如何通过API查询企业已注册设备的MDM Profile是否被删除?
Hey there! Let's tackle your question about checking if an MDM profile has been removed from your enterprise-enrolled device, plus how to do this via API. Here's what you need to know:
Manual Checks for MDM Profile Status
First, if you have physical access to the device, you can verify the profile status directly based on the OS:
iOS/iPadOS & macOS
- iOS/iPadOS: Open Settings > General > VPN & Device Management. Any installed MDM profiles will be listed here. If your enterprise's MDM entry is missing, it's been deleted.
- macOS: For newer versions, go to System Settings > Privacy & Security > Device Management. On older macOS releases, open System Preferences > Profiles. If the target MDM profile isn't present, it's no longer installed.
Windows
- Settings UI: Navigate to Settings > Accounts > Access work or school. If your enterprise's MDM connection is gone, or shows as "Disconnected" with no option to rejoin, the profile is likely removed.
- Command Line: Open an elevated Command Prompt and run
dsregcmd /status. Look for theMDM EnrollmentandMDM Statusfields—if they showNot enrolled, the MDM profile has been deleted.
Querying via API
Nearly all enterprise MDM platforms offer APIs to check device enrollment and profile status, which is perfect for automated checks. Here are examples for common platforms:
Microsoft Intune
- Use the Microsoft Graph API to fetch device details: Send a
GETrequest tohttps://graph.microsoft.com/v1.0/devices/{deviceId}. In the response, check themanagementStatefield—managedmeans the MDM profile is still active, whileunenrolledindicates it's been removed. - To specifically check profiles, call
https://graph.microsoft.com/v1.0/deviceManagement/managedDevices/{deviceId}/deviceConfigurationsand verify if your enterprise's MDM profile is in the returned list.
Jamf Pro
- For Mac devices, send a
GETrequest tohttps://your-jamf-server-url/JSSResource/computers/id/{deviceId}. For iOS/iPadOS, usehttps://your-jamf-server-url/JSSResource/mobiledevices/id/{deviceId}. Look for themdm_profile_installedfield in the response—truemeans the profile is present,falsemeans it's gone.
General API Tips
- You'll need appropriate API permissions (usually read-only or admin access) for your MDM platform, plus a valid auth token/API key to authenticate requests.
- Each platform's API structure varies, so refer to their official docs for exact endpoints and response field details.
内容的提问来源于stack exchange,提问作者Vijayavel Mohan
相关产品推荐
相关产品推荐

