Skip to main content
Move Macs from your previous Mobile Device Management (MDM) solution to Primo by reassigning them in Apple Business. The migration never requires a device wipe: employees keep their data, apps, and session. This article covers organization-owned Macs registered in Apple Business. If your Macs are not in Apple Business, choose another approach in enrollment methods. iPhone and iPad follow a different migration process not covered here.

Prerequisites

  • The Mac is organization-owned and registered in Apple Business — purchased from Apple or a reseller linked to your organization, or added with Apple Configurator
  • The Mac is enrolled with your previous MDM through Automated Device Enrollment (ADE)
  • macOS 11 or later
  • Administrator access to Apple Business, with a role allowed to set migration deadlines
  • Primo already connected to Apple Business (set this up first)
  • If you deploy apps purchased in volume: your Volume Purchase Program (VPP) token transferred to Primo before you start, following the migration order in App Store apps
Macs added with Apple Configurator can only migrate after their 30-day provisional enrollment period. On macOS 26, Macs that left Automated Device Enrollment and re-enrolled through profile-based enrollment can still migrate.

Reassign the Macs in Apple Business

1

Sign in to Apple Business

Go to business.apple.com and sign in.
2

Select the Macs to migrate

Go to Devices, then select the Mac(s) you want to reassign.
3

Reassign to Primo

Click Edit MDM Server, select your Primo MDM server as the destination, and confirm the assignment.
4

Set the migration deadline

Apple Business asks for a deadline to complete enrollment. Employees can postpone the migration until then. Keep the deadline within 30 days if you deploy apps purchased in volume.
Reassigning a Mac does not start the migration on its own. Without a deadline, the Mac never receives a migration prompt — and nothing reports the failure, in Apple Business, in the dashboard, or on the device. Set the deadline in the same session as the reassignment.
This deadline is set in Apple Business and applies to the migration only. It is unrelated to the OS update deadline you configure in the dashboard, which enforces a minimum macOS version.
What happens next depends on the macOS version. Apple numbers macOS by year, so macOS 26 (Tahoe) directly follows macOS 15 (Sequoia) — there are no versions 16 through 25.
If your previous MDM delivers the Wi-Fi configuration through a profile, the Mac loses that profile the moment it unenrolls — whether it unenrolls itself on macOS 26 or you remove the profile on earlier versions. Without network access it cannot reach Primo to complete enrollment. Confirm affected Macs can join a network another way (Ethernet, or a manually configured Wi-Fi network) before you start.

Migrate on macOS 26 and later

macOS 26 supports Apple’s native MDM migration. Do not unenroll the Macs from your previous MDM — each Mac unenrolls itself during the migration.
  1. Apple notifies the Mac that a migration is pending.
  2. The employee sees a migration prompt with the deadline you set. They can start the migration immediately or postpone it.
  3. Notifications repeat daily, then hourly during the last 24 hours, then at 60, 30, 10, and 1 minute before the deadline.
  4. At the deadline, the Mac shows a full-screen prompt the employee cannot dismiss. The Mac then unenrolls from the previous MDM and re-enrolls with Primo.
The Mac is never wiped — whether the employee starts the migration or the deadline enforces it.
The unenrollment signal sent to your previous MDM is best-effort. After the migration completes, delete any device records that remain in the previous console manually.

Migrate on macOS 15 and earlier

Apple’s native migration is not available before macOS 26. The migration relies on enrollment enforcement instead: a Mac assigned to Primo in Apple Business and no longer enrolled with an MDM prompts the employee to enroll.
1

Reassign the Macs in Apple Business

Follow the steps above.
2

Unenroll the Macs from your previous MDM

Remove the management profile from the previous MDM console. Deleting the device record is not enough — the profile must be removed from the Mac itself. Employees cannot do this: on a supervised Mac the profile is not user-removable.
3

Trigger the enrollment prompt

The Mac re-checks its Apple Business assignment periodically — up to 24 hours, or at the next restart or network change. To trigger it immediately, run this command on the Mac with administrator rights:
4

The employee accepts the prompt

The Mac shows a Remote Management notification asking the employee to enroll. This is a one-time approval — no wipe, no data loss.

