iOS devices showing as offline in Esper Console with commands stuck in "Queued" state: investigate DEP token validity and re-sync
iOS
When a DEP token expires or becomes invalid, all enrolled iOS devices appear offline in the Esper Console and every command — including pings, app deployments, and profile pushes — stays stuck in Queued state indefinitely.
Why this happens
Esper communicates with iOS devices through Apple's Mobile Device Management framework, which requires a valid DEP token to maintain the MDM server association. When that token expires or loses its link to your Apple Business Manager (ABM) or Apple School Manager (ASM) organization, the Esper Console loses its authority to send commands — even though device metadata cached before the token lapsed may still appear. This is distinct from an APNs certificate issue; renewing your APNs certificate alone will not resolve a DEP token problem.
Before you begin
This issue typically affects all enrolled iOS devices simultaneously. A single offline device is more likely a network or hardware problem. Confirm the scope before proceeding.
- Confirm the devices have internet access. Ask a user to open a browser or load any page on one of the affected devices. This rules out a site-wide network outage as the cause before making any changes in the Esper Console.
- Check your DEP token status. In the Esper Console, go to Settings → Apple MDM Management → DEP Token. Note the token expiry date, the associated ABM or ASM organization name, and any warning banners. A token that is expired, revoked, or associated with a different organization will prevent all command delivery.
-
Download a fresh DEP token from ABM or ASM. Log in to business.apple.com or school.apple.com, navigate to your MDM server entry for Esper, and download a new
.p7mtoken file. The token must come from the same ABM or ASM organization that originally enrolled your devices. - Remove the existing DEP token in the Esper Console. Go to Settings → Apple MDM Management and remove the current token. Removing the old token before uploading the new one prevents a duplicate-association conflict that can cause re-sync to fail silently.
-
Upload the new DEP token. On the same Settings → Apple MDM Management page, upload the
.p7mfile downloaded in step 3. - Trigger a re-sync. Click Re-sync to force the Esper Console to re-establish the MDM server association with Apple. Wait 5–10 minutes before checking device status.
Queued to Completed within two minutes, and the device's Last Seen timestamp should update to the current time.
If this doesn't resolve it
If devices remain offline and commands stay in Queued state after re-uploading and re-syncing the DEP token, contact Esper Support with the following information:
- Your tenant ID and enterprise name
- Number of affected devices and their UDIDs
- Exact timestamp when devices last checked in (visible in Devices & Groups → [Device Name] → Activity Feed)
- Screenshot of Settings → Apple MDM Management → DEP Token showing current token status
- Screenshot of a stuck command in
Queuedstate from an affected device - Confirmation of whether your APNs certificate is valid and its expiry date
Still need help?
If the DEP token validity check and re-sync steps don't resolve your offline iOS devices and queued commands, please submit a support ticket and include your DEP token expiration date, the specific device serial numbers showing as offline, and the timestamps of stuck commands.
Please sign in to leave a comment.
Comments
0 comments