Could not download the identity profile from the encrypted profile service on MAC

%3CLINGO-SUB%20id%3D%22lingo-sub-2162603%22%20slang%3D%22en-US%22%3ECould%20not%20download%20the%20identity%20profile%20from%20the%20encrypted%20profile%20service%20on%20MAC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2162603%22%20slang%3D%22en-US%22%3E%3CDIV%20class%3D%22lia-message-subject-wrapper%20lia-component-subject%20lia-component-message-view-widget-subject-with-options%22%3E%3CDIV%20class%3D%22MessageSubject%22%3E%3CDIV%20class%3D%22MessageSubjectIcons%20%22%3E%26nbsp%3B%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22lia-message-body%20lia-component-message-view-widget-body%20lia-component-body-signature-highlight-escalation%20lia-component-message-view-widget-body-signature-highlight-escalation%22%3E%3CDIV%20class%3D%22lia-message-body-content%22%3E%3CP%3EI%20am%20getting%20attached%20error%20while%20logging%20onto%20company%20portal%20on%20MAC.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20verified%20that%20MDM%20push%20certificate%20is%20up%20to%20date.%20I%20am%20trying%20to%20do%20it%20on%20a%20machine%20that's%20installed%20on%20VM%20ware.%26nbsp%3B%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2162603%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2334965%22%20slang%3D%22en-US%22%3ERe%3A%20Could%20not%20download%20the%20identity%20profile%20from%20the%20encrypted%20profile%20service%20on%20MAC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2334965%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3Eyou%20might%20want%20to%20check%20if%20your%20device%20has%20a%20serial%20number.%20Sometimes%20after%20repair%20(replace%20of%20motherboard)%20the%20serial%20number%20is%20not%20written%20to%20the%20firmware%20again.%20You%20can%20verify%20with%20the%20%22About%20This%20Mac%22%20if%20you%20have%20a%20serial%20number.%20It%20must%20be%20displayed%20there.%20You%20then%20have%20two%20options.%20Call%20apple%20support%20to%20fix%20the%20missing%20serial%20number%20or%20you%20can%20follow%20some%20guides%20in%20the%20internet%20to%20write%20back%20the%20serial%20number%20to%20the%20firmware.%20But%20be%20aware%20utilizing%20internet%20tools%20for%20this%20is%20not%20supported%20and%20totally%20your%20personal%20risk!%20The%20process%20can%20also%20not%20be%20undone!%20It%20is%20not%20recommended%20to%20do!%20If%20you%20still%20like%20to%20do%20it%2C%20have%20a%20look%20for%20%22blank%20board%20serializer%22%20and%20there%20look%20for%20a%20version%20which%20boots%20with%20devices%202012%20and%20later.%20After%20you%20have%20your%20serial%20number%20again%2C%20the%20enrollment%20should%20work%20again.%20%3CBR%20%2F%3E%3CBR%20%2F%3Ebest%2C%3CBR%20%2F%3EOliver%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2335015%22%20slang%3D%22en-US%22%3ERe%3A%20Could%20not%20download%20the%20identity%20profile%20from%20the%20encrypted%20profile%20service%20on%20MAC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2335015%22%20slang%3D%22en-US%22%3ESO%20it's%20installed%20on%20vmware%3CBR%20%2F%3E%3CBR%20%2F%3EI%20found%20this%20article...%20maybe%20it's%20describing%20your%20problem%3CBR%20%2F%3E-----%3CBR%20%2F%3EIntune%2FApple%20doesn't%20like%20working%20on%20a%20VM-based%20Mac%20unless%20certain%20modifications%20are%20made%20to%20the%20.VMX%20file%20to%20make%20it%20look%20like%20a%20real%20Mac.%20I%20made%20these%20modifications%20originally%20but%20then%20upon%20rolling%20back%20one%20of%20my%20VM%20snapshots%2C%20the%20modification%20got%20lost.%20Since%20I%20was%20working%20off%20the%20base%20snapshot%2C%20what%20used%20to%20work%20no%20longer%20worked%20on%20any%20of%20the%20other%20VMs%20I%20built%20from%20the%20base%20snapshot.%3CBR%20%2F%3E%3CBR%20%2F%3ESo....%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20modify%20the%20.vmx%20file%20you%20need%20to%20right-click%20on%20the%20VM%20bundle%20(I'm%20using%20VMWare%20here)%20and%20Show%20Package%20Contents.%20You%20will%20find%20the%20.vmx%20file%20in%20there%20that%20you%20need%20to%20modify%20with%20a%20text%20editor.%3CBR%20%2F%3E%3CBR%20%2F%3EAdd%20the%20following%203%20lines%20to%20the%20end...%20IMPORTANT%2C%20no%20quotes%20on%20the%20last%202%20items....%20AND%20come%20up%20with%20your%20own%20valid%20serial%20number%2Fhw.model%20match.%3CBR%20%2F%3E%3CBR%20%2F%3ESMBIOS.use12CharSerialNumber%20%3D%20%E2%80%9CTRUE%E2%80%9D%3CBR%20%2F%3EserialNumber%20%3D%20FVFZX1A1JYW0%3CBR%20%2F%3Ehw.model%20%3D%20Macmini8%2C1%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20find%20a%20serial%20number%20and%20matching%20hardware%20model%2C%20go%20find%20another%20Mac%2C%20click%20on%20the%20Apple%20on%20the%20top%20left%20then%20About%20This%20Mac%20and%20then%20System%20Report.%20There%20you%20will%20see%20the%20Model%20Identifier%20of%20the%20Mac%20as%20well%20as%20the%20Serial%20Number%20(system)%20of%20the%20Mac.%20You%20probably%20shouldn't%20reuse%20a%20serial%20number%20(not%20sure%20what%20will%20happen%20though)%20but%20instead%20change%20a%20few%20of%20the%20characters%20in%20the%20serial%20number%20to%20make%20it%20different%20from%20any%20of%20the%20ones%20that%20you%20have.%20The%20serial%20number%20schema%20is%3A%3CBR%20%2F%3E%3CBR%20%2F%3EChar%201-3%20(Factory%20code)%3CBR%20%2F%3EChar%204%20(Year%20and%20whether%20first%20half%20or%20second%20half)%3CBR%20%2F%3EChar%205%20(Manufacturing%20week)%3CBR%20%2F%3EChar%206-8%20(ID%20number%20of%20device%20-%20this%20is%20the%20part%20you%20can%20change%20with%20least%20impact)%3CBR%20%2F%3EChar%209-12%20(Model%20-%20this%20is%20the%20part%20that's%20most%20tied%20to%20the%20hw.model%20value%20above)%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Occasional Contributor
 

