Apple ADE: MDM Certificate vs. MDM Trust Chain
What
FileWave 16.2.0 changed the default certificate material added to Automated Device Enrollment (ADE, formerly DEP) profiles. The choice is controlled by MDM Certificate added to ADE profiles in FileWave Central under Preferences > VPP & ADE.
When/Why
The setting determines how an enrolling Apple device validates the FileWave MDM server certificate. MDM Trust Chain adds the parent certificate chain and avoids recreating ADE profiles during routine server-certificate renewal. MDM Certificate uses the current MDM server certificate for stricter matching, but affected ADE profiles must be updated when that certificate is renewed. Recreating profiles during renewal can produce duplicate ADE/DEP profiles.
How
In FileWave Central, open Preferences > VPP & ADE and review MDM Certificate added to ADE profiles.
Keep MDM Trust Chain unless your security requirements call for the current MDM server certificate in the enrollment profile. If you select MDM Certificate, include ADE profile updates and assignment review in every server-certificate renewal plan.

No comments to display
No comments to display