Because there are certain limitations with how Activation Lock reports its status to Jamf Pro, it is important to understand how to determine if Activation Lock is enabled on computers and mobile devices in your environment. Due to these limitations, the only way to determine if Activation Lock is currently enabled on a device is to view the device in Apple Business or Apple School Manager.
User-based Activation Lock is a device-specific function. When Jamf Pro queries a device with the DeviceInformation command, the status it returns is typically accurate. However, there are circumstances that can prevent that status from being accurate, such as if Activation Lock was enabled on a device by a user prior to enrollment. Because of this potential inaccuracy, Jamf recommends using Apple Business or Apple School Manager as the source of truth for user-based Activation Lock status.
When organization-based Activation Lock is enabled on a mobile device, the Activation Lock status reports as "Not enabled", which is inaccurate. This is due to organization-based Activation Lock being an entirely server-side function. There is no Activation Lock data on the device itself, and Jamf cannot query Apple's servers to discover the Activation Lock status.
There are other ways to determine if organization-based Activation Lock was enabled on a mobile device. Jamf recommends the following methods:
View the Activation Lock status in Apple Business or Apple School Manager.
View the Activation Lock bypass code in Jamf Pro. If there is a code present under Bypass Code to Use When Activation Lock is Enabled on the Device, organization-based Activation Lock was enabled on the device.
For more information on how to view the Activation Lock bypass code, see Viewing Activation Lock Information.