# Troubleshooting tips for errors occurring when enrolled via ABM/ASM **Last Updated On**: 14 Jul 2026 **17 minutes read** Enrollment via ABM eases the role of the IT admin by providing bulk out of the box enrollment. Here are some of the common errors that happen during different stages of this enrollment. ## ABM portal errors 1. **After logging in to the Apple Business Manager (ABM) portal, you are unable to view the Add MDM Server button.** The option to add MDM servers is available only when you have the **Device Manager** role assigned to you. Make sure the administrator has assigned the Device Manager role to you. Also, check if the admin has agreed to Apple's terms and conditions. To learn more about role management and the difference between roles in ABM and other Apple Deployment Programs, refer to **Roles** in [ABM user guide](https://www.apple.com/business/site/docs/Apple_Business_Manager_Getting_Started_Guide.pdf). ## Syncing ABM with MDM 1. **Endpoint Central server is not able to contact ABM to sync devices.** Check if mdmenrollment.apple.com is allowed along with other [domains](https://www.manageengine.com/mobile-device-management/faq.html#g2) and [ports](https://www.manageengine.com/mobile-device-management/faq.html#g1) listed here. Also, verify the availability of the required [Apple services](https://www.apple.com/support/systemstatus/). 2. **You encounter the error "Technician removed from ABM server".** If the technician who created the ABM server is removed from the Endpoint Central console, a new technician must be assigned to the ABM server in order to continue enrolling devices via ABM. 1. To assign a new technician, in the Apple Enrollment tab, click on **Servers** and click on **Modify Settings** under **Action** for the respective server. 2. In the pop-up window, click on **Modify** without modifying any settings. This will assign the currently logged in user as the owner for the server. ![Modifying the ABM server to assign the current technician as owner](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/abm-technician-2.webp) 3. **When you are unable to perform sync in ABM server.** If you have not accepted the terms and conditions in ABM server, sync will fail. Go to [ABM portal](https://business.apple.com/) and accept all the terms and conditions. Wait for sometime and perform the sync once again. ![ABM sync error shown when the terms and conditions are not accepted](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/abm_error7.webp) 4. **IOS device added to ABM but not showing in MDM console after sync.** **Cause:** Device already exists in MDM under managed, retired, or staged tab. **Resolution:** Check and remove the device from the existing tabs (managed, retired, staged) in MDM, then re-sync ABM with MDM. ## During device activation The following page will appear, when there is any error in enrollment during device activation. ![Generic enrollment error page shown during device activation](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/abm_error1.webp) Click on **Back** and go to the previous page, click **Next**, wait for sometime till it redirects you to the error page. Note the error and check for the error in the below mentioned errors. 1. **Request timed out.** **Reason:** When the server is unreachable to the device due to poor network connectivity. ![Request timed out error during device activation](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/abm_error2.webp) **Resolution:** - Ensure that the device can reach Endpoint Central server from the network used. - Make sure that you can reach the Apple [URL](https://support.apple.com/en-us/HT210060) from the network you are trying to enroll the device. - Check whether the DNS records are properly added for the server and its reachable from the network used. - Go to **Enrollment -> ABM/ASM enrollment page -> Servers tab**, modify and save the ABM token settings. Factory reset your device in recovery mode and try to enroll again. Check this to factory reset in [iPhone and iPod](https://support.apple.com/en-us/HT201263), [iPad](https://support.apple.com/en-us/HT212787). **Note:** If you're using EC build above **2224.1**, you should enable Tools and Remote control port (8443) for inbound traffic. 2. **Configuration of the profile cannot be downloaded.** **Reason:** This issue happens when you cannot reach the Endpoint Central server from the network used. **Resolution:** - Ensure that you can reach the Endpoint Central server from the network used. - Make sure your proxy/firewall allows this connection properly. If you are using Secure Gateway server, ensure its server time is in sync with Endpoint Central server's time. - On the server console, go to **Enrollment -> ABM/ASM enrollment** page and check whether any error is shown at the top. Resolve them. - Factory reset your device in recovery mode and try to enroll again. Check this to factory reset in [iPhone and iPod](https://support.apple.com/en-us/HT201263), [iPad](https://support.apple.com/en-us/HT212787). 3. **Invalid profile.** **Reason:** The Configuration for your iPhone could not be downloaded from organization name. This happens because of some errors in syncing ABM with MDM. ![Invalid profile error during device activation](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/apple_config_troub_tip12.webp) **Resolution:** - Head to the server console, **Enrollment -> ABM/ASM enrollment** page and check whether any error is shown at the top. Resolve them. - Factory reset your device in recovery mode and try to enroll again. Check this to factory reset in [iPhone and iPod](https://support.apple.com/en-us/HT201263), [iPad](https://support.apple.com/en-us/HT212787). 4. **Failed to retrieve configuration.** **Reason:** This error occurs when the device is running an unsupported OS version. The iOS or iPadOS version is below the required version (iOS 13 or iPadOS 13.1), preventing configuration retrieval from Apple Business Manager (ABM) or the MDM server. **Resolution:** - Ensure the device is updated to **iOS 13 or above** (for iPhones) or **iPadOS 13.1 or above** (for iPads). - After updating the OS, retry the enrollment process through Apple Business Manager (ABM). 5. **Cancelled.** **Reason:** If your enterprise SSL certificate does not satisfy the requirements, then this error happens. ![Cancelled error caused by an SSL certificate issue (screen 1)](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/abm_error5.webp) **Resolution:** - If you are using Enterprise SSL certificate, ensure it satisfies the requirements mentioned [here](https://support.apple.com/en-us/HT210176). 