ABM sync failure caused by wrong MDM token or device count mismatch: upload correct Esper token and reconcile device count in ABM portal
iOS
iOS
If your ABM sync is failing, the issue is typically caused by either a device count mismatch between your Esper Console and Apple Business Manager (ABM) portal, or by uploading an incorrect MDM token. This article walks you through identifying and fixing both issues.
Before you begin
You'll need admin access to both your Esper Console and your Apple Business Manager portal at business.apple.com.
How to identify the problem
ABM sync failures usually stem from one of two issues:
- Device count mismatch: A device has been removed from your Esper Console but remains assigned to the Esper server in ABM. This causes the sync to fail when the two systems don't match.
- Wrong MDM token uploaded: The token you uploaded to Esper was issued by a different MDM vendor (such as a legacy system), not by Esper. This prevents Esper from authenticating with ABM.
You can verify the token issuer by checking the certificate details in your ABM token file. If it shows an organization other than Esper, you're using the wrong token.
Fix 1: Reconcile device count mismatch
- Log in to Apple Business Manager at business.apple.com.
- Go to Devices and filter by the Esper server assignment.
- In your Esper Console, open Devices & Groups to see which devices are registered in Esper.
- Compare the two lists. Any devices showing in ABM but not in your Esper Console need to be removed from ABM.
- In ABM, select each unregistered device and either unassign it from the Esper server or release it from MDM entirely.
- Return to your Esper Console and go to Device Enrollment → Apple Business Manager.
- Click Sync Now.
- Verify that the sync completes without error and the device counts now match.
Fix 2: Upload the correct Esper token
- Log in to your Esper Console and go to Device Enrollment → Apple Business Manager.
- Click the option to download your Esper-issued public key or token. This is the token that authorizes Esper as your MDM server.
- Log in to Apple Business Manager and go to Settings → MDM Servers.
- Find your Esper server entry and upload the Esper-issued token file you just downloaded to renew the trust relationship.
- Return to your Esper Console at Device Enrollment → Apple Business Manager.
- Download the renewed ABM token from the ABM portal and upload it into the Esper Console.
- Click Sync Now.
- Verify that the sync completes successfully. The token issuer should now show as Esper, not a third-party vendor.
If both issues are present
Complete Fix 1 (reconcile device count) first, then complete Fix 2 (upload the correct token), and perform a single sync at the end.
Troubleshoot if sync still fails
- Expired token: ABM tokens expire annually. Check your ABM portal to see if your token needs renewal.
- Devices in pending-release state: Some devices in ABM may still be pending release from a previous MDM. These count against your assignment total even though they're not active. Release them in ABM before syncing.
- Still seeing errors: Note the exact error message from the sync attempt. This will help Esper Support investigate further.
Still need help?
If ABM sync continues to fail after following these steps, contact Esper Support. Provide your exact error message and confirm that device counts match and your token issuer shows as Esper.
Please sign in to leave a comment.
Comments
0 comments