Unable to enroll DEP devices, failing while the 2nd profile installation with an error: "the new mdm payload doesn't match the old payload"
Get the correct .pfx file, re-upload it to the XMSserver and reboot it it.
Now it should be in a proper chain.
For the DEP devices which are not able to connect to the XMS server, need to full wipe them and enroll them again.
After doing this, they will get enrolled without any error and now the users can remove both the profiles manually, and re-enroll the devices.
Found that the SSL listener was not in a proper chain. Manual MDM profile removal under DEP configuration was blocked.