jamf remote lock command stuck on pending: what to do
Fixes Jamf remote lock commands stuck on pending: push connectivity, command status, and fallback options. Use when a lock command never leaves pending. Not for lost devices with no network.
TL;DR
A remote lock stuck on pending means the device has not checked in with Jamf: it is offline, push notifications are broken, or the MDM profile is damaged. Confirm the device's last check-in, verify Apple push is working, then try again or fall back to other controls.
The query
jamf remote lock command stuck on pending: what to doUse this when
- remote lock command sits on pending in Jamf
- lost device needs locking urgently
- lock works on some devices but not one
Not for
- devices that never enrolled in Jamf
- wipe commands (different command, same debugging)
- Android devices (different MDM flow)
Steps
- In Jamf, check the device's last check-in time and last inventory update. Expected output: you know how long the device has been silent
- Confirm the device is online: ask the user or check network logs. Expected output: connectivity confirmed or ruled out
- Verify Apple Push Notification service is reachable and the Jamf push certificate is valid. Expected output: push path healthy
- Cancel the stuck command and reissue the remote lock. Expected output: a fresh command queued
- If it still pends, check the MDM profile on the device is intact; re-enroll if damaged. Expected output: profile healthy or re-enrolled
- If the device stays offline, document the pending lock and use your lost-device procedure for the interim. Expected output: risk documented and the ticket tracked
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_qLqxp4G2TaWsKobk5eQzHA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.