Description
Each profile deployed and managed by Jamf Now is signed as part of the profile creation process. If the signing certificate becomes expired managed profiles will show as Unverified. This should not impact the device's ability to communicate with Jamf Now.
The following screenshots display how a Jamf Now managed profile on a device will appear Unverified if the signing certificate expired:
Making Profiles Verified Again
A new profile would need to install to have it show as 'verified.' There are a few options:
Automatic MDM profile renewal: Jamf Now automatically initiates the MDM profile renewal process when the main MDM profile is set to expire in 6 months. This is the most common way for the MDM profile to become verified again, as it does not require any action from the administrator or end user.
Re-enrolling a Mac via Terminal: Refer to the Jamf Now documentation page Re-enrolling a Computer Using Automated Device Enrollment for instructions.
Erasing and re-enrolling auto-enrolled iOS/iPadOS devices: This option is necessary for auto-enrolled iOS/iPadOS devices.
Unenrolling and re-enrolling Open Enrolled devices: Open Enrolled devices can be unenrolled and re-enrolled via Open Enrollment.