Checklist
iOS/iPadOS & Apple ADE troubleshooting checklist
Based on the article: Apple ADE devices missing in Intune or stuck without an enrollment policy · 5 min read
You bought iPhones or iPads through Apple Business or Apple School Manager, but they never show up under your enrollment program token in Intune, or they power on and skip remote management entirely. In this post I'll walk through the chain that connects Apple to Intune, show where it usually breaks, and finish with what a healthy device looks like.
Symptoms to confirm
- The serial number is visible in Apple Business but not in the token's Devices list in Intune.
- The device is listed in Intune but has no enrollment policy, so enrollment fails when someone activates it.
- The token shows an error: expired or invalid token, access denied, or terms and conditions not accepted.
- Devices enroll with old settings after you edited the policy, or sit on Awaiting final configuration for a long time.
Likely causes
Automated Device Enrollment (ADE) is a chain, and every link has to be intact:
- In Apple Business (Apple's 2026 successor to Apple Business Manager) or Apple School Manager, the device is assigned to a device management service, also called an MDM server.
- That service's token (
.p7mfile) is uploaded to Intune and still valid. - Intune syncs the serial numbers and each device gets an enrollment policy. Intune now creates these as enrollment policies; profiles made in the older Profiles experience still work, but that experience is being retired.
- The device downloads that policy during Setup Assistant, which only runs on a new or erased device.
| Sync type | Limit |
|---|---|
| Automatic delta sync | Every 12 hours |
| Manual Sync button | Once every 15 minutes; each request gets 15 minutes to finish |
| Full sync | No more than once every seven days |
Checklist
- 1
Check the assignment in Apple Business
Search for the serial number in Apple Business or Apple School Manager and check which management service it's assigned to. If it's unassigned, or still points at an old MDM server or another vendor, assign it to the service linked to your Intune token.
- 2
Check the token status
In the Microsoft Intune admin center, go to Devices › Device onboarding › Enrollment, select the Apple mobile tab (simply Apple in some tenants) and open Enrollment program tokens. Check the status and the expiry date.
Token error Likely cause Fix Expired or invalid token Token expired, revoked or malformed Renew it (step 3) Access denied Intune was removed from the MDM server list in Apple, or the token expired Confirm the service still exists in Apple and whether a newer token was downloaded, then renew Terms and conditions not accepted Apple published new terms An Apple Business administrator signs in and accepts them - 3
Renew the token the right way
Renew every year, and also when the password changes for the Apple account that created the token or when that person leaves.
- Sign in to Apple Business with an account that has the Administrator or Device Enrollment Manager role.
- Open the management service that belongs to the token and choose Download Token (in Apple Business it sits under the … menu).
- In Intune, select the token, choose Renew token, enter the Apple ID that created the original token, upload the new file and finish the wizard.
Watch out: downloading a token in Apple invalidates the one Intune is using right now. Only select Download Token when you're ready to complete the renewal straight away.
- 4
Sync once, then wait
Select the token, then Devices › Sync. Clicking repeatedly won't speed anything up.
- 5
Assign a policy and set a default
In the token's Devices list, select the devices and choose Assign policy. Then use Set Default Policy on the token, so devices that sync from Apple later aren't left without one.
- If the default All users device platform restriction blocks iOS/iPadOS, ADE fails and the device shows an invalid profile. Block personally owned devices instead of the whole platform.
- If a device has a policy but enrollment still doesn't start, make a small edit to the policy (this updates its modification time), sync the token, then power on the device.
- 6
Reset the device so it reads the policy
The enrollment policy is only read during Setup Assistant. An activated device won't see a new or changed policy until it's erased; the device name template is the only setting that updates without a reset.
- 7
Understand Awaiting final configuration
With Await final configuration set to Yes (the default for new policies; it needs iOS/iPadOS 13 or later), Setup Assistant pauses just before the home screen while Intune installs device configuration policies. Apps aren't part of this wait.
Verify
- The serial number appears in the token's Devices list and the Profile status column shows a policy assigned. Filter that column on Blocked to find devices that still need attention.
- During Setup Assistant, the Remote Management screen names your organisation.
- After enrollment, the device appears under Devices › All devices, and its enrollment profile name matches your policy. In Graph, check
enrollmentProfileNameand, if your policy supervises devices,isSupervised.
Prevent it next time
- Create tokens with a shared organisational Managed Apple Account, not a personal one, and document which account it is.
- Add a team reminder a month before the enrollment token and the Apple MDM push certificate expire.
- Set a default policy on every token, and unassign devices in Apple before deleting them from Intune.