Prerequisites
- The Mac is organization-owned and registered in Apple Business — purchased from Apple or a reseller linked to your organization, or added with Apple Configurator
- The Mac is enrolled with your previous MDM through Automated Device Enrollment (ADE)
- macOS 11 or later
- Administrator access to Apple Business, with a role allowed to set migration deadlines
- Primo already connected to Apple Business (set this up first)
- If you deploy apps purchased in volume: your Volume Purchase Program (VPP) token transferred to Primo before you start, following the migration order in App Store apps
Macs added with Apple Configurator can only migrate after their 30-day
provisional enrollment period. On macOS 26, Macs that left Automated Device
Enrollment and re-enrolled through profile-based enrollment can still migrate.
Reassign the Macs in Apple Business
1
Sign in to Apple Business
Go to business.apple.com and sign in.
2
Select the Macs to migrate
Go to Devices, then select the Mac(s) you want to reassign.
3
Reassign to Primo
Click Edit MDM Server, select your Primo MDM server as the destination,
and confirm the assignment.
4
Set the migration deadline
Apple Business asks for a deadline to complete enrollment. Employees can
postpone the migration until then. Keep the deadline within 30 days if you
deploy apps purchased in volume.
This deadline is set in Apple Business and applies to the migration only. It is
unrelated to the OS update deadline you configure in the dashboard, which
enforces a minimum macOS version.
Migrate on macOS 26 and later
macOS 26 supports Apple’s native MDM migration. Do not unenroll the Macs from your previous MDM — each Mac unenrolls itself during the migration.- Apple notifies the Mac that a migration is pending.
- The employee sees a migration prompt with the deadline you set. They can start the migration immediately or postpone it.
- Notifications repeat daily, then hourly during the last 24 hours, then at 60, 30, 10, and 1 minute before the deadline.
- At the deadline, the Mac shows a full-screen prompt the employee cannot dismiss. The Mac then unenrolls from the previous MDM and re-enrolls with Primo.
The unenrollment signal sent to your previous MDM is best-effort. After the
migration completes, delete any device records that remain in the previous
console manually.
Migrate on macOS 15 and earlier
Apple’s native migration is not available before macOS 26. The migration relies on enrollment enforcement instead: a Mac assigned to Primo in Apple Business and no longer enrolled with an MDM prompts the employee to enroll.1
Reassign the Macs in Apple Business
Follow the steps above.
2
Unenroll the Macs from your previous MDM
Remove the management profile from the previous MDM console. Deleting the
device record is not enough — the profile must be removed from the Mac
itself. Employees cannot do this: on a supervised Mac the profile is not
user-removable.
3
Trigger the enrollment prompt
The Mac re-checks its Apple Business assignment periodically — up to 24
hours, or at the next restart or network change. To trigger it immediately,
run this command on the Mac with administrator rights:
4
The employee accepts the prompt
The Mac shows a Remote Management notification asking the employee to enroll.
This is a one-time approval — no wipe, no data loss.
Review what changes on the Mac
- Data and session — untouched. Local accounts, files, and settings remain.
- Apps — remain installed. Apps managed by the previous MDM become unmanaged; Primo redeploys apps according to your policies.
- Apps purchased in volume — may be temporarily removed from devices while the VPP link switches over, then redeploy automatically once the new link is active.
- Configuration profiles — the migration removes all profiles from the previous MDM. Primo applies its own profiles after enrollment.
- FileVault — the disk stays encrypted throughout. The recovery key escrowed by your previous MDM becomes unavailable once that service is decommissioned. Primo escrows a new recovery key after enrollment, not during it.
- Activation Lock — the migration removes the previous service’s Activation Lock, and its bypass codes become invalid. Primo retrieves the new bypass code on a recurring check, which can take up to a week.
Employees regain use of the Mac as soon as enrollment completes — before the
FileVault recovery key, bootstrap token, and Activation Lock bypass code are
escrowed. Until those land, you have no recovery key and no bypass code for
that Mac. Always run the verification below.
Verify the migration
1
Check the Mac appears in Devices
The device record shows the Mac as enrolled and supervised.
2
Confirm the enrollment state on the Mac
On the device, open System Settings > General > VPN & Device Management.
The previous MDM profile should be gone, and a Primo management profile
present. To check from the command line instead:
3
Confirm profiles and apps are applied
Expected configuration profiles and app deployments appear on the device
record.
4
Confirm the FileVault recovery key is escrowed
If no key appears, ask the employee to restart the Mac and wait for the next
sync — the key cannot be escrowed until the bootstrap token is in place.
5
Check the iCloud Lock status
Confirm a bypass code is escrowed. See
Activation Lock bypass code escrow.
Troubleshooting
Apple Business does not offer a migration deadline for a Mac- The Mac does not meet the migration requirements. Bulk actions fail for it — check the Apple Business activity log for the failed action.
- Confirm the Mac is enrolled through Automated Device Enrollment and is past the 30-day provisional period if it was added with Apple Configurator.
- On macOS 26 and later, confirm a migration deadline is set in Apple Business. This is the most common cause: reassignment alone does not trigger the migration, and nothing reports the missing deadline.
- Confirm the reassignment is saved in Apple Business and the Mac is online.
- On macOS 15 and earlier, confirm you removed the previous management profile
from the Mac, then run
sudo profiles renew -type enrollment. - Check the enrollment state on the Mac itself to see whether the previous profile is actually gone.
- The Mac displays the Wi-Fi network picker. The enrollment screen also offers a Choose a Wi-Fi network link.
- Reassign the Mac back to the previous MDM server before the migration starts. The device withdraws its migration prompts.
What if the previous MDM is already decommissioned?
A Mac left on a decommissioned MDM is not lost. It keeps working and keeps all its data — it simply becomes unmanaged: the previous profiles stay in place until something removes them, and the employee notices nothing. To bring it under management on macOS 15 and earlier, you still need to remove the management profile, and you cannot do that without access to the previous console — the employee cannot remove it either. Two options:- Restore access to the previous MDM long enough to unenroll the Macs.
- Erase and re-enroll each Mac through zero-touch deployment. This wipes the device — back up employee data first.
Contact
If Macs remain unenrolled after the deadline, or a FileVault recovery key never appears, contact support@getprimo.com with:- The device serial numbers
- The macOS version on each device
- The name of your previous MDM solution
- The migration deadline you set in Apple Business