# How to find lost iOS devices with MDM

Hexnode UEM can help locate and secure a lost or stolen iOS device when the device is enrolled and has the required management state. For organization-owned iPhone and iPad devices, Apple Automated Device Enrollment (ADE), formerly Device Enrollment Program (DEP), makes recovery more reliable by reinstalling the MDM profile during setup after a wipe when profile removal is not allowed. Supervised devices provide the strongest Hexnode UEM recovery controls, including location scans, Lost Mode, Lock Device, Wipe Device, and Remote Ring. Managed but unsupervised devices support fewer actions, and unmanaged devices must be located through Apple’s Find My service.

TL;DR: Find a Lost iOS Device with Hexnode UEM
----------------------------------------------

- Use Apple Automated Device Enrollment through Apple Business or Apple School Manager to keep the Hexnode UEM profile non-removable on organization-owned devices.
- Deploy a Location Tracking policy before using the **Scan Device Location** action in Hexnode UEM.
- Use **Manage > [Select Device] > Actions** to lock, wipe, ring, locate, or enable Lost Mode on supported devices.
- Lost Mode and Activation Lock management require supervised iOS devices. Unsupervised devices have limited recovery options.
- If the device is not enrolled in Hexnode UEM, use [iCloud Find Devices](https://www.icloud.com/find), provided Find My was enabled on the device.

Use Automated Device Enrollment for Persistent iOS Device Recovery
------------------------------------------------------------------

Apple Automated Device Enrollment (ADE) through Apple Business or Apple School Manager improves device recovery because the Hexnode UEM profile can be made non-removable. If an enrolled device is erased, the assigned MDM profile is installed again during Setup Assistant when the device is connected to a network and assigned to the Hexnode UEM server.

- **Configuration requirement:** In Hexnode UEM, go to **Admin > Apple Business/School Manager > Automated Device Enrollment > Enrollment Profiles > Create Enrollment Profile** and keep **Allow MDM profile removal** unchecked.
- **Recovery benefit:** ADE helps re-establish Hexnode UEM management after a reset, so supported actions such as Remote Ring, Wipe, Lock, and Lost Mode can be used again after the device completes enrollment and comes online.

Find and Secure Supervised iOS Devices in Hexnode UEM
-----------------------------------------------------

Supervised iOS devices provide the highest level of recovery control in Hexnode UEM. With the required policies and network connectivity, Hexnode UEM can scan the device location, lock the device, erase corporate data, enable Lost Mode, or trigger a remote ring.

### Deploy a Location Tracking Policy for iOS Devices

Location tracking must be configured by policy before Hexnode UEM can collect location history or run an on-demand location scan.

1. Go to **Policies > New Policy > Enterprise > iOS > Tracking and Fencing > Location Tracking**.
2. Configure the location tracking frequency.
3. Assign the policy to the target device under **Policy Targets**.
4. Click **Save**.

Run the Scan Device Location Action
-----------------------------------

After the Location Tracking policy is active, use the **Scan Device Location** action to request the current location of the managed iOS device.

1. Go to the **Manage** tab in the Hexnode UEM console.
2. Select the target device.
3. Click **Actions > Scan Device Location**.
4. Open the **Location History** tab to view the reported location data.

[![Find lost iOS devices with Hexnode MDM using Scan Device Location](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/02/Find-lost-iOS-device-with-MDM.png "Find lost iOS device with MDM")](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2021/02/Find-lost-iOS-device-with-MDM.png)

Use Lock, Wipe, Lost Mode, and Remote Ring
------------------------------------------

Go to **Manage > [Select Device] > Actions** in Hexnode UEM to perform supported recovery and security actions.

- **Lock Device:** Locks the iOS device with the device passcode and prevents further use until the passcode is entered.
- **Wipe Device:** Erases data and settings to reduce the risk of data exposure.
- **Enable Lost Mode:** Locks a supervised iOS device and displays a custom message and contact number.
- **Remote Ring:** Plays a loud sound to help locate a nearby device.

 Warning 
If a device in **Lost Mode** is restarted, it will lose its Wi-Fi connection. Lost Mode can only be disabled via the portal if the device has an active network connection.

 

 Manage Activation Lock for iOS Device Recovery
----------------------------------------------

Activation Lock helps prevent unauthorized users from erasing, reactivating, or selling a device by requiring the associated Apple Account during reactivation. In Hexnode UEM, Activation Lock settings are configured through an iOS policy.

Enable Activation Lock in Hexnode UEM
-------------------------------------

1. Go to **Policies > New Policy > iOS > Enterprise > Advanced Restrictions**.
2. Open **Allow Security and Privacy Settings**.
3. Select **Activation Lock**.
4. Save the policy and apply it to the target device.

 Note: 
After pushing the policy, manually disable and re-enable **Find My iPhone** on the device to trigger the lock.

 

 Find Managed but Unsupervised iOS Devices in Hexnode UEM
--------------------------------------------------------

If an iOS device is managed by Hexnode UEM but is not supervised, Hexnode UEM can still run basic security commands when a [Location Tracking policy](https://www.hexnode.com/mobile-device-management/help/how-to-configure-location-tracking-with-hexnode-mdm/) is in place.

