# How to assign ADE devices to Hexnode?

There are many ways to enroll an Apple device in a UEM. One of the ways is to register the Apple device via the Automated Device Enrollment (ADE) method and then assign the device to the UEM server. For that, you should first [enroll your organization in ABM](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-in-apple-dep//).

To add devices to Apple ABM, make sure that you have:

1. A device bought directly from Apple or an authorized dealer after 1 March 2011 and running at least iOS 7.0.4, iPadOS 13.1, visionOS 2.0, macOS 10.9 or tvOS 10.2.
2. An [iOS or iPadOS devices can be directly added to ABM using Apple Configurator](https://www.hexnode.com/mobile-device-management/help/add-ios-11-devices-to-dep-using-apple-configurator/) regardless of where and when the device is purchased.
3. An [APNs certificate](https://www.hexnode.com/mobile-device-management/help/apns-settings/) setup for the UEM server to communicate with the device.

Steps to Enroll devices via ADE
-------------------------------

Add Devices to Apple Business Manager

### Step 1: Add devices to Apple Business Manager

You will need the Apple Customer Number, or the Reseller ID associated with the purchased devices to add them to ABM. To add the purchased device to the ABM portal, associate the number or ID obtained from the device suppliers to ABM.

1. Log in to your [Apple Business Manager ](https://business.apple.com) account.
2. Click your name at the bottom of the sidebar and go to **Preferences** > **MDM server assignment**.
3. Click on **Edit** next to **Customer Number**.
4. Enter your **Apple Customer Number** or **Reseller Number** and click **Add**.
5. Click on **Done**.

If you have purchased devices from more than one entity, you have to add all the numbers and ID via this method.

#### Apple Customer Number

If the devices were directly purchased from Apple, Apple would assign your organization an Apple Customer Number. Contact your finance department or [Apple Sales](https://www.apple.com/contact/) for your [Apple Customer Number](https://www.apple.com/retail/business/). If the devices were purchased from Apple Store, contact the Business Team for the Customer Number.

#### Reseller ID

If the devices were purchased from Apple Authorized Reseller or a wireless carrier, you would need to enter their Reseller ID in your ABM portal. Also, you should provide your Organization ID to the reseller or carrier.

To find your Organization ID,

1. Log in to your **Apple Business Manager** account.
2. Click on your name at the bottom of the sidebar and go to **Preferences** > **Organization Information**.
3. Your **Organization ID** will be displayed under **Organization Information**.

To get the Reseller ID, contact the Apple Authorized Reseller or carrier via which the devices were purchased. The devices can be enrolled in the MDM only if the reseller or the carrier supports the device enrollment feature in Apple Business Manager.

 

 

 

Configure ADE Enrollment Profile

### Step 2: Configure Enrollment Profile

An ADE Enrollment profile defines the initial setup experience and management configurations for your Apple devices. By configuring an enrollment profile in the Hexnode console, you can customize device settings, choose authentication methods, skip specific Setup Assistant screens, set up Shared iPads, and automatically deploy apps and policies during the initial setup.

For a complete, step-by-step guide on creating and configuring all available settings, refer to our dedicated documentation on [ADE Enrollment Profiles](https://www.hexnode.com/mobile-device-management/help/ade-enrollment-profile/).

 

 

 

Create an ADE Account in Hexnode

### Step 3: Create an ADE Account in Hexnode

To add devices in the ABM program, you need to obtain a server token from Apple.

1. In the Hexnode UEM portal, go to **Enroll** > **All Enrollments** > **No-Touch** > **Apple Business/School Manager** > **Devices**.
2. Then, click on **Add ADE Account**.
3. Provide an **Account Name** and download the certificate file **Hexnode_Apple_DEP_cert.pem**.
4. Sign in to [Apple Business Manager ](https://business.apple.com) account.
5. Click your name at the bottom of the sidebar. Then, go to **Preferences**, and click on the **Add** button next to **Your MDM Servers**.
6. Name the MDM server and upload the public key (the certificate file previously obtained in **Step 4**) and click **Save.**
7. Click on **Download MDM Server Token**.
8. Go back to your Hexnode UEM console and upload the server token in the field **Upload ADE server token file**.
9. Check the box **Add as a Pre-approved device** if you want to [pre-approve](https://www.hexnode.com/mobile-device-management/help/pre-enrollment-of-devices-hexnode-mdm/#pre-approved-dep-enrollment) the devices that you are planning to enroll using Hexnode.
10. Choose a **Default Configuration Profile**. By default, the **Default ADE profile** will be selected. If you want to attach a different configuration profile with the ADE Account, choose it from the drop-down.
11. Click on **Next**.

 

 

 

Assign Devices to the MDM server

### Step 4: Assign devices to the MDM server

You can either assign Apple devices individually to the respective device management server or bulk assign devices to the same management server.

 Note: 
You can automatically assign newly purchased devices added to the ABM by designating an MDM server as the default. To set a default MDM server, click the name at the bottom sidebar and navigate to **Preferences** > **MDM Server Assignment** in the ABM portal.

