-
Notifications
You must be signed in to change notification settings - Fork 755
Clarify confusing "pending" behavior and fix broken link #37902
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
- Profiles are stuck in "pending" when APNs expires:
Added note about pending MDM commands until APNs certificate renewal.
articles/apple-mdm-setup.md
Outdated
| > Apple requires that APNs certificates are renewed annually. | ||
| > - The recommended approach is to use a shared admin account to generate the CSR ensuring it can be renewed regardless of individual availability. | ||
| > - If your certificate expires, you will have to turn MDM off and back on for all macOS hosts. | ||
| > - Configuration profile enforcement/removal and all other MDM commands will be stuck in "pending" until you renew. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Basically all MDM commands will be very, very slow(could take days or longer to get executed) once the cert expires. This includes profile installation/removal, iOS/iPadOS refetch, lock, wipe, etc. Ultimately it won't be fixed by the cert renewal but by re-enrolling the affected hosts.
| > Apple requires that APNs certificates are renewed annually. | ||
| > - The recommended approach is to use a shared admin account to generate the CSR ensuring it can be renewed regardless of individual availability. | ||
| > - If your certificate expires, you will have to turn MDM off and back on for all macOS hosts. | ||
| > - If your certificate expires, you will have to turn MDM off and back on for all macOS hosts. Until you do, configuration profile enforcement/removal and all other MDM commands will be stuck in "pending". |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@JordanMontgomery: Basically all MDM commands will be very, very slow(could take days or longer to get executed) once the cert expires. This includes profile installation/removal, iOS/iPadOS refetch, lock, wipe, etc. Ultimately it won't be fixed by the cert renewal but by re-enrolling the affected hosts.
@JordanMontgomery what do you think about my latest revision? I say "stuck" because they might as well be to the IT admin. Waiting for multiple days is close to as broken as them never getting applied.
Also, do commands really work after multiple days with an expired cert? You've seen that? That's weird...
|
@noahtalerman, looks like there's an outstanding question that needs answering for review, but as for the text, I suggest shortending and making more direct:
|
Uh oh!
There was an error while loading. Please reload this page.