Category filter
Renew an expired ADE token when Hexnode sync adds 0 devices
TL;DR
If syncing Automated Device Enrollment (ADE) in Hexnode adds 0 devices, check whether the ADE token has expired. An expired ADE token breaks the connection between Apple Business and Hexnode. Renew the token in Apple Business, upload the new server token in Hexnode under Admin > Automated Device Enrollment > Accounts, save the ADE account, and then run the sync again.
Executive summary
Hexnode uses the ADE server token from Apple Business to sync corporate-owned Apple devices assigned to the Hexnode MDM server. When this token expires, Hexnode cannot fetch the assigned ADE devices, and a manual sync may return 0 newly added devices. Renewing the token in Apple Business and uploading it to the existing ADE account in Hexnode restores the connection required for device synchronization.
Symptoms
- A manual ADE sync in Hexnode adds 0 devices.
- The ADE account already exists in Hexnode, but assigned devices do not populate after sync.
- The ADE token associated with the account is expired.
Cause
The ADE token has expired. This token authorizes communication between Apple Business and Hexnode. Once expired, Hexnode cannot successfully retrieve devices assigned to the device management server in Apple Business.
Renew ADE Token
Step 1: Apple Business Portal
- Log in to Apple Business.
- Select Devices from the top banner.
- On the left side of the page, select Management Services and click the required server name under Device Management Services.
- Click the ellipsis icon (…) in the upper-right corner.
- Click Download Token.
- When the dialog box displays “Downloading a new server token will reset your existing one,” click Download server token.
Step 2: Hexnode Portal
- Log in to the Hexnode portal.
- Navigate to Admin > Automated Device Enrollment > Accounts.
- Move the cursor to the right end of the server name and click Edit.
- On the Edit ADE Account page, click Choose File next to Upload Token.
- Select the newly downloaded server token file.
- Click Save.
- Run ADE sync again to fetch the devices assigned to the Hexnode MDM server.
What to verify after renewal?
- The ADE account in Hexnode shows an active token.
- The correct device management server is selected in Apple Business.
- The target devices are assigned to the Hexnode MDM server in Apple Business.
- A manual sync successfully pulls the assigned Apple Business/ADE devices into Hexnode.
Frequently Asked Questions
Why did ADE sync add 0 devices?
One confirmed cause is an expired ADE token. When the token expires, the connection between Apple Business and Hexnode is no longer valid, so Hexnode cannot fetch assigned devices.
Do I need to create a new ADE account in Hexnode when the token expires?
No. If the ADE account already exists, edit the existing account and upload the newly downloaded server token file.
Where is the ADE token uploaded in Hexnode?
Upload the renewed token from Admin > Automated Device Enrollment > Accounts by editing the corresponding ADE account and using Choose File next to Upload Token.