
Restore managed Apple devices
Overview
When you restore a managed Apple device, the restore process depends on the version of the operating system.
Restore a backup with account-driven enrollments
Restoring a device backup doesn’t restore the device management service enrollment profile. The user has to navigate to Settings > General > VPN & Device Management and select the Sign In to Work or School Account button to perform the enrollment after the restore.
In case a backup has been created with the same Managed Apple Account that was used to initiate the enrollment, a restore option is presented as part of the enrollment flow. If the backup contains managed app data, it’s restored unless the app is already installed on the device. In that case, the user is told which app data is being skipped during the restore.
Restore managed devices with iOS 27, iPadOS 27, and visionOS 27
When you restore a backup on a device with iOS 27, iPadOS 27, visionOS 27 that was enrolled with profile-based Device Enrollment and Automated Device Enrollment and appears in Apple School Manager or Apple Business, it automatically enrolls through Automated Device Enrollment. Otherwise, the device doesn’t enroll into management during the restore.
If a managed app isn’t marked for removal upon unenrollment, its data is restored from the backup. A device management service can take over management of this data by installing the corresponding managed app after the restore. If the backup contains in-house proprietary books, the device management service restores them as well.
Restore managed devices with iOS 26, iPadOS 26, and visionOS 26, or earlier
Restore backups with profile-based Device Enrollment and Automated Device Enrollment
You can restore a backup to either the same device or a different device. Depending on the level of management from a device management service, there are differences in what the backup restores. And, regardless of whether a backup is unencrypted or encrypted, after restoring a device, the user needs to create a passcode or password, and can optionally perform the steps to create biometric authentication.
For Automated Device Enrollments, you can set the do_not_use_profile_from_backup key in the management configuration which causes the device to ignore it during a restore and reach out to Apple School Manager or Apple Business instead. The resulting behavior is the same as a restore to a different device. This allows you to provide the same user experience for devices registered in Apple School Manager or Apple Business independent of the target device or change the management state during a restore.
Note: Declarations are never restored. Instead, the device syncs assigned declarations from the device management service and applies them as determined by the associated activation predicate. If a previously applied declaration isn’t assigned or not applied anymore, the device automatically removes associated configuration states and assets.
Restore a backup to the same device
If you restore a backup to the same device, the process restores the management configuration and a device management service enrollment profile. Using this information, the next time the device connects to the internet, it performs a check-in with the device management service, which then determines whether to accept the connection from the restored device.
Important: If the device identity certificate became invalid since the backup was created or the device management service doesn’t accept the connection from the restored device, the operating system removes the enrollment profile, associated configurations, and any apps marked for removal during unenrollment.
You can’t restore any profiles containing a hardware-bound key that you deploy using the Automated Certificate Management Environment protocol. If the device management service uses such an identity to authenticate a device, the operating system can’t restore the enrollment, so it removes it. For devices that appear in Apple School Manager or Apple Business, the device automatically starts enrollment using Automated Device Enrollment instead.
If the backup contains managed app data or enterprise books, this data is restored as well. If the managed app isn’t present on the device but the backup includes the managed app data, a placeholder may be shown for the app. App placeholders aren’t shown when restoring devices using Apple Configurator.
Restore a backup to a different device
If you restore a backup to a different device, the operating system automatically deletes the management configuration and device management service enrollment during the restore. For devices that appear in Apple School Manager or Apple Business, the device then reaches out to Apple School Manager or Apple Business to determine whether a device management service it has provided a management configuration. If available, it downloads the management configuration and applies it.
If the backup contains managed app data, the device management service restores that, unless there’s a configuration indicating that the device management service needs to remove the data upon unenrollment. If the backup contains enterprise books, the device management service restores them as well.