Cannot manually install carrier APN profile on MDM-enrolled iPadSolved

Participant
Discussion
10 hours ago Oct 01, 2026
An enrolled iPad needed a carrier APN profile to activate cellular service. The provider gives us a .mobileconfig file that we normally download and install manually on the iPad.
With the Hexnode policy applied, iOS first showed that profile installation was disabled. I enabled Install configuration profile under advanced restrictions, but the manual install still failed with another profile installation error.
The only workaround that worked was removing the policy, installing the APN profile manually, and then pushing the policy back to the iPad. Is there a better way to prevent this on supervised, MDM-enrolled iPads?

Replies (1)

Marked SolutionPending Review
Hexnode Expert
50 minutes ago Oct 01, 2026
Marked SolutionPending Review

This happens because iOS treats user-initiated profile installation differently on supervised, MDM-enrolled devices when restrictions and management policies are enforced. Enabling manual configuration profile installation may not be enough for carrier APN profiles that are downloaded and opened directly on the device.

The recommended approach is to deploy the APN through Hexnode instead of installing it manually on the iPad. This uses the MDM management channel and avoids the iOS UI restrictions.

You can use either of these methods:

1. Configure the APN payload in Hexnode

– Go to Policies.

– Create or edit an iOS policy.

– Navigate to iOS > Network > APN.

– Enter the APN details provided by the carrier.

– Save and assign the policy to the iPad.

2. Deploy the carrier-provided .mobileconfig file

– Go to Policies > iOS > Configurations > Deploy Custom Configuration.

– Upload the provider’s APN .mobileconfig file.

– Save and assign the policy to the target device.

In both cases, the APN profile is installed silently over the air through Hexnode, so the user does not need to open and install the profile manually.

Regards,

Mary Romero

Save