Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Device enrolled but CA trust: Awaiting approval for days | Employee hasn’t answered the trust prompt | Ask them to respond, or push the CA certificate profile from the device row |
| CA trust: Declined | Employee clicked Cancel on the password prompt | It prompts once per enrollment by design — talk to them, or use MDM-enforced trust |
| MDM profile action says the device has not uploaded its CA certificate | Agent predates the feature or hasn’t reported since installing | Update the agent; wait one check-in |
| Pushed the trust profile but the badge still says Local | The device hasn’t reported since the profile landed (download ≠ install; the badge follows the device’s own report) | Wait for its next check-in; verify the profile actually deployed in your MDM |
| A deployed profile seems to have changed nothing | User-scoped assignment, or a wrong code requirement in your MDM | Both make a profile report as installed while doing nothing — see MDM profile delivery |
| Proxy: error / degraded | Local proxy process unhealthy on the device | Check the device row’s freshness; if persistent, have IT check the agent on that Mac |
| Everything Unknown for one device | Device offline / agent stopped / very old agent | Confirm the Mac is on and networked; reinstall or update the agent |
| Policy shows running v3 while latest is v5 | Device converging or offline | Normal within minutes; investigate only if it persists across check-ins |
| Employee reports “nothing gets blocked” | They’re on Default with log-only rules, or the destination isn’t in any targeted group | Check their template assignment and the rule’s destination groups; check Events to see what actually fired |
| A paste was blocked that shouldn’t be | An over-broad rule above a missing carve-out | Add an Allow rule for the destination above the broad rule — first match wins |
Still stuck? Contact support with the device’s identifier from the Devices page and roughly when the behavior started.