
Migrate managed devices to another device management service
Apple School Manager and Apple Business support migrating devices to a new third-party device management service with the following features:
In Apple School Manager, a user with the role of Administrator, Site Manager, and Device Enrollment Manager can set a deadline for completing enrollment, and view the pending migrations notification on the device page.
In Apple Business, a user whose role has permissions to view, add, and delete device management services can set a deadline for completing enrollment, and view the pending migrations notification on the device page.
If the user doesn’t take action, the organization can enforce migration and reenrollment. This involves a restart on an iPhone or iPad, and a nondismissible full-screen prompt on a Mac.
iPhone and iPad devices have the option to preserve apps and their associated data if the new device management service delivers the apps before sending the
DeviceConfiguredcommand.Handling of Activation Lock, bootstrap tokens, and FileVault.
Requirements
To migrate from one device management service to another, your devices need to meet the following requirements:
Devices need to have iOS 26, iPadOS 26, or macOS 26, or later.
Enroll using Automated Device Enrollment.
Additionally, a Mac with macOS 26 or later supports migration that unenrolls from an Automated Device Enrollment and reenrolls with profile-based enrollment.
If the device is enrolled manually using Apple Configurator, it needs to be after the 30-day provisional period.
Devices aren’t migrated if configured for Return to Service with app preservation or set up as Shared iPad.
Note: If devices don’t meet the requirements, you’re unable to set the migration deadline option, and bulk actions result in failures (which appear in the activity log).
Migrating a device
To migrate a device to a new device management service you can do one of the following:
Assign one or more devices to the new service in Apple School Manager or Apple Business and set a migration deadline. For more information, see Migrate devices to a new management service in Apple Business and Migrate devices to a new management service in Apple School Manager.
Use the Apple School Manager and Apple Business APIs to programmatically assign devices and set or update the migration deadline. For more information on the Apple School Manager and Apple Business APIs, see Apple School Manager and Apple Business APIs in Apple Developer documentation.
Notifications
After setting the migration deadline, users receive notifications to confirm reenrollment, with more frequent notifications leading up to the deadline.
Notifications display daily, and hourly 24 hours before the deadline. For the last hour before the deadline, the user receives notifications at sixty-, thirty-, ten-, and one-minute intervals.
If the device has no internet connectivity after unenrollment, it displays the Wi-Fi picker for the user to manually connect to proceed. If an enrollment failure occurs due to a network issue, the enrollment screen displays a Choose Wi-Fi Network link above “Enroll this [iPhone][iPad]”.
Device management service migration and Activation Lock
As part of the migration, the existing Activation Lock gets removed and associated bypass codes invalidated. The new device management service can apply an organization-linked Activation Lock to iPhone, iPad, and Apple Vision Pro devices as part of the migration process.
If migration fails, Apple School Manager or Apple Business also remove any prior Activation Lock and invalidate bypass codes. Then Activation Lock is turned on and only the following can remove it:
Apple School Manager: Any user with the role of Administrator
Apple Business: Any user with the role of Organization Administrator
Mac migration considerations
On a Mac, all users receive a prompt and can start the migration. After the migration is complete, and depending on the new device management service:
The user who completes the migration is the managed user
The Mac may still not have any managed user
If a Mac has FileVault turned on, the new device management service can install a FileVault escrow configuration. This automatically rotates the Personal Recovery Key using a bootstrap token (which the new service needs to support).
Preserve managed apps
If you want your users to have the same set of managed apps after migration as they had before migration, you can preserve them during the process. This helps avoid data loss and allows for a quicker migration because the device doesn’t need to download previously installed managed apps.
Important: To support this process, make sure your device management service configured to not send remove app commands during unenrollment. Declarative managed apps are always preserved by the device.
Volume purchased apps
To properly prepare a migration that involves volume purchased apps:
Remove the content token from the current device management service.
Create a new content token for the same organizational unit and upload the content token to the correct device management service. For more information, see:
Apple School Manager User Guide: Manage content tokens in Apple School Manager
Apple Business User Guide: Manage content tokens in Apple Business
If you can’t access the current device management service, you can’t unassign the apps, so the apps remain assigned and users can use them until:
The app performs a receipt check.
The new device management service unassigns them.
Eventually, the content token expires, and the previous device management service loses access to the Apple Business location. Assignments still remain.
In-house proprietary apps
You don’t need to unassign apps that your organization creates. You can just download them again after enrolling the device in the new device management service.