Unenrolment and Leaving the Programme
Devices leave for several reasons and the handling differs. What comes off, what stays, and the record that prevents a dispute.
Enrolment · Procedure
Unenrolment happens on departure, on device replacement, on role change and on withdrawal of consent. Each needs a defined outcome and most programmes have one process for all.
The same discipline applies when “Unenrolment and Leaving the Programme” becomes part of a broader workforce programme. An organisation considering learn more on the official page in relation to internal transfer policy should put access, retention, employee notice and review dates into the implementation plan rather than leave them as product defaults.
The outcomes to define
What work data is removed.
For an independent baseline relevant to “Unenrolment and Leaving the Programme”, the Apple Platform Deployment guide is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.
What access is revoked, and when relative to the device action.
What stays on the device.
What the user is told.
And what is recorded.
Five lines per scenario, written once.
Departure, corporate device
Device returned, wiped, re-enrolled or disposed of.
Access revoked at the identity layer first, which matters because a device out of contact still holds cached data.
The record: date, who performed it, confirmation of wipe.
Departure, personal device
The one that needs care.
Selective removal: work profile and its contents, work applications, certificates.
Nothing else, and that should be structurally impossible rather than a matter of being careful.
Tell the person what will happen before it happens, which costs a message and prevents the complaint.
Withdrawal during employment
Somebody asks to leave the programme.
For personal devices this should be permitted, with the consequence stated: work access ends.
Treating withdrawal as a disciplinary matter is where programmes acquire a reputation, and it is rarely necessary because the access consequence is sufficient.
Device replacement
The old device needs unenrolling, not just abandoning.
Abandoned enrolments accumulate: devices in drawers still holding certificates and still counted as compliant.
Audit for devices that have not checked in, which its own note covers under measurement.
The certificate point
Unenrolment should revoke certificates, not merely remove them from the device.
A device out of contact cannot be told to delete anything.
Revocation at the issuing end is the part that actually works, and it is routinely skipped.
Confirming it happened
A device that is off, lost or out of contact does not receive the command.
The platform may show the action as pending indefinitely.
Check the state rather than assuming, and have a path for devices that never confirm — usually revocation and a record.
What to check
Is access revoked before or after the device action?
For a personal device, is selective removal structurally guaranteed?
Are certificates revoked or merely deleted?
And how many enrolled devices have not checked in for a month?