Enrolled devices in Apple business manager can easily just remove themself from organization during factory reset

Enrolled devices in Apple business manager can easily just remove themself from organization during factory reset

I thought I had everything done correctly but I cannot seem to activation lock our corporate ios devices.
They are registered in apple business manager.  During a factory reset they correctly come up to the Remote Management page but under the "enroll this iphone" button is text "Remove iPhone from Organization" which I tested and it absolutely worked and the phone continued on with the regular personal device registrations screens.  In apple business manager it now shows up as released.  No password required, no admin action, just a simple reset from the general settings.  

In apple business manager devices all the phones show "activation lock" Off in ABM.

To re-enroll I have to use the apple configurator to add it back, assign it back to our Zoho MDM and in Zoho MDM go to the Enrollment - Apple ABM and hit sync and it enrolled again.  (If you do not hit sync after using configurator to add it back again it will continue to go to the personal activation steps.  Likely some back end token needs to sync after every time you manually re-enroll a device even if it's already listed)

I have the MDM setting in Apple business manager to say "Allow this MDM Server to release devices." disabled too.  




                New to ADSelfService Plus?