mdm enrollment failed: "an existing MDM profile was found" on macos
Removes a stale MDM profile blocking macOS enrollment with the existing MDM profile error: identifying the leftover and re-enrolling cleanly. Use when enrollment fails saying an MDM profile was found. Not for server-unreachable or credential errors.
TL;DR
A previous management profile is still installed, and macOS allows only one MDM enrollment. Remove the old profile from System Settings, confirm it is gone, then enroll again.
The query
mdm enrollment failed: "an existing MDM profile was found" on macosUse this when
- macOS enrollment fails with the existing MDM profile message
- a Mac was reimaged but kept its old profile
- moving a Mac from one MDM to another
Not for
- MDM server not reachable errors
- enrollment credential or invitation failures
- Apple Business Manager assignment problems
Steps
- Open System Settings, then General, then Device Management, and list the installed profiles. Expected output: the stale management profile is visible.
- Remove the old MDM profile, providing admin credentials if prompted. Expected output: the profile list no longer shows the old enrollment.
- Verify removal with the profiles command to confirm no MDM payload remains. Expected output: no MDM profile is reported.
- Start enrollment with the new MDM invitation or enrollment URL. Expected output: the new profile installs and the Mac checks in.
- Confirm in the new MDM console that the device is enrolled and compliant. Expected output: the device record appears with a recent check-in.
Applies to
macOS Ventura and later, Jamf Pro, Mosyle, Kandji, or any MDM, Apple Business Manager.
Variant phrasings
Profile remove button is greyed out
The profile is non-removable; erase the Mac or use the old MDM to release it first.
Old profile returns after removal
Automated Device Enrollment re-pushes it; release the device in Apple Business Manager first.
Why it happens
macOS enforces a single MDM authority per device. Reimages and tenant moves often leave the old profile behind, and the new enrollment refuses to proceed until it is gone.
Edge cases
- User-approved MDM on older macOS needed manual approval; the flow differs before Ventura.
- If the old MDM is decommissioned, an erase may be the only path to clear a non-removable profile.
- Document the serial before erasing; you will need it to reassign in Apple Business Manager.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst3eckmbbCU8zTd-KcH8pmQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.