### Individual Device Assignment

1. From the **Devices** page, select the required device.
2. On the top-right portion of the screen, click on the horizontal ellipsis button. Then, click on **Edit MDM Server**.
    [![Assigning devices in ABM.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Device-Assignment.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Device-Assignment.png "Device Assignment")
3. Tap **Assign to the following MDM**. Now select the server from the drop-down. Tap **Continue**. [![Assigning MDM Server](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Assign-MDM-Server.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Assign-MDM-Server.png "Assign MDM Server")
4. Click on **Confirm** to assign the device to the management server.

### Bulk Device Assignment

1. From the Devices page, either 
    - - Manually select the devices that you require. On Mac, press **Command** key in the keyboard and click on the device names to make the selection. On Windows, use the control **CTRL** key.
            [![Assigning devices to MDM Server in bulk.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Bulk-Device-Assignment.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Bulk-Device-Assignment.png "Bulk Device Assignment")
    
    Or
    
    
    - Apply the device filters to streamline the device list. The available filters are *Device Management, Source, Order number, Device type, Storage size*. To add a filter criterion, click *Filter* below the Search bar and check in the relevant boxes corresponding to each filter option. Then, click on **Search** to sort out devices according to the criterion. From the filtered device list, you can either select **All devices** or click on the device name for a specific device. [![Applying device filters.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Device-Filter.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Device-Filter.png "Device Filter")
        
        [![List of all devices in ABM.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/All-Devices.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/All-Devices.png "All Devices")
2. Click on **Edit** corresponding to the **Edit MDM server** option. [![Option to edit MDM Server.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Edit-MDM-Server.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Edit-MDM-Server.png "Edit MDM Server")
3. Select **Assign to the following MDM** option. From the drop-down, select the MDM server. Click on **Continue**.
    [![Assigning devices to an MDM server.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Assign-to-the-following-MDM.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/08/Assign-to-the-following-MDM.png "Assign to the following MDM")
4. Click on **Confirm** to assign the device to the management server.

The details of assigned devices can be seen in the device **Assignment History**, including the order number, the MDM server to which the device is assigned, assignment date and the device type.

 

 

 

Sync Devices to Hexnode 

### Step 5: Sync devices with Hexnode

The devices added under the MDM server created for Hexnode in the Apple Business Manager portal have to be synced with Hexnode. This synchronization will import the details of the added devices to the corresponding ADE Account in Hexnode. To sync devices to Hexnode,

1. On your Hexnode UEM console, go to **Enroll > All Enrollments > No Touch > Apple Business/School Manager > Accounts**.
2. Click on **Sync all ADE accounts**.

Navigate to **Devices** to view all devices synced from the MDM server in the ABM portal.
Change the device filter from **Show all devices** to the required **ADE Account** to list the devices assigned to that particular ADE Account.

 

 

 

Associate the Enrollment Profile with Individual Devices (Optional)

### Step 6: Associate the Enrollment Profile with individual devices

ADE Enrollment Profile assists the MDM in streamlining the device enrollment and set up on ABM added devices. If you want to attach a different Enrollment Profile (other than the one attached with the ADE Account) with an individual device,

1. On your Hexnode UEM console, navigate to **Enroll > All Enrollments > No Touch > Apple Business/School Manager > Devices**.
2. Select the device and click on **Associate Enrollment Profile**.
3. Select the profile and click **Assign**.

 

 

#### **All ADE Devices**

All ADE Devices

 SetUp Assistant OptionsSupported versionsDescriptionApple ID- iOS 7.0+
- tvOS 10.2+
- macOS 10.9+

Skip Apple ID setup.Biometric- iOS 8.1+
- macOS 10.12.4+

Skip biometric setup.True Tone Display- iOS 9.3.2+
- macOS 10.13.6+

Skip True Tone Display pane.Apple Pay- iOS 8.1+
- macOS 10.12.4+

Skip Apple Pay setup.Restore- iOS 7.0+
- macOS 10.9+

Disable restoring from backup.Screen Time- iOS 12.0+
- macOS 10.15+

Skip the Screen Time pane.Appearance- iOS 13.0+
- macOS 10.14+

Skip the Choose Your Look window.Diagnostics- iOS 7.0+
- tvOS 10.2+
- macOS 10.9+

Skip sending diagnostic information to Apple.Location Services- iOS 7.0+
- macOS 10.11+

Skip setting up Location Services.Privacy- iOS 11.3+
- tvOS 11.3+
- macOS 10.13.4+

Skips the privacy pane.Siri- iOS 7.0+
- tvOS 10.2+
- macOS 10.12+

Disable users from configuring Siri.Terms and Conditions- iOS 7.0+
- tvOS 10.2+
- macOS 10.9+

Hide terms and conditions from the user.

