
Use Return to Service for Apple devices
Return to Service makes the process of resetting and reenrolling iPhone, iPad, Apple TV, and Apple Vision Pro fully automated. It allows you to prepare a device for the next user without manual setup. After securely erasing user data from the device, it automatically enrolls in a device management service and configures itself with the appropriate settings, making it ready for the next user quickly and securely.
Initiate Return to Service
On iPhone, iPad, Apple TV, and Apple Vision Pro, Return to Service is initiated by sending an erase command to a managed device enrolled using Device Enrollment or Automated Device Enrollment. The command can provide the Wi-Fi details and define which device management service to enroll in.
The Wi-Fi profile is required to activate the device, unless it has other means of connecting to the internet (such as a tethered connection).
If the device is registered in Apple School Manager or Apple Business, you can omit the device management service configuration as the device checks for an enrollment profile during activation. You can specify the enrollment profile in the erase command in situations where Automated Device Enrollment might otherwise require user interaction, for example to authenticate the enrollment.
Using the provided information, the device erases all data and automatically proceeds to the Home Screen, ready to be used. As part of this process, the previously selected language and region are applied. On iPhone and iPad devices with iOS 27 and iPadOS 27, you can alternatively set the language and region in the Automated Device Enrollment profile. You can also specify whether an existing eSIM is preserved during a reset. Supervision status manually set by Apple Configurator is also retained.
If the enrollment after a reset fails, for example, due to a transient network issue or when encountering device management service errors, iPhone and iPad devices with iOS 27 and iPadOS 27 can be configured to retry with an increasing time delay (up to five minutes).
On Apple Vision Pro, Return to Service is also available for the user to initiate from the Lock Screen or the Control Center. You can also set a timeout to automatically initiate Return to Service after a set period of inactivity (in seconds). In either case, Apple Vision Pro checks in with the device management system to ask for Return to Service to be initiated using the erase command.
Preserve apps with Return to Service
On devices with iOS 26, iPadOS 26, and visionOS 26, or later that are using Automated Device Enrollment, Return to Service can also preserve managed apps. It securely erases user data, including locally stored user-generated app data, but app binaries remain to make the process even faster.
This process has two phases:
Setup: Set up the device for Return to Service with app preservation.
Reset: Reset the device configured for Return to Service with app preservation.
Set up the device for Return to Service with app preservation
To use Return to Service with app preservation, you need to follow the following process:
Join the device to a Wi-Fi network.
Upon activation, the device receives a management configuration specifying the following:
Setup Assistant panes to skip during the initial setup.
Enable Return to Service.
Make sure the iPad isn’t configured as Shared iPad.
If necessary, you can enforce a software update as part of the enrollment.
The device enrolls in the device management service.
The device creates a bootstrap token and sends it to the device management service (similar to macOS). The bootstrap token in iOS, iPadOS, and visionOS is required to authenticate subsequent Return to Service operations.
The operating system configures the device and installs managed apps that are preserved during Return to Service.
The device management service releases the device from the Remote Management Setup Assistant pane.
A file system snapshot is taken.
Note: You can deliver declarations and profiles during the awaiting configuration state, but the operating system doesn’t preserve them. Also, apps deployed after the snapshot is taken aren’t preserved.
Reset a device configured for Return to Service with app preservation
Your device management service initiates Return to Service and includes the following:
The configuration required for Wi-Fi connectivity.
The escrowed bootstrap token.
If necessary, the enrollment profile for the device management service. If you don’t specify one, the device queries Apple School Manager or Apple Business.
Additional options for iOS 27 and iPadOS 27
Users can either initiate Return to Service from the Control Center or you can set a timeout to automatically initiate Return to Service after a set period of inactivity (in seconds).
After initiation, the device performs a check-in with the device management service to retrieve the necessary enrollment information. The information can also include the option to retry the enrollment if the initial attempt fails.
The reset process works like this:
The operating system securely erases the previous user’s data from the device.
The device restarts.
The device reverts to the file system snapshot.
The device joins the Wi-Fi network that Return to Service specifies.
If necessary, you can enforce a software update as part of the enrollment.
The device enrolls in the device management service.
The operating system installs managed apps and configurations. If the managed app was installed previously, the device preserves the app from the snapshot.
The device management service releases the device from the Remote Management Setup Assistant pane.
Manage software and app updates with Return to Service
Software updates on devices that are used with Return to Service (which don’t have app preservation enabled) can be initiated after enrollment using device management. For more information, see Deploy software updates using declarative management in Apple Developer documentation. Also, managed apps can be updated using device management. See Update managed apps.
If Return to Service with app preservation is active, the device disables software updates—both automatic and user-initiated—as well as app updates when the device reverts to its previous state during the snapshot restore.
On devices with iOS 27, iPadOS 27, and visionOS 27, the device management service can initiate a software update and deploy new app versions during the enrollment after a device reset. If configured, the device applies the software update and then restarts to initiate the enrollment flow again. On devices configured for Return to Service with app preservation, the app versions deployed during the enrollment become part of the snapshot and are restored during a reset.
Instead, the device management service can start a software update and deploy new app versions during the enrollment after a device reset. If configured, the device applies the software update and then restarts to initiate the enrollment flow again. The app versions deployed during the enrollment become part of the snapshot and are restored during a reset.
Note: As software and app updates are applied only during a device reset to devices configured for Return to Service with app preservation, you need to define a suitable usage pattern that includes regular device resets. This allows a device to remain on a current operating system version.
Allow Apple Vision Pro to join Wi-Fi on restart
When a user finishes using an Apple Vision Pro, the device is often shutdown or disconnected from its power source. When the next user picks up the device, it powers on and remains locked to the previous user. In order for the new user to initiate the Return to Service flow from the Lock Screen, the device needs to be on a Wi-Fi network so it can send requests to the device management service.
To ensure Wi-Fi connectivity after a restart, the device management service can install a Wi-Fi configuration, and allow it to be used before the device is unlocked. This option is available only when using Return to Service with app preservation and allows the device to join that Wi-Fi network automatically after a restart.