IntuneTroubleshooting

Apple ADE devices missing in Intune or stuck without an enrollment policy

Why Apple ADE devices don't appear in Intune or enroll without the right policy: device assignment, token sync limits and renewal, default policies, and why a reset is needed.

You bought iPhones or iPads through Apple Business or Apple School Manager, but they never show up under your enrollment program token in Intune, or they power on and skip remote management entirely. In this post I'll walk through the chain that connects Apple to Intune, show where it usually breaks, and finish with what a healthy device looks like.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (7 steps: Check the assignment in Apple Business; Check the token status; Renew the token the right way; Sync once, then wait; Assign a policy and set a default; and 2 more). 4. Verify the fix. 5. Prevent it next time. Toolbox: Device onboarding › Enrollment, Devices › Sync, enrollmentProfileName, isSupervised, Devices › All devices.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttime1Check theassignment in…2Check thetoken status3Renew thetoken the righ…4Sync once,then wait5Assign a policyand set a def…+2 moreTOOLBOXDevice onboarding › EnrollmentDevices › SyncenrollmentProfileNameisSupervisedDevices › All devicesHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (7 steps: Check the assignment in Apple Business; Check the token status; Renew the token the right way; Sync once, then wait; Assign a policy and set a default; and 2 more). 4. Verify the fix. 5. Prevent it next time. Toolbox: Device onboarding › Enrollment, Devices › Sync, enrollmentProfileName, isSupervised, Devices › All devices.1Symptoms2Why it happens3How to fix it1Check the assignment in Apple Business2Check the token status3Renew the token the right way4Sync once, then wait5Assign a policy and set a default+2 more4Verify the fix5Prevent it next timeTOOLBOXDevice onboarding › EnrollmentDevices › SyncenrollmentProfileNameisSupervisedDevices › All devices
At a glance: how this guide is organised · 7 fix steps · 5 key tools

Symptoms#

  • The serial number is visible in Apple Business but not in the token's Devices list in Intune.
  • The device is listed in Intune but has no enrollment policy, so enrollment fails when someone activates it.
  • The token shows an error: expired or invalid token, access denied, or terms and conditions not accepted.
  • Devices enroll with old settings after you edited the policy, or sit on Awaiting final configuration for a long time.

Why it happens#

Automated Device Enrollment (ADE) is a chain, and every link has to be intact:

  1. In Apple Business (Apple's 2026 successor to Apple Business Manager) or Apple School Manager, the device is assigned to a device management service, also called an MDM server.
  2. That service's token (.p7m file) is uploaded to Intune and still valid.
  3. Intune syncs the serial numbers and each device gets an enrollment policy. Intune now creates these as enrollment policies; profiles made in the older Profiles experience still work, but that experience is being retired.
  4. The device downloads that policy during Setup Assistant, which only runs on a new or erased device.

Timing matters too, because Intune limits how often it talks to Apple:

Sync typeLimit
Automatic delta syncEvery 12 hours
Manual Sync buttonOnce every 15 minutes; each request gets 15 minutes to finish
Full syncNo more than once every seven days

How to fix it#

1. Check the assignment in Apple Business#

Search for the serial number in Apple Business or Apple School Manager and check which management service it's assigned to. If it's unassigned, or still points at an old MDM server or another vendor, assign it to the service linked to your Intune token. If you have several tokens, make sure you're checking the matching one in Intune.

2. Check the token status#

In the Microsoft Intune admin center, go to Devices › Device onboarding › Enrollment, select the Apple mobile tab (simply Apple in some tenants) and open Enrollment program tokens. Check the status and the expiry date.

Token errorLikely causeFix
Expired or invalid tokenToken expired, revoked or malformedRenew it (step 3)
Access deniedIntune was removed from the MDM server list in Apple, or the token expiredConfirm the service still exists in Apple and whether a newer token was downloaded, then renew
Terms and conditions not acceptedApple published new termsAn Apple Business administrator signs in and accepts them

3. Renew the token the right way#

Renew every year, and also when the password changes for the Apple account that created the token or when that person leaves.

  1. Sign in to Apple Business with an account that has the Administrator or Device Enrollment Manager role.
  2. Open the management service that belongs to the token and choose Download Token (in Apple Business it sits under the … menu).
  3. In Intune, select the token, choose Renew token, enter the Apple ID that created the original token, upload the new file and finish the wizard.

Watch out: downloading a token in Apple invalidates the one Intune is using right now. Only select Download Token when you're ready to complete the renewal straight away.

4. Sync once, then wait#

Select the token, then Devices › Sync. Clicking repeatedly won't speed anything up. Also remember that a device you delete from Intune while it's still assigned in Apple comes back on the next full sync, and a device released from Apple can take up to 45 days to disappear from Intune.

5. Assign a policy and set a default#

In the token's Devices list, select the devices and choose Assign policy. Then use Set Default Policy on the token, so devices that sync from Apple later aren't left without one. A device that's switched on without a policy fails enrollment.

Two more checks that catch people out:

  • If the default All users device platform restriction blocks iOS/iPadOS, ADE fails and the device shows an invalid profile. Block personally owned devices instead of the whole platform.
  • If a device has a policy but enrollment still doesn't start, make a small edit to the policy (this updates its modification time), sync the token, then power on the device.

6. Reset the device so it reads the policy#

The enrollment policy is only read during Setup Assistant. An activated device won't see a new or changed policy until it's erased; the device name template is the only setting that updates without a reset. Either Wipe it from Intune, or Retire it and erase it from Settings or Apple Configurator, then run Setup Assistant again.

7. Understand Awaiting final configuration#

With Await final configuration set to Yes (the default for new policies; it needs iOS/iPadOS 13 or later), Setup Assistant pauses just before the home screen while Intune installs device configuration policies. Apps aren't part of this wait. There's no fixed time limit, although Microsoft reports most test devices were released within about 15 minutes. If devices sit there far longer, check Apple's service status and, for older profiles that install Company Portal through VPP, make sure the VPP token isn't expired or out of licences.

Verify the fix#

  • The serial number appears in the token's Devices list and the Profile status column shows a policy assigned. Filter that column on Blocked to find devices that still need attention.
  • During Setup Assistant, the Remote Management screen names your organisation.
  • After enrollment, the device appears under Devices › All devices, and its enrollment profile name matches your policy. In Graph, check enrollmentProfileName and, if your policy supervises devices, isSupervised.

Prevent it next time#

  • Create tokens with a shared organisational Managed Apple Account, not a personal one, and document which account it is.
  • Add a team reminder a month before the enrollment token and the Apple MDM push certificate expire.
  • Set a default policy on every token, and unassign devices in Apple before deleting them from Intune.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)