Review what changes on the Mac

  • Data and session — untouched. Local accounts, files, and settings remain.
  • Apps — remain installed. Apps managed by the previous MDM become unmanaged; Primo redeploys apps according to your policies.
  • Apps purchased in volume — may be temporarily removed from devices while the VPP link switches over, then redeploy automatically once the new link is active.
  • Configuration profiles — the migration removes all profiles from the previous MDM. Primo applies its own profiles after enrollment.
  • FileVault — the disk stays encrypted throughout. The recovery key escrowed by your previous MDM becomes unavailable once that service is decommissioned. Primo escrows a new recovery key after enrollment, not during it.
  • Activation Lock — the migration removes the previous service’s Activation Lock, and its bypass codes become invalid. Primo retrieves the new bypass code on a recurring check, which can take up to a week.
Employees regain use of the Mac as soon as enrollment completes — before the FileVault recovery key, bootstrap token, and Activation Lock bypass code are escrowed. Until those land, you have no recovery key and no bypass code for that Mac. Always run the verification below.

Verify the migration

1

Check the Mac appears in Devices

The device record shows the Mac as enrolled and supervised.
2

Confirm the enrollment state on the Mac

On the device, open System Settings > General > VPN & Device Management. The previous MDM profile should be gone, and a Primo management profile present. To check from the command line instead:
3

Confirm profiles and apps are applied

Expected configuration profiles and app deployments appear on the device record.
4

Confirm the FileVault recovery key is escrowed

If no key appears, ask the employee to restart the Mac and wait for the next sync — the key cannot be escrowed until the bootstrap token is in place.
5

Check the iCloud Lock status

Confirm a bypass code is escrowed. See Activation Lock bypass code escrow.

Troubleshooting

Apple Business does not offer a migration deadline for a Mac
  • The Mac does not meet the migration requirements. Bulk actions fail for it — check the Apple Business activity log for the failed action.
  • Confirm the Mac is enrolled through Automated Device Enrollment and is past the 30-day provisional period if it was added with Apple Configurator.
The Mac never shows a prompt
  • On macOS 26 and later, confirm a migration deadline is set in Apple Business. This is the most common cause: reassignment alone does not trigger the migration, and nothing reports the missing deadline.
  • Confirm the reassignment is saved in Apple Business and the Mac is online.
  • On macOS 15 and earlier, confirm you removed the previous management profile from the Mac, then run sudo profiles renew -type enrollment.
  • Check the enrollment state on the Mac itself to see whether the previous profile is actually gone.
The Mac has no network after unenrollment
  • The Mac displays the Wi-Fi network picker. The enrollment screen also offers a Choose a Wi-Fi network link.
You need to cancel a migration on macOS 26
  • Reassign the Mac back to the previous MDM server before the migration starts. The device withdraws its migration prompts.

What if the previous MDM is already decommissioned?

A Mac left on a decommissioned MDM is not lost. It keeps working and keeps all its data — it simply becomes unmanaged: the previous profiles stay in place until something removes them, and the employee notices nothing. To bring it under management on macOS 15 and earlier, you still need to remove the management profile, and you cannot do that without access to the previous console — the employee cannot remove it either. Two options:
  • Restore access to the previous MDM long enough to unenroll the Macs.
  • Erase and re-enroll each Mac through zero-touch deployment. This wipes the device — back up employee data first.
Before erasing, turn off Find My on the Mac, or confirm a valid Activation Lock bypass code is available. A decommissioned MDM cannot hand over its bypass code, and the migration invalidates it in any case. Erasing a Mac that still has Find My enabled brings it back Activation-Locked and unusable. If you cannot turn Find My off while the Mac still starts up, do not erase it. See Activation Lock bypass code escrow.
Retrieve any Activation Lock bypass codes you may need from the previous MDM before decommissioning it. The migration invalidates them, and they cannot be recovered afterwards.

Contact

If Macs remain unenrolled after the deadline, or a FileVault recovery key never appears, contact support@getprimo.com with:
  • The device serial numbers
  • The macOS version on each device
  • The name of your previous MDM solution
  • The migration deadline you set in Apple Business