# Common errors while enrolling iOS  devices in Hexnode

1. The new MDM payload does not match the old payload.
------------------------------------------------------

[![iOS enrollment troubleshooting-The new MDM payload does not match the old payload](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2019/03/The-new-MDM-payload-does-not-match-the-old-payload.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2019/03/The-new-MDM-payload-does-not-match-the-old-payload.png)### Description

Error message while enrolling an iOS device.

### Probable Cause

The device might already have an MDM profile installed in it.

### Solution

To remove the existing MDM profile,

1. On your iOS device, go to **Settings** > **General**.
2. Scroll down and select **VPN and Device Management**.
3. Tap Hexnode MDM, or in case you’ve previously enrolled in a different MDM, tap the name of that MDM provider.
4. Scroll down and tap **Leave Remove Management** > **Erase**.
![Leave Remote Management in iOS devices to remove existing MDM profile](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/11/Leave-Remote-Management-in-iOS-device.png)
 Warning: 
Users [cannot remove the existing MDM profile](https://www.hexnode.com/mobile-device-management/help/how-to-make-mdm-profile-non-removable-on-ios-devices/) if,

- The profile was created by Apple Configurator and is password protected.
- The profile is linked to an MDM profile that is enrolled with Apple [Device Enrollment Program (DEP)](https://www.hexnode.com/mobile-device-management/help/enrollment-of-apple-devices-through-dep/).

 

2. According to your corporate policy, only the following devices can be enrolled and can access the corporate resources: …….
Contact your IT administrator for more information.
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

[![Error message while enrolling iOS device](https:2024/04/Specific-device-types-are-not-allowed-to-enroll.png)](https:2024/04/Specific-device-types-are-not-allowed-to-enroll.png)### Description

Error message while enrolling an iOS device.

### Probable Cause

The device type might not be permitted to enroll in Hexnode.

### Solution

1. Go to **Enroll** > **Settings** in the Hexnode portal.
2. Scroll down to **Enrollment Restrictions** > **Device Models allowed**, select **iPhone** or **iPad** based on the device type that you are using.
3. Click on **Save**.
[![Configuring allowed device models in enrollment restrictions in Hexnode](https:2021/11/Configuring-Device-Models-allowed-in-Enrollment-restrictions.png)](https:2021/11/Configuring-Device-Models-allowed-in-Enrollment-restrictions.png)
3. A connection to the server could not be established.
-------------------------------------------------------

[![Hexnode error message while enrolling a restricted device.](https:2024/04/Connection-to-server-cannot-be-established.png)](https:2024/04/Connection-to-server-cannot-be-established.png)### Description

Error message while enrolling an iPadOS 13 device.

### Probable Cause

The device type might not be permitted to enroll in Hexnode.

### Solution

1. Go to **Enroll** > **Settings** in the Hexnode portal.
2. Scroll down to **Enrollment Restrictions** > **Device Models allowed**, select **iPad**.
3. Click on **Save**.

4. Could not download the identity profile from the Encrypted Profile Service. The credentials within the Device Enrollment profile may have expired.
-----------------------------------------------------------------------------------------------------------------------------------------------------

[![Error while enrolling a restricted Mac in Hexnode.](https:2024/04/Error-Could-not-download-the-identity-profile-from-the-Encrypted-Profile-Service.png)](https:2024/04/Error-Could-not-download-the-identity-profile-from-the-Encrypted-Profile-Service.png)### Description

Error message while enrolling macOS devices.

### Probable Cause

The device type might not be permitted to enroll in Hexnode.

### Solution

1. Go to **Enroll** > **Settings** in the Hexnode portal.
2. Scroll down to **Enrollment Restrictions** > **Device Models allowed**, check the box corresponding to **macOS**.
3. Click on **Save**.

5. Apple’s MDM Certificate (APNs) is required for enrolling Apple devices. Please contact your administrator.
-------------------------------------------------------------------------------------------------------------

### Description

Error message while enrolling an iOS device.

### Probable Cause

You may not have configured an APNs certificate.

### Solution

You need to set up an APNs certificate for an iOS device to communicate with the MDM server.

After logging in to your Hexnode MDM portal,

1. Go to **Admin** tab > **APNs**.
2. Click on **Configure APNs Certificate.**
3. Click on **Generate CSR Request** > *Download* the self-signed-certificate from Hexnode > click **Next**.
4. Click on **Go to Apple Push Terminal** > Login with your company Apple ID.
5. Click on **Create a Certificate** to create the APNs certificate.
6. Click on **Choose file** > *Upload* the self-signed certificate (hexnode_signed_casr.txt).
7. *Download* the APNs certificate generated by Apple.
8. Go back to your Hexnode MDM portal > Enter your company *Apple ID* > *Upload* the APNs certificate > Click **Finish**.

6. Unable to access the enrollment URL sent via email.
------------------------------------------------------

### Probable Cause

Hexnode UEM server may not be reachable to the users.

### Solution

- Make sure that you have disabled *Block all incoming connections* in the Firewall settings.
Go to **System Preferences** > **Security & Privacy** > **Firewall** > click **Firewall Options** > *Uncheck* **Block all incoming connections** > Click **OK**.

7. The enrolled devices are not listed in the Hexnode MDM portal even if the users have installed the profile.
--------------------------------------------------------------------------------------------------------------

### Probable Cause

The devices may not be able to reach APNs.

### Solution

- Check your Wi-Fi network connectivity.
- In case Wi-Fi is disabled, make sure that your device has cellular data network connectivity.

8. Error message “Profile installation failed. The internet connection appears to be offline” displayed on the device.
----------------------------------------------------------------------------------------------------------------------

### Description

The error message is displayed when the device is not connected to the internet.

[![This error message is displayed when the device is not connected to the internet. ](https:2022/08/Profile-Installation-Failed.png)](https:2022/08/Profile-Installation-Failed.png)### Probable Cause

Wi-Fi is not connected or mobile data is disabled.

### Solutions

- Check your Wi-Fi network connectivity.
- In case Wi-Fi is disabled, make sure that your device has cellular data network connectivity.

9. Error message “Profile Installation Failed. Stolen Device Protection is active. To install this kind of profile, temporarily disable Stolen Device Protection in Settings and try again” displayed on the device.
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

### Description

While attempting to enroll the device (when Stolen Device Protection is enabled), an error message is displayed.

[![MDM profile installation failed due to Stolen Device Protection](https:2019/03/MDM-profile-installation-error.png)](https:2019/03/MDM-profile-installation-error.png)### Probable Cause

Stolen Device Protection is activated.

### Solutions

- Turn off the *Stolen Device Protection* option from *Settings* before the enrollment process.
[![Stolen Device Protection setting on iOS device](https:2019/03/Stolen-Device-Protection-setting.png)](https:2019/03/Stolen-Device-Protection-setting.png)- Updating the OS to the latest version will also help resolve the issue.