ABM sync fails — fix device count mismatch or wrong MDM token
iOS
When an Apple Business Manager (ABM) sync fails in the Esper Console, the sync either errors out immediately or completes but shows a device count that does not match what ABM reports.
Why this happens
ABM sync fails for one of two reasons: a device has been removed from the Esper Console but is still assigned to the Esper MDM server in ABM, causing the two systems to disagree on device count; or the token uploaded to the Esper Console was issued by a different MDM vendor rather than by Esper, so ABM rejects the authentication attempt. Both issues can be present at the same time.
Before you begin
Confirm you have admin access to both the Esper Console and Apple Business Manager at business.apple.com. You will need to act in both portals during these steps.
Fix 1: Reconcile a device count mismatch
- Log in to business.apple.com, go to Devices, and filter the list by your Esper MDM server assignment. Note which devices ABM considers assigned to Esper.
- In the Esper Console, open Devices & Groups and note which devices are registered there. This gives you the list Esper expects to see.
- Compare the two lists. Any device that appears in ABM but not in the Esper Console is causing the count mismatch and must be resolved in ABM.
- In ABM, select each unmatched device and either unassign it from the Esper MDM server or release it from MDM entirely. Devices in a pending-release state from a previous MDM also count against your assignment total — release those as well before continuing.
- Return to the Esper Console and navigate to Device Enrollment → Apple Business Manager.
- Click Sync Now.
Verify: The sync should complete without an error and the device count shown in the Esper Console should match the count displayed in ABM within a few minutes of the sync completing.
Fix 2: Replace a wrong or mismatched MDM token
You can confirm you have the wrong token before starting: open your ABM token file and check the certificate issuer field. If it shows an organization other than Esper, the token was issued by a different MDM vendor and must be replaced.
- In the Esper Console, navigate to Device Enrollment → Apple Business Manager and download the Esper-issued public key. This key authorizes Esper as your MDM server in ABM.
- Log in to business.apple.com, go to Settings → MDM Servers, and locate your Esper server entry.
- Upload the Esper-issued public key you just downloaded. This renews the trust relationship between ABM and Esper.
- Still in ABM, download the updated ABM token that ABM generates after the key upload.
- Return to the Esper Console at Device Enrollment → Apple Business Manager and upload the updated ABM token you just downloaded from ABM.
- Click Sync Now.
Verify: The sync should complete successfully. The token issuer displayed in the Esper Console should now show Esper, not a third-party vendor name.
If both issues are present
Complete Fix 1 in full first to reconcile the device count, then complete Fix 2 to replace the token. Run a single Sync Now at the end of Fix 2 — there is no need to sync between the two fixes.
Additional things to check if sync still fails
- Expired token: ABM tokens expire annually. Log in to business.apple.com → Settings → MDM Servers and check the expiry date on your Esper server entry. If it has expired, repeat Fix 2 to generate and upload a fresh token.
- Pending-release devices: Devices not yet fully released from a previous MDM still count toward your ABM assignment total even though they are not active in Esper. Release them in ABM before retrying the sync.
If this doesn't resolve it
If the sync continues to fail after completing both fixes, collect the following before contacting Esper Support:
- The exact error message displayed in the Esper Console after the failed sync attempt
- A screenshot of the device count shown in both the Esper Console (Device Enrollment → Apple Business Manager) and in ABM (Devices, filtered by your Esper server)
- The token issuer name shown in the Esper Console
- The expiry date of the current token as shown in ABM
Contact Esper Support with this information so the issue can be investigated further.
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments