Skip to content

Troubleshooting

SymptomLikely causeFix
Device enrolled but CA trust: Awaiting approval for daysEmployee hasn’t answered the trust promptAsk them to respond, or push the CA certificate profile from the device row
CA trust: DeclinedEmployee clicked Cancel on the password promptIt prompts once per enrollment by design — talk to them, or use MDM-enforced trust
MDM profile action says the device has not uploaded its CA certificateAgent predates the feature or hasn’t reported since installingUpdate the agent; wait one check-in
Pushed the trust profile but the badge still says LocalThe device hasn’t reported since the profile landed (download ≠ install; the badge follows the device’s own report)Wait for its next check-in; verify the profile actually deployed in your MDM
A deployed profile seems to have changed nothingUser-scoped assignment, or a wrong code requirement in your MDMBoth make a profile report as installed while doing nothing — see MDM profile delivery
Proxy: error / degradedLocal proxy process unhealthy on the deviceCheck the device row’s freshness; if persistent, have IT check the agent on that Mac
Everything Unknown for one deviceDevice offline / agent stopped / very old agentConfirm the Mac is on and networked; reinstall or update the agent
Policy shows running v3 while latest is v5Device converging or offlineNormal within minutes; investigate only if it persists across check-ins
Employee reports “nothing gets blocked”They’re on Default with log-only rules, or the destination isn’t in any targeted groupCheck their template assignment and the rule’s destination groups; check Events to see what actually fired
A paste was blocked that shouldn’t beAn over-broad rule above a missing carve-outAdd an Allow rule for the destination above the broad rule — first match wins

Still stuck? Contact support with the device’s identifier from the Devices page and roughly when the behavior started.