6. **The cloud configuration server is unavailable.** ![Cloud configuration server unavailable error on Mac](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/macerror.webp) **Reason:** - If no MDM server is assigned to a Mac in the ABM portal and the Mac hasn't been synced in the MDM server, attempting to enroll it through ABM using a terminal command will result this error. - This error occurs when multiple users are present on a Mac, and the command is executed by a user signed in with a non-administrator account. **Resolution:** To resolve this error, follow these steps: - Login to the [ABM portal](https://business.apple.com/) and assign the Mac to an MDM server. - Navigate to **Devices > Inventory > Select the required Mac device.** ![Selecting the Mac device under Devices > Inventory in ABM](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/macassignment1.webp) - Click on **Assign Device Management** and select the MDM server from the dropdown. ![Assigning the Mac to an MDM server via Assign Device Management](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/macassignment2.webp) - In the MDM console, navigate to Enrollment > Enroll through ABM/ASM, select the assigned server, and perform a sync. - Once synced, enter the enrollment command in the device's terminal. The device should now enroll successfully. - Log in as an Administrator user and execute the command to complete the ABM enrollment successfully. 7. **A server with the specified hostname could not be found.** ![Server with the specified hostname could not be found error](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/abm-connection-issue.webp) **Reason:** This issue occurs when the configured MDM server cannot be reached due to network-related problems. Common causes include poor connectivity, incorrect DNS resolution, or interference from proxy or VPN configurations. **Resolution:** To resolve this error, follow these steps: - Ensure the device is connected to a stable internet connection. - If the issue persists, try switching to a different Wi-Fi network or use a mobile data connection to eliminate any network-specific restrictions. - Ensure that the new network does not have proxy or VPN configurations that could block access to the MDM server. - Once the connection is stable and unrestricted, attempt to enroll the device again. 8. **Google Workspace (G Suite) authentication not working in ABM enrollment.** During Apple Business Manager (ABM) enrollment, iOS/iPadOS devices may encounter the following Google authentication error while authenticating with Google Workspace (G Suite): **Access blocked: This request does not comply with Google's policies (Error 403: disallowed_useragent)** ![Google Workspace authentication error (Error 403: disallowed_useragent)](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/google_workspace_error.webp) **Reason:** When Google Workspace (GSuite) Directory authentication is configured for ABM enrollment, during device activation, the enrollment flow redirects users to the Google sign-in page for authentication. However, the sign-in page may be blocked on iOS/iPadOS devices due to Google's user-agent policies. **Resolution:** Configure the ABM enrollment settings to use **Admin** for the **Device to be activated by** option, as shown in the image below. ![Setting 'Device to be activated by' to Admin in ABM enrollment settings](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/device_activated_by_admin.webp) This ensures that directory authentication is not used during the enrollment process. After enrollment, the device will be available under the **Staged** tab for user assignment. ## Endpoint Central console errors - **Why are my devices not listed under Apple Business Manager (ABM) tab when I add the devices to ABM using Apple Configurator?** When devices are enrolled to ABM using Apple Configurator, the devices will be initially listed under Apple Configurator tab even though they are added to the ABM portal. On reset, the device gets listed under ABM. - **Even after successful sync, the device is not listed in the Endpoint Central server under Enrollment -> Apple -> Apple Enrollment (ABM/ASM) -> Devices.** Check if the device has been enrolled in the Endpoint Central server using an enrollment method other than ABM. Remove the device from management, reset the device and sync again with the server. The device is listed on under **Enrollment -> Apple -> Apple Enrollment (ABM/ASM) -> Devices.** ## Forbidden Errors ![Forbidden error shown during ABM sync (example 1)](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/t1.webp) ![Forbidden error shown during ABM sync (example 2)](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/mobile-device-management/forbidden-error2.webp) The following are the 2 cases of Forbidden errors encountered: 1. **Server Deleted in ABM/ASM:** If the ABM/ASM server associated in MDM console, is deleted from ABM/ASM portal, forbidden error occurs. To resolve this error, delete the server from the MDM console and create new one. 2. **Using Load Balancer:** An ABM/ASM sync error will be encountered if a Load Balancer is used. If that is the case, all outgoing request to ABM (mdmenrollment.apple.com) must be routed through the same outgoing IP as ABM sync is a series of operation and if IP address changes in between, Apple will invalidate and send error. 3. **ABM User Role Changes:** An ABM/ASM sync error will be encountered if the user who originally created the ABM server in the ABM portal has their role changed from Administrator or Device Enrollment Manager to People Manager, Content Manager, or Staff. ## Restoring Data - **Error after migrating data between Mac devices enrolled via ABM** Apple does not support migration with ABM devices and migration through Time-machine will break ABM enrollment. Hence migrating data from an old Mac device to a new one will result in new certificates in the key-chain getting restored with old certificates, consequently leading to loss in connection with MDM server. In these scenarios you can back up the data to an external drive, and re-enroll the device. - **Users are unable to transfer data from old iPhone to new iPhone.** Users won't be able to migrate data using peer-to-peer transfer in iOS devices during ABM/ASM enrollment. This is because Apple does not support Quick transfer for ABM enrolled devices. However, users can transfer data using iCloud or Finder or iTunes.