 

 

#### iOS Devices Only

iOS only

 SetUp Assistant OptionsSupported versionsDescriptionMove from AndroidiOS 9.0+Remove Move from Android option from the Restore pane.KeyboardiOS 11.0+Skip the Keyboard pane.Watch MigrationiOS 11.0+Skip the screen for watch migration.iMessage and Face TimeiOS 12.0+Skip the iMessage and FaceTime screen.PasscodeiOS 7.0+Hides and disables the passcode pane.SIM SetupiOS 12.0+Skip the add cellular plan pane.OnboardingiOS 11.0+Skip on-boarding informational screens.Software UpdateiOS 12.0+Skip the mandatory software update screen.Home Button SensitivityiOS 10.0+Skip the Home Button screen.Device to Device MigrationiOS 13.0+Skip Device to Device Migration pane.ZoomiOS 8.3+Skip the Zoom pane which shows larger text and controls.Welcome/Get StartediOS 13.0+Skip the Get Started pane.

 

 

#### macOS Devices Only

macOS Only

 SetUp Assistant OptionsSupported versionsDescriptionFileVaultmacOS 10.10+Disable FileVault Setup Assistant screen.iCloud StoragemacOS 10.13.4+Skip iCloud Documents and Desktop screen.iCloud AnalyticsmacOS 10.12.4+Skip the iCloud Analytics screen.RegistrationmacOS 10.9+Prevent users from filling out the registration form and sending it to Apple.

 

 

#### tvOS Only

tvOS only

 SetUp Assistant OptionsSupported versionsDescriptionScreen SavertvOS 10.2+Skip setting up screen saver.TV Home Screen SynctvOS 11.0+Skip TV home screen layout sync screen.Where is this Apple TV?tvOS 11.4+Prevent user from selecting the room for the Apple TV.Set up your Apple TVtvOS 10.2+Prevent users from configuring their Apple TV.Sign In to your TV providertvOS 11.0+Skip the TV provider sign in screen.

 

 

#### visionOS Only

visionOS only

 SetUp Assistant OptionsSupported versionsDescriptionIntelligencevisionOS 26+Skips the ***Apple Intelligence*** setup pane.Software UpdatevisionOS 26+Skips the mandatory software update screen.PasscodevisionOS 26+Hides and disables the passcode pane.TipsvisionOS 26+Skips the ***Tips*** pane.Welcome/Get startedvisionOS 26+Skips the ***Get Started*** pane.

 

 

What happens at the device end?
-------------------------------

If you have a device that is not yet activated, switch on the device and connect it to the internet. The Apple server will push the Enrollment Profile previously attached to the devices via the MDM server on the ABM. This will enroll the device in the MDM. However, if you have an already activated device, reset it to its factory settings to get it enrolled in the MDM.

If no enrollment authentication is enforced via the MDM, the device will get directly enrolled in the MDM. However, if enrollment authentication was turned on, the device will get enrolled only after user authentication.

 Warning:- The organization can choose to **release a device from the ABM portal** via which it was purchased. If the device is released from the ABM portal before the enrollment, it cannot be enrolled via the Automated Device Enrollment Program. If the device is released from ABM after the enrollment, it will get removed from the ABM portal as well as from the Hexnode UEM portal.
- Only devices running **macOS 12.0.1 or above** with **Apple Silicon** or **T2 Security chip** can be added back to ABM using Apple Configurator on iPhone.
- iOS and Apple TV devices released from ABM can be added back via Apple Configurator. Devices released from ABM running iOS 11.0+ and tvOS can be enrolled in Hexnode via [‘ADE using Apple Configurator’](https://www.hexnode.com/mobile-device-management/help/add-ios-11-devices-to-dep-using-apple-configurator/). However, such devices will not act like a normal ADE enrolled device during the initial 30 days of deployment. That is, during the 30-day provisional period, the user can remove the MDM management either from the **Settings** app (**General > Device Management > Remove Management**) or by wiping the device. To remove MDM management on wiping, click on **Leave Remote Management** on the **Remote Management** setup wizard.

 

Troubleshooting
---------------

#### 1. Issue: The enrollment profile configurations are not reflected on the macOS device.

**Probable Cause:**

The macOS device has either failed to fetch the latest enrollment profile configurations from Apple’s servers or acknowledged an outdated profile that does not include the recent changes made in the Hexnode UEM portal.

**Solution:**

To audit the current enrollment profile settings and confirm they match the latest configurations, execute the following command in the device Terminal:

*sudo profiles show -type enrollment*

If the command returns the error “No enrollment configuration found,” or if the parameter values do not reflect your latest profile configurations (for example, if the MDM profile set to be non-removable in the portal but the Terminal returns *IsMDMUnremovable = 0*; instead of *IsMDMUnremovable = 1*;), the device has not successfully pulled the updated profile.

In such cases, [re-enroll the macOS device](https://www.hexnode.com/mobile-device-management/help/re-enrolling-macs-using-automated-device-enrollment-after-device-setup/) via Terminal to force the device to fetch the latest enrollment profile settings.

https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/macOS-Terminal-output-of-the-applied-enrollment-profile-configurations.png

[![Terminal window displays the list of settings configured to the device via enrollment profile.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/macOS-Terminal-output-of-the-applied-enrollment-profile-configurations.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2026/05/macOS-Terminal-output-of-the-applied-enrollment-profile-configurations.png "macOS Terminal output of the applied enrollment profile configurations")