 

I am getting attached error while logging onto company portal on MAC.

 

I have verified that MDM push certificate is up to date. I am trying to do it on a machine that's installed on VM ware. 

3 Replies
Hi,

you might want to check if your device has a serial number. Sometimes after repair (replace of motherboard) the serial number is not written to the firmware again. You can verify with the "About This Mac" if you have a serial number. It must be displayed there. You then have two options. Call apple support to fix the missing serial number or you can follow some guides in the internet to write back the serial number to the firmware. But be aware utilizing internet tools for this is not supported and totally your personal risk! The process can also not be undone! It is not recommended to do! If you still like to do it, have a look for "blank board serializer" and there look for a version which boots with devices 2012 and later. After you have your serial number again, the enrollment should work again.

best,
Oliver
SO it's installed on vmware

I found this article... maybe it's describing your problem
-----
Intune/Apple doesn't like working on a VM-based Mac unless certain modifications are made to the .VMX file to make it look like a real Mac. I made these modifications originally but then upon rolling back one of my VM snapshots, the modification got lost. Since I was working off the base snapshot, what used to work no longer worked on any of the other VMs I built from the base snapshot.

So....

To modify the .vmx file you need to right-click on the VM bundle (I'm using VMWare here) and Show Package Contents. You will find the .vmx file in there that you need to modify with a text editor.

Add the following 3 lines to the end... IMPORTANT, no quotes on the last 2 items.... AND come up with your own valid serial number/hw.model match.

SMBIOS.use12CharSerialNumber = “TRUE”
serialNumber = FVFZX1A1JYW0
hw.model = Macmini8,1

To find a serial number and matching hardware model, go find another Mac, click on the Apple on the top left then About This Mac and then System Report. There you will see the Model Identifier of the Mac as well as the Serial Number (system) of the Mac. You probably shouldn't reuse a serial number (not sure what will happen though) but instead change a few of the characters in the serial number to make it different from any of the ones that you have. The serial number schema is:

Char 1-3 (Factory code)
Char 4 (Year and whether first half or second half)
Char 5 (Manufacturing week)
Char 6-8 (ID number of device - this is the part you can change with least impact)
Char 9-12 (Model - this is the part that's most tied to the hw.model value above)



Oh :-D, I ignored the upper bar in the picture... you are totally right... it is a VM... then the approach mentioned should work. I used this approach already in the past. Thx @Rudy_Ooms for pointing this out.