iOS devices showing as registered (inactive): re-enroll via Apple Business Manager
iOS
When an iOS device loses its MDM profile, it appears as Registered (Inactive) in the Esper Console and becomes unresponsive to management actions, group assignments, and Blueprint application.
Why this happens
iOS devices enroll through Apple's Device Enrollment Program (DEP) during initial setup. If the device is erased outside of a managed workflow, restored from a personal backup, or the MDM profile is manually removed, the enrollment link breaks. The Esper Console retains the original device record but can no longer communicate with the device, leaving it in an inactive state.
Before you begin
Confirm the MDM profile is actually missing before proceeding. On the affected device, go to Settings → General → VPN & Device Management and look for an Esper profile entry.
- If the profile is absent, continue with the steps below.
- If the profile is present but the device still shows as inactive in the Esper Console, do not proceed with a factory reset. Instead, collect the device serial number and a screenshot of its Console status, then contact Esper Support.
Also confirm that Activation Lock is disabled on the device before proceeding. If Activation Lock is enabled, you will need the original Apple ID credentials to complete setup after the reset.
Steps
-
Remove and re-adopt the device in Apple Business Manager.
Log in to Apple Business Manager (ABM) and locate the affected device by serial number. Remove the device from ABM, then re-adopt it and assign it to the Esper MDM server. This step re-establishes the DEP assignment that triggers automatic MDM enrollment during device setup. -
Factory reset the device.
On the device, go to Settings → General → Transfer or Reset → Erase All Content and Settings and follow the on-screen prompts. A factory reset is required to re-trigger the DEP enrollment flow — re-assigning the MDM server in ABM alone will not push the MDM profile to a device that has already completed initial setup. -
Complete the out-of-box setup.
Power on the device and work through the initial setup screens. The device will detect its ABM assignment and automatically initiate MDM enrollment. Complete the setup process; the Esper MDM profile is pushed automatically without any manual intervention. -
Confirm the device appears as active in the Esper Console.
In the Esper Console, go to Devices & Groups and locate the device. Wait for it to appear with an active (online) status. This confirms the MDM profile was received and the device is communicating with Esper. -
Assign the device to the appropriate group.
In Devices & Groups, select the re-enrolled device and use Move to Group to assign it. Re-enrollment creates a new device record, so group membership from the previous record is not carried over automatically. -
Remove the stale device record.
In Devices & Groups, locate the original inactive device entry and delete it. Leaving duplicate records in your tenant causes confusion in reporting and device counts.
Verify: The re-enrolled device should appear with an active (online) status in Devices & Groups within a few minutes of completing setup. Management actions — including Blueprint application, remote commands, and group assignment — should all be available and responsive. If the device shows active but management actions are unresponsive, wait up to 10 minutes for the initial sync to complete.
If this doesn't resolve it
Check the following before contacting support:
- Re-adoption in ABM fails: Verify Activation Lock is disabled and confirm the device is not already assigned to a different MDM server in ABM.
- Device re-enrolls but drops back to inactive immediately: Check for conflicting MDM profiles under Settings → General → VPN & Device Management and remove any non-Esper profiles.
- Multiple devices showing this state at once: Note your tenant name, the affected device serial numbers, and the approximate time the devices went inactive. This pattern may indicate a platform-level sync issue.
If none of the above resolves the issue, contact Esper Support and include the device serial numbers, your tenant name, and a screenshot of the inactive device entries in the Esper Console.
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments