OS%20update.%3C%2FLI%3E%0A%3CLI%20style%3D%22line-height%3A%20150%25%3B%22%3EFeb%2013%2C%202019%20updated%20that%20the%20fix%20worked%20as%20expected.%26nbsp%3B%3C%2FLI%3E%0A%3CLI%20style%3D%22line-height%3A%20150%25%3B%22%3EMarch%2028%2C%202019%20resolved%20(10.14.4%20is%20live).%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%20style%3D%22margin-left%3A%200in%3B%20line-height%3A%20150%25%3B%22%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-325357%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20issue%20was%20fixed%20by%20Apple's%2010.14.4%20release.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-325357%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%20Known%20Issue%20Support%20Tip%20iOS%20mac%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E

Fully resolved. Update to 10.14.4 which is now available. This fixes the known issue. 

 

We recently posted MC172422 – the text of which is listed below. There’s a known issue for macOS running version 10.14 and higher where MDM-enrolled macOS devices may fail to renew their management profile. The only workaround is to un-enroll and re-enroll the device prior to the certificate expiration. We have been working with Apple and Apple has confirmed that they need to take a fix on their side. Apple expects to ship the fix in their next OS beta update. We have tested the fix in beta and it addresses the issue. Please adopt the next OS update for macOS. Once we test the fix, we'll update this post. Unfortunately, at this time, there’s no action Intune can take. Intune has a ticket filed with Apple and we will keep you posted if we have any updates. 

             

Here’s the M365 Message Center post:

 

MC172422 - Prevent or Fix Issues

Published On: January 22, 2019

 

As described in IT172124, there’s a known issue where Intune-enrolled macOS devices may fail to renew their management profile. Typically, devices attempt to renew their management profile upon every check-in starting at 28 days before the profile expires. We’re working with Apple to fix the bug, but there’s no estimate on the timing for the fix.

 

How does this affect me?

This issue has been seen in devices running OS version 10.14 or higher enrolled in Intune.

 

What action do I need to take?

Until this bug is fixed, you can either choose to not update to macOS Mojave (version 10.14) or you can run the script linked to in Additional Information to identify the devices that could have a management profile expire and then re-enroll them into Intune when they get close to their expiration date. The management profile is valid for a year and re-enrolling these devices would allow them to stay managed. We will remove this post when a solution is rolled out.

 

https://aka.ms/IT172124_script

 

Updated this post:

  • Feb 6, 2019 with info that the fix is in Apple's next OS update.
  • Feb 13, 2019 updated that the fix worked as expected. 
  • March 28, 2019 resolved (10.14.4 is live).