
Plan your device management migration
A device management service is an essential component to remotely manage and secure Apple devices. Organization-owned devices can automatically enroll in a device management service as part of the Setup Assistant process after unboxing the device, powering it on, and connecting it to a network.
After a device is enrolled, you may have a need to reenroll devices in a device management service for many reasons, such as:
Moving from an on-premises to a cloud-based device management service.
Moving devices into a single device management service when acquiring another company.
Migrating from one device management service to one from a different developer.
Apple School Manager and Apple Business make it easy to migrate a device from one device management service to another while keeping the user data in place.
Migration stages
Follow the steps below to prepare your environment for a seamless migration:
Document the current device management service environment and its dependencies
Plan your migration process
Sett up the new device management service and configuring it to work with Apple services
Recreate the enrollment profile and all configuration profiles and payloads
Test the migration
Perform the migration
Document the environment
Before initiating the migration, ensure you have a full picture of your current service and integration points. For example, this can involve documenting architecture decisions and requirements and integrations into:
Identity providers (IdPs) and PKI services
Network infrastructures
App distribution pipelines
Access management systems
Performance and security monitoring solutions
Asset management services
Apple services, such as Apple Push Notification service (APNs) and Apple School Manager or Apple Business.
Gather the necessary information and access to ingrate your new device management service with these services. Be sure to collect this information before you migrate any devices.
Plan your migration process
Establish and verify a plan for the migration process. Depending on your organizational requirements, your plan may also involve other teams, such as:
Apple service management: A user with the proper permissions in Apple School Manager or Apple Business and access to the Apple Push Notification service (APNs).
Security: Certificates (including the APNs certificate) and identity configurations.
Network: Wi-Fi credentials, managing the organization’s firewall.
App dispersement: This may include in-house proprietary apps, managed apps, Custom Apps, unlisted apps, and Content Managers.
User support and documentation: Call centers, help desks, and documentation for the staff and end users.
Set up your new device management service
Perform the required steps to configure your new device management service including required integrations.
This includes creating a new Apple Push Notification service (APNs) certificate and uploading it to your new device management service. Next, link your new service to Apple School Manager or Apple Business.
For more information, see Link to a third-party device management service in Apple School Manager or Link to a third-party device management service in Apple Business.
Recreate your enrollment and configuration profiles
You need to re-create your enrollment profile and configurations in your new device management service to provide continued service access and a seamless user experience.
Ensure that the new device management service applies configurations that match those of the previous device management service and use the await configuration state for managed apps, Wi-Fi, FileVault, and Activation Lock configurations.
For more information, consult your developer’s device management service documentation.
Test the migration
Verify your migration, associated operational processes, and the end user experience with the device types in scope according to your organizational requirements.
Perform the migration
Perform the actual migration and support the process with appropriate user communication and reporting. Depending on the size of your organization, you may also want to run the migration in batches.
The Admin API available in Apple School Manager and Apple Business offers a programmatic way to migrate devices in bulk and can also significantly simplify migrating devices in batches. It can be used to:
Assign devices to a device management service
Unassigned devices from a device management service
Set the migration deadline
Update the migration deadline
Cancel a device migration
For more information on the Apple School Manager and Apple Business APIs, see Apple School Manager and Apple Business APIs in Apple Developer documentation.