Default device enrollment profile is missing

What is the name of the domain?

What is the issue you’re encountering

When manually enrolling a device which does not match any existing profile conditions, it will use a profile with the id default which does not show up on the dashboard. The invisible profile itself is not functional, showing the error CF_DNS_LOOKUP_FAILURE when attempting to connect with WARP

What steps have you taken to resolve the issue?

  • I have tried creating a profile manually, which fails with the error Error configuring your profile: Cannot set forbidden fields in the default profile.
  • I have tried creating a profile through the device enrollment wizard, which works, but trying to set it as a default profile fails with the error Error updating profile: Error: resource not found

What are the steps to reproduce the issue?

  1. Go to Settings → WARP Client
  2. Notice missing default profile

Screenshot of the error

This is the ouput of warp-cli settings in case it is useful

Merged configuration:
(not set)       Compliance Environment: Normal
(derived)       Always On: false
(override)      Switch Locked: false
(default)       Mode: Warp
(network policy)        WARP tunnel protocol: WireGuard
(not set)       MASQUE Protocol Settings:
  HTTP Version: MASQUE (HTTP/3 with HTTP/2 fallback)
(not set)       Prefer post-quantum for MASQUE: false
(network policy)        Disabled for Wifi: false
(network policy)        Disabled for Ethernet: false
(network policy)        Resolve via: .cloudflare-gateway.com @ [162.159.36.1, 162.159.46.1, 2606:4700:4700::1111, 2606:4700:4700::1001]
(not set)       qlog log until: FutureSystemTime(None)
(default)       Onboarding: true
(network policy)        Exclude mode, with hosts/ips:

(default)       Fallback domains:
  corp
  domain
  home
  home.arpa
  host
  internal
  intranet
  invalid
  lan
  local
  localdomain
  localhost
  private
  test
(not set)       Daemon Teams Auth: false
(network policy)        Disable Auto Fallback: false
(network policy)        Captive Portal: 0
(network policy)        Support URL:
(network policy)        Organization: <organization name goes here>
(network policy)        Allow Mode Switch: false
(network policy)        Allow Updates: false
(network policy)        Allowed to Leave Org: false
(network policy)        Profile ID: default
(not set)       Registration Scope: System
(network policy)        Register Tunnel Interface IP: false
(not set)       Firewall Scope: All interfaces
(network policy)        SCCM VPN Boundary Support: false

I have the exact same problem. The default profile isn’t there and I am unable to create any other profile. Basically, stuck and cannot proceed!