You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Added MDM Server, but only option is "Erase iPhone"

Hi Everyone,


I could use some help with Apple Business Manager and my MDM.


I used Apple Configurator 2 on a iPhone. I scanned the QR code and device I was adding, an iPhone, states


"This iPhone has been added to "[my company name]".


This iPhone has been assigned to MDM Server "[my server name]" in Apple Business Manager"


I logged into Apple Business Manager and the device is correctly assigned to my MDM Server. Then I went to my MDM, in this case Knox Manage, and synced the device over. I can now see the device and I assigned it a profile.


However, nothing has changed on the iPhone itself. I still see the same message with the only option being "Erase iPhone". If I click this button, the device erases and the OBE starts all over again.


It is not clear where I'm suppose to go from here.


Any assistance is appreciated.


Kind regards

iPhone 14

Posted on Sep 19, 2024 10:15 AM

Reply
2 replies

Oct 9, 2024 5:45 AM in response to SiDi2024

If you are sideloading devices via Configurator, then you have additional steps. The sideload injects a retail purchased device into the chain of custody that is ABM. ABM can assign it to an MDM. But then the MDM must have a prestage enrollment and you must erase the device one more time to allow it to discover that it is an institutional device that must enroll using the automated device enrollment workflow.


Here are the broad strokes.


1: You have ABM and an MDM setup. You've created an MDM server in ABM and your exported the DEP token and imported it into your MDM. From above, it sounds like you have succeeded in do this. (As an aside, a similar process is required for the VPP token).


2: You have a retail purchased asset that is not associated to your organization and you use Configurator to side load it. If done from a Mac, the asset is assigned to the "configurator" MDM in ABM and you must reassign it. If done from an iPhone and you selected Specific MDM, then it can be auto associated to your desired MDM. In this case, looking at the record in ABM will show that it is assigned to your MDM.


3: In your MDM, setup your prestage profile (not sure what Knox calls this, but it is your initial MDM profile that begins automated enrollment. The device in question must be assigned to this profile as well. It will include options like controlling Setup Assistance, management of activation lock, etc.


4: Erase your device again. The reason for this is that when you first power it on (before capturing with Configurator), it talked to Apple's activation server and was marked a retail device. It is still considering itself a retail device. By erasing it, it will be forced to talk to the activation server again. This time, it will be told that it is an enterprise device linked to your organization. And the details of ABM will direct it to your MDM where it will hit your prestage and begin automated enrollment.


5: During this reboot, you will be asked to choose a language, a country, if accessibility is needed, and then to join a network. Once you do, the unit will hit the activation server and you should be presented with the automated enrollment window. Enroll the device.


Hope this is helpful. In the future, make sure you are buying devices from a DEP capable reseller. Give them your org ID (found in ABM) and have them give your their reseller ID (enter the in your ABM). This way, future devices will arrive already in ABM and already assigned to the MDM. No more Configurator. You are making your life way too complicated.


Added MDM Server, but only option is "Erase iPhone"

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.