Prerequisites
- The device is organization-owned and registered in Apple Business
- The device is enrolled with your previous MDM through Automated Device Enrollment (ADE)
- iOS or iPadOS 26 or later for a migration without erasing the device. For earlier versions, see the iOS and iPadOS 18 and earlier tab in Migrate the devices
- Administrator access to Apple Business, with a role allowed to set migration deadlines
- Primo already connected to Apple Business as an MDM server (set this up first)
- An active Apple Push Notification service (APNs) certificate in Primo (set it up)
Apple’s native migration is not available for Shared iPad.
Prepare the migration
Complete these steps before you reassign any device. The migration removes everything the previous MDM installed, and some of it cannot be recovered afterwards.1
Transfer your content token (VPP)
If you deploy apps purchased in volume, remove the content token from your
previous MDM, then connect it to Primo. Never keep the same token active in
both MDMs. Follow the migration order in
App Store apps,
Migrate from another MDM tab.
2
Recreate your configuration in Primo
The migration removes every configuration profile installed by the previous
MDM: Wi-Fi, restrictions, email accounts, and any other setting. Recreate
the ones you need in Primo before the migration, so they apply as soon as
each device enrolls.
3
Retrieve Activation Lock bypass codes
Export the Activation Lock bypass codes from your previous MDM. The
migration invalidates them, and they cannot be recovered once the previous
MDM is decommissioned. See
Activation Lock bypass code escrow.
4
Ask employees to back up their authenticator apps
See the warning in Review what changes on the device.
Reassign the devices in Apple Business
1
Sign in to Apple Business
Go to business.apple.com and sign in.
2
Select the devices to migrate
Go to Devices, then select the iPhones and iPads you want to reassign.
3
Reassign to Primo
Click Assign Device Management, select your Primo MDM server as the
destination, and confirm the assignment.
4
Set the migration deadline
Apple Business asks for a deadline to complete enrollment, between 1 and 90
days. Employees can postpone the migration until then. Keep the deadline
within 30 days if you deploy apps purchased in volume.
This deadline is set in Apple Business and applies to the migration only. It is
unrelated to the OS update deadline you configure in the cockpit, which
enforces a minimum OS version.
Migrate the devices
What happens next depends on the OS version. Apple numbers iOS and iPadOS by year, so version 26 directly follows version 18. There are no versions 19 through 25.- iOS and iPadOS 26 and later
- iOS and iPadOS 18 and earlier
iOS and iPadOS 26 support Apple’s native MDM migration.
Do not unenroll the devices from your previous MDM: each device
unenrolls itself during the migration.
- The device receives an Enrollment Required notification with the deadline you set.
- The employee can tap Start Enrollment to migrate right away, or Not Now to postpone it.
- Notifications repeat daily, then hourly during the last 24 hours.
- At the deadline, the migration is forced. The device unenrolls from the previous MDM, enrolls with Primo through Automated Device Enrollment, and restarts.
After the migration completes, delete any device records that remain in
the previous MDM console.
Review what changes on the device
- Apps — apps managed by the previous MDM are removed during the migration. Primo then reinstalls them according to your policies, without their local data.
- Cloud-synced apps — employees only need to sign in again. Their data comes back from the cloud.
- Configuration profiles — the migration removes all profiles from the previous MDM. Primo applies its own profiles after enrollment.
- Supervision — on iOS and iPadOS 26, the device stays supervised.
- Activation Lock — bypass codes from the previous MDM become invalid.
Verify the migration
1
Check the device appears in Devices
The device record shows the device as enrolled and supervised.
2
Confirm the enrollment state on the device
On the device, open Settings > General > VPN & Device Management. The
previous MDM profile should be gone, and a Primo management profile
present.
3
Confirm profiles and apps are applied
Expected configuration profiles and app deployments appear on the device
record.
Troubleshooting
The device never shows a migration prompt- Confirm a migration deadline is set in Apple Business. This is the most common cause: reassignment alone does not trigger the migration, and nothing reports the missing deadline.
- Confirm the device runs iOS or iPadOS 26 or later and is not a Shared iPad.
- Confirm the reassignment is saved in Apple Business and the device is online.
- Confirm the content token is removed from the previous MDM and connected to Primo. Some apps may need to be reassigned manually once the new token is active. See App Store apps.
Contact
If devices remain unenrolled after the deadline, contact support@getprimo.com with:- The device serial numbers
- The iOS or iPadOS version on each device
- The name of your previous MDM solution
- The migration deadline you set in Apple Business