Overview
Remote disenrolment has two conditions, and both have to hold:
- The device is enrolled and still present in your fleet.
- The device shows as Online.
Miss either one and the action is not offered.
How to use
Disenrol remotely
Open the device, then click Actions > Disenroll.

Management is removed immediately on macOS. On Windows it takes a short while longer.
How to use
When the device is offline
An offline device cannot be sent a command, so there is nothing to remove. You have two options:
- Wait for the device to come back online, then disenrol it normally.
- Mark it as disenrolled, which records that the device is no longer managed. Use this when the device is gone for good and you have already lost contact with it.
Marking a device as disenrolled changes your records, not the device. If that machine ever reconnects, it is still carrying the profile and the agent.
Uninstall by hand
Sometimes you have the device in front of you but not in the platform. In that case, remove the two pieces by hand: the management profile first, then the agent.

On Windows you need administrator rights on the device.
Remove the management account:
- Open Start > Settings > Accounts.
-
Go to Access work or school.

- Find the entry for the MDM in the list of accounts managing the device — it appears as Managed by Fleet MDM.
- Select it and click Disconnect (or Remove).

-
Follow the prompts to the end.
Then remove the agent:
- Search for Control Panel in the taskbar and open it.
- Go to Programs > Programs and Features.
- Right-click Fleet osquery and choose Uninstall.
- Follow the prompts.
On macOS the profile lives in System Settings:
- Open System Settings > Privacy & Security.
- Scroll down and click Profiles.
- Select your company's enrolment profile and click the ➖ button.
-
Click Remove.


Enter your account password.
The agent is still there after the profile is gone. Download the disenrolment package, then right-click it and open it to finish the job.
Tips and Best Practices
- Disenrol before the laptop leaves the building. It is a single click while the device is online, and a manual uninstall or a dead record once it is not.
- Remove both pieces, not just one. A device with the profile gone but the agent still running keeps reporting; a device with the agent gone but the profile intact stays managed. Half a removal leaves a confusing record either way.
- Use "Mark as disenrolled" as a records fix, not a security measure. If the device still exists somewhere, it is still carrying your configuration.
- Wipe instead of disenrolling when the device will not come back. Disenrolment removes management, not company data.
Troubleshooting and FAQ
Troubleshooting
- The Disenrol action is greyed out. The device is offline. Wait for it to reconnect, or mark it as disenrolled if it is never coming back.
- Windows still shows the device as managed after disenrolling. Windows applies the removal with a delay. If it persists, check Access work or school on the device itself — the account may need removing by hand.
- The macOS profile cannot be removed. It is locked. A locked profile is removed from the platform, not from the device.
- The device reappears in the fleet after being disenrolled. The agent was never removed. Uninstall Fleet osquery on Windows, or run the disenrolment package on macOS.
FAQ
-
Does disenrolling erase the device?
No. It removes management and leaves data, apps and accounts untouched. Use a wipe if you need the data gone.
-
What is the difference between disenrolling and marking as disenrolled?
The first removes management from the device. The second only updates your records, for devices you can no longer reach.
-
Can a disenrolled device be enrolled again?
Yes, through any of the normal enrolment methods.
-
Why does Windows need two separate removals?
The management account and the agent are separate pieces of software. Removing one leaves the other in place.