darkbloom unenroll errors: moving from MDM to App Attest, step by step
Updated
Short answer: darkbloom unenroll only shows you which profile to remove after Darkbloom’s coordinator has confirmed, within the last 10 seconds, that App Attest verifies your running provider and that removal is turned on for your Mac. Most errors mean one of those isn’t true yet, or the command couldn’t read your profiles because it wasn’t run in an interactive Terminal. Keep the profile installed until the command names it. Everything below comes from Darkbloom’s docs and the command’s source code (links at the end).
Before you start
- macOS 27 or later. On older macOS the App Attest option refuses and tells you to keep the profile.
- The provider running and up to date: darkbloom update, then darkbloom restart.
- A user logged in at the Mac’s screen (or over Screen Sharing), with the provider running in that session.
- darkbloom status or darkbloom doctor saying App Attest authorizes this connection and that Darkbloom MDM removal is available.
- An administrator password, in case the command needs sudo to read the installed profiles.
Step by step
- Open Terminal on the Mac itself, or over Screen Sharing. Not over SSH, and not as a background job.
- Run darkbloom doctor. It should say App Attest authorizes this connection and that removal is available.
- Run darkbloom unenroll and choose 2, “Remove only Darkbloom MDM — keep serving with App Attest”. Option 1 is full exit: it stops the provider and offers to delete your keys. Press Enter to cancel.
- If asked, enter your administrator password. It is used only to read the list of installed profiles.
- The command names the exact profile, with its identifier and server, and opens System Settings → General → Device Management. Remove only that profile. Keep any company management profile.
- Keep the provider running while you remove it, then run darkbloom doctor again.
- darkbloom unenroll --keep-serving does the same without the menu.
Error messages and what to do
| Message | What it means | What to do |
|---|---|---|
| “App Attest authorization is unconfirmed; keep any existing management profiles installed…” | The command found no fresh verdict from the coordinator for this running provider: it isn’t running, isn’t connected, or its state is more than 10 seconds old. | Start or restart the provider from the logged-in desktop, wait until darkbloom status shows it online, then run the command again. |
| “App Attest authorizes this connection. Darkbloom MDM removal is not enabled for this machine yet.” | App Attest works, but Darkbloom hasn’t turned on removal for your Mac. | Keep the profile. There is nothing to fix on your side; try again later. |
| “Serving through legacy verification; keep the Darkbloom MDM profile.” | Your Mac is still verified through MDM, not App Attest. | Keep the profile. Update and restart the provider, then check the APP ATTEST section of darkbloom doctor. |
| “The coordinator supports App Attest, but this connection is not currently qualified…” | App Attest isn’t verifying this connection right now. The reason follows the message. | Fix what darkbloom doctor flags (logged-in session, Full Security, a current provider). The coordinator retries after 1 minute, then 5, then every 10. |
| “This coordinator has not enabled App Attest serving…” | Darkbloom hasn’t enabled App Attest for this connection. | Keep the profile, check darkbloom doctor and contact Darkbloom support. |
| “Removing MDM while keeping this provider online requires macOS 27 or later…” | The Mac runs an older macOS. | Keep the profile until you upgrade to macOS 27 and App Attest verifies the Mac. |
| “Run darkbloom unenroll in an interactive terminal to choose…” | The command ran without a terminal, for example from a script or an SSH session without one. | Run it in Terminal, or use --keep-serving. |
| “Could not verify the exact Darkbloom enrollment profile and server…” | The command couldn’t read the installed profiles as administrator (password refused, no terminal, or a background job), or couldn’t match the Darkbloom profile. | Run it again in the foreground of a Terminal window and enter your administrator password. If it still fails, keep your profiles and contact Darkbloom support. |
| “App Attest readiness changed during the profile check…” | The verdict expired or changed while the command read the profiles. | Keep the profile. Wait until darkbloom status shows App Attest again, then retry. |
| “The installed management profile could not be identified…” | The profile check itself failed. | Run darkbloom doctor, then try again. |
| “App Attest authorizes this connection. No Darkbloom MDM enrollment needs removal.” | Not an error: there is no Darkbloom profile to remove. | Nothing to do. |
| “A provider process is still running or shutting down…” | Full exit only: a darkbloom process started by hand is still running. | Stop it, then run the command again. No local data was removed. |
| “--force cannot be combined with --keep-serving…” | --force means full exit, which deletes local data. | Leave out --force. |
What not to do
- Don’t remove the profile in System Settings before the command names it. That is a common way providers lost verification in September 2026.
- Don’t delete Keychain items, credentials or ~/.darkbloom to force App Attest. Darkbloom’s docs say not to delete account, machine, Keychain or management state to force retries.
- Don’t choose full exit (option 1) unless you want to stop providing.
- Don’t remove a company management profile. App Attest works alongside it.
After removal
The command keeps your Darkbloom account, machine identity, App Attest keys and models. If App Attest authorization later expires or is revoked, new requests wait until the Mac is verified again. Run darkbloom status and check the Trust line.
Sources
- Provider attestation guide (removal rules): github.com/Layr-Labs/d-inference/blob/master/docs/provider/attestation.md
- CLI reference (darkbloom unenroll): github.com/Layr-Labs/d-inference/blob/master/docs/provider/cli-reference.md
- App Attest authorization: github.com/Layr-Labs/d-inference/blob/master/docs/reference/provider-authorization.md
- Menu choice and macOS check: github.com/Layr-Labs/d-inference/blob/master/provider-swift/Sources/darkbloom/UnenrollCommand+Choice.swift
- App Attest removal path: github.com/Layr-Labs/d-inference/blob/master/provider-swift/Sources/darkbloom/UnenrollCommand+KeepServing.swift
- Readiness messages: github.com/Layr-Labs/d-inference/blob/master/provider-swift/Sources/ProviderCore/Diagnostics/ProviderAuthorizationReadiness.swift
How BloomGauge helps
BloomGauge shows live whether paid work is reaching your Mac and what it earns each hour, so if verification lapses after you remove the profile, it shows up as paid work stopping, not as a gap in next week’s payout.
Questions
How do I remove Darkbloom MDM and keep serving on macOS 27?
Wait until darkbloom doctor says App Attest authorizes the connection and MDM removal is available. Then run darkbloom unenroll in Terminal on the Mac, choose option 2 (keep serving with App Attest), enter your administrator password if asked, and remove only the profile it names in System Settings → General → Device Management.
Why does darkbloom unenroll say App Attest authorization is unconfirmed?
The command needs a verdict from Darkbloom’s coordinator for the running provider that is less than 10 seconds old. Start or restart the provider from the logged-in desktop, wait until darkbloom status shows it online, and run the command again.
What does “Could not verify the exact Darkbloom enrollment profile and server” mean?
darkbloom unenroll couldn’t read the installed profiles as administrator, usually because it wasn’t run in the foreground of an interactive Terminal or the password prompt was refused. Run it again in Terminal on the Mac and enter your password. Keep all profiles installed until it names the right one.
Does darkbloom unenroll remove the profile for me?
No. It checks that removal is safe, names the exact Darkbloom profile and opens System Settings. You remove it there.
Related
- Darkbloom verification pending: MDM, App Attest and trust on macOS 27
- Running Darkbloom on a headless Mac: no monitor, SSH and automatic login
- Is Darkbloom safe? What access it gets to your Mac
Updated 2026-09-29. Still stuck? Ask in #bloomgauge on the Darkbloom Slack or contact us. BloomGauge is independent and not affiliated with Darkbloom.