Skip to main content

Restoring MDM Communication in Jamf School Without Wiping

Description

This process involves creating a new Device Management Service in Apple School Manager, linking it to a new Automated Device Enrollment (ADE) entry in Jamf School, reassigning devices to the new service, and allowing devices to re-enroll automatically.

Requirements

Devices must meet all of the following criteria to be eligible:

  • Devices must be running iOS 26, iPadOS 26, or macOS 26 or later.

  • If a device was enrolled manually using Apple Configurator, the 30-day provisional period must have passed before migration is possible.

  • Devices enrolled using Automated Device Enrollment with is_return_to_service=true are not eligible.

  • Device management service migration is not available on Shared iPad.

This workflow can be used in scenarios where managed devices may lose communication with Jamf School, for example, an APNs mismatch. Historically, restoring communication required wiping the affected iOS/iPadOS device.

With Apple's MDM migration functionality, this can now be resolved without a wipe, provided the device meets the requirements above.


Restoring your MDM Communication

Step 1: Create Device Management Service in ASM and ADE Entry in Jamf School

  1. In Jamf School, navigate to Organization > Settings > Automated Device Enrollment.

  2. Click the plus sign to open the dialog for adding a new token, then click Download Public Key to download the key. Do not open the downloaded .pem file, keep it accessible for the next steps.

  3. Log in to Apple School Manager.

    • Click your username in the lower-left corner and choose Preferences.

    • Ensure that the resulting page has a "Your MDM Servers" section.

      1. If this section is missing, confirm that the Apple Account used to log in has the appropriate permissions in Apple School Manager.

      2. Select Add under Device Management Services to create a new Device Management Service.

  4. Give the Device Management Service a unique name.

  5. Under MDM Server Settings, either drag and drop the Public Key or click Upload Certificate to select the file from your computer.

  6. Click Save.

  7. Click Download Token at the top of the page.

  8. Back in Jamf School, upload the server token and click Apply.

Step 2: Associate the New ADE Token in Jamf School

  1. Create a new Enrollment Profile in Profiles > Automated Device Enrollment Profiles.

  2. Once saved, edit the profile and make it the default profile for devices in the new token. Navigate to the General tab > Default Profile section near the bottom of the profile. Once the Default Profile option is selected, choose the new token created in Step 1.

Step 3: Reassign Devices to the New Device Management Service in ASM

  1. In Jamf School, go to Devices > Inventory.

  2. (Optional) Click Filter to narrow the device list to the devices you want to migrate.

  3. Click Export.

  4. Select Serial Number, OS Version, and Device Name, then click Export.

  5. The export becomes a task. Once the task is complete, download the CSV file from Jamf School under Organization > Task Manager using the Download button for the device.

  6. Open the CSV file in Microsoft Excel and copy the serial numbers.

  7. Log in to Apple School Manager.

    • Navigate to Devices and paste the serial numbers into the search bar.

    • Click All Devices

    • Click Assign Device Management.

  8. From the dropdown, select the Device Management Service created in Step 1.

  9. Click + Add Deadline and specify the latest date and time by which devices must switch over to the new Device Management Service.

    Note: If Add Deadline is greyed out, you either have devices that don't meet the requirements or it might be necessary to reach out to Apple School support to resolve.

  10. Click Continue.

  11. Press Confirm when prompted to change the device management service.

  12. After confirming, Apple School Manager displays a status page.

Step 4: End User Experience

  1. Once devices are reassigned, end users receive a notification prompting them to enroll in the new Device Management Service. The notification location depends on device type:

    • Mobile devices: (iPhone/iPad): the notification appears on the device screen.

    • Mac computers: the notification appears in the upper-right corner of the desktop.

      Note: The notification can be dismissed up until the deadline. Notifications display daily, then hourly in the 24 hours before the deadline. In the final hour before the deadline, notifications appear at 60, 30, 10, and 1-minute intervals.​

  2. If the user taps or clicks the notification, they are taken to System Settings with the option to Start Enrollment.

  3. If the user proceeds manually or the deadline is reached, a full-screen prompt appears requiring the user to enroll.

    Note: The Not Now option is greyed out once the deadline has passed.

  4. After selecting Enroll, the user is prompted to enter their device password. Admin credentials are not required. A Standard Account can complete this process.

  5. The device re-enrolls into the Jamf School instance and APNs communication is restored.

Did this answer your question?