Apple Configurator enrollment URL shows Code 403 while preparing iOS devicesSolved

Participant
Discussion
3 weeks ago Jul 16, 2026

I’m trying to prepare iPhones with Apple Configurator and enroll them into Hexnode for a new deployment. The goal is to supervise the iOS devices during enrollment.

I copied the Apple Configurator enrollment URL from the Hexnode portal and added it as the MDM server URL in Apple Configurator, but it fails with:

“Unable to verify the server’s enrollment URL. Code 403”

When I try installing the profile on the iPhone, it also says the profile is not correct. I’m using a Mac with Apple Configurator. Is there a specific URL format or step I’m missing? Also, should the device be erased only once during supervised enrollment?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
3 weeks ago Jul 16, 2026
Marked SolutionPending Review

Hi @ace_98,

For Apple Configurator enrollment, the Code 403 error usually means Apple Configurator cannot validate the MDM enrollment endpoint. In this case, the first thing to verify is the exact enrollment URL format. For Hexnode Apple Configurator enrollment, use the URL from, Enroll > Platform-Specific > iOS > Apple Configurator

When adding the MDM server in Apple Configurator, make sure the URL is pasted without quotes, spaces, line breaks, or punctuation at the end. The enrollment URL should be in this format: https://:443/configuratorenroll/authtoken-.

Avoid using a malformed format such as: https://:443/configuratorenroll/?authtoken=

That difference can cause Apple Configurator to return “Unable to verify the server’s enrollment URL. Code 403” and can also lead to the “profile is not correct” message on the iPhone.

For supervised enrollment:

  1. Install Apple Configurator on a Mac.
  2. Add your organization in Apple Configurator, if required.
  3. Create or edit the MDM server entry using the correct Hexnode Apple Configurator enrollment URL.
  4. Connect the iPhone to the Mac.
  5. Select the device and choose Prepare.
  6. Enable Supervision if the device must be supervised.
  7. Assign the Hexnode UEM server/profile.
  8. Complete the Prepare workflow.

Supervising an iPhone through Apple Configurator will erase the device. Ideally, the wipe should happen only once as part of the prepare process.

Regards,
Sienna Carter
Hexnode UEM

Marked SolutionPending Review
Participant
2 weeks ago Jul 20, 2026
Marked SolutionPending Review

What if I don’t want the device to be supervised? Can I just prepare it and assign the profile without enabling supervision?

Marked SolutionPending Review
Hexnode Expert
2 weeks ago Jul 20, 2026
Marked SolutionPending Review

Hi @rose-wilson,

If you want an unsupervised Apple Configurator enrollment, turn off the Supervision option in the Apple Configurator prepare profile and assign the Hexnode UEM server using the corrected enrollment URL.

Keep in mind that unsupervised devices have fewer management capabilities than supervised devices. If you need full iOS management controls, supervised enrollment is recommended.

If you also want to add the device to Apple Business during the Apple Configurator workflow, include the organization and device assignment details as part of the prepare process.

Regards,
Sienna Carter
Hexnode UEM

Save