- **Available actions:** [Lock Device](https://www.hexnode.com/mobile-device-management/help/lock-a-device-using-hexnode-mdm/#), [Wipe Device](https://www.hexnode.com/mobile-device-management/help/wipe-a-device-completely-using-hexnode-mdm/), and [Scan Device Location](https://www.hexnode.com/mobile-device-management/help/how-to-scan-device-location-using-hexnode-mdm/).
- **Unsupported on unsupervised devices:** [Enable Lost Mode](https://www.hexnode.com/mobile-device-management/help/how-to-enable-lost-mode-on-supervised-ios-devices/) and [Disable Activation Lock](https://www.hexnode.com/mobile-device-management/help/mdm-bypass-activation-lock/#).

Find Unmanaged and Unsupervised iOS Devices with Find My
--------------------------------------------------------

If the device is not managed by Hexnode UEM and is not supervised, use Apple’s native Find My service instead of Hexnode UEM. Find My must have been enabled on the device before it was lost.

1. Sign in to [iCloud Find Devices](https://www.icloud.com/find).
2. Select the specific device from the device list.
3. Use the available Find My options to locate the device.
4. Verify the required conditions: **Find My** must be enabled, and the device must be online for live location updates.
5. Use supported actions such as Play Sound, Lost Mode, Activation Lock, or Erase Device.

 Note: 
For iOS 5 devices, you can execute **Lock** and **Locate** (on-demand), but persistent Tracking (background history) is not supported.

 

 Disable Lost Mode After an iOS Device Is Recovered
--------------------------------------------------

After the lost iOS device is recovered, disable Lost Mode from the Hexnode UEM portal, from the device lock screen, or during disenrollment when applicable.

- **From the Hexnode UEM portal:** Go to **Manage > [Select Device] > Actions > Disable Lost Mode**.
- **From the device:** Enter the device passcode on the lock screen to disable Lost Mode.
- **During disenrollment:** If an administrator disenrolls a device while Lost Mode is active, the device automatically exits Lost Mode. Hexnode UEM pushes the **Disable Lost Mode** command as part of the disenrollment process so the device remains usable.

Troubleshoot Lost iOS Device Recovery in Hexnode UEM
----------------------------------------------------

### Scan Device Location Does Not Return a Current Location

If **Scan Device Location** does not return an updated location, confirm that the device is managed by Hexnode UEM, has an active network connection, and has a Location Tracking policy assigned. Location scans and MDM commands require the device to communicate with the Hexnode UEM server.

### iOS Device Is Stuck in Lost Mode

An iOS device can remain in Lost Mode when it cannot connect to a network after restart or when it is outside the range of known Wi-Fi networks. If the device has no SIM card or cellular data, Hexnode UEM cannot receive the **Disable Lost Mode** command until connectivity is restored.

Common causes include:

- **Connectivity loss:** The device is outside known Wi-Fi range or has no SIM card or cellular data.
- **Post-restart lockout:** Some iOS versions require passcode entry after restart before Wi-Fi becomes available, but Lost Mode prevents normal passcode entry.
- **USB accessory restriction:** If **Allow USB accessories while locked** is disabled, the device may reject recovery accessories while locked.

### Restore Network Connectivity to Disable Lost Mode

If the device is offline, use a wired network connection when compatible adapters are available.

- **Hardware required:** Lightning to USB 3 Camera Adapter and an Apple USB Ethernet adapter.
- **Action:** Connect the device to a wired internet source with the adapters. After the device comes online, run **Actions > Disable Lost Mode** from the Hexnode UEM console.

### Restore the Device with Apple Configurator

1. Connect the iOS device to a Mac through USB and open **Apple Configurator**.
2. Select the device in the Apple Configurator window.
3. Go to **Actions > Restore**, or Control-click the device and select **Restore**.

 Note: 
This erases all content and removes the supervision profile from supervised devices.

 

### Erase the Device with Apple Configurator

1. Connect the device to a Mac and open **Apple Configurator**.
2. Go to **Actions > Advanced > Erase All Content and Settings**, or Control-click the device and select **Advanced > Erase All Content and Settings**.

### Restore the Device in Recovery Mode

Use recovery mode when the Mac does not recognize the device normally. Open **Finder** on macOS Catalina or later, or **iTunes** on macOS Mojave or earlier.

**Enter recovery mode using the steps for the device model:**

- **iPhone 8 or later:** Press and quickly release the **volume up** button. Press and quickly release the **volume down** button. Press and hold the **side** button until the recovery-mode screen appears.
- **iPhone 7 and iPhone 7 Plus:** Press and hold the **side** button and the **volume down** button at the same time until the recovery-mode screen appears.
- **iPad models without a Home button:** Press and quickly release the volume button closest to the top button. Press and quickly release the volume button farthest from the top button. Press and hold the **top** button until the recovery-mode screen appears.
- **iPad with a Home button and iPhone 6s or earlier:** Press and hold the **Home** button and the **top** or **side** button at the same time until the recovery-mode screen appears.

**Final action:** After the device appears on the Mac, click **Restore**. This erases all data stored on the device.