Skip to main content

Automated MDM Migration for Apple Devices with ABM enrolled (OS 26 and Later)

Overview

Beginning with iOS 26, iPadOS 26, and macOS 26, Apple supports migrating eligible organization-owned devices from one Mobile Device Management (MDM) service to another without erasing the device.

This allows administrators to move eligible devices to Swif while preserving user data and avoiding a factory reset. The migration is managed through Apple Business, formerly Apple Business Manager (ABM).

During migration, the device:

  1. Receives migration notifications.

  2. Unenrolls from the previous MDM service.

  3. Enrolls with Swif.

  4. Receives the enrollment profile, policies, applications, and settings assigned through Swif.

Important: A non-wipe migration does not automatically copy policies, certificates, applications, recovery keys, or other settings from the previous MDM service. Configure and test the equivalent settings in Swif before beginning the migration.

Requirements

Devices must meet the following requirements:

Requirement

Details

Operating system

iOS 26, iPadOS 26, or macOS 26 or later

Ownership

The organization must own the device

Enrollment

The device must normally be enrolled through Automated Device Enrollment

Apple Configurator devices

The 30-day provisional period must have ended

Network access

The device must be able to reach Apple and Swif enrollment services

Destination service

The device must be recognized and properly configured in Swif

A device does not need to have originally shipped with OS 26. A device upgraded from an earlier operating-system version can migrate without being erased if it meets Apple’s current migration requirements.

Unsupported Devices and Configurations

Native migration is not available for:

  • Shared iPad devices

  • Devices running an operating system earlier than iOS 26, iPadOS 26, or macOS 26

  • Devices manually added through Apple Configurator that are still within the 30-day provisional period

  • Devices configured for Return to Service with application preservation

  • Migrations to or from Apple’s built-in device management service

If a device is ineligible, Apple Business does not display the option to add a migration deadline. Bulk operations containing ineligible devices can also fail and appear in the Apple Business activity log.


Before You Begin

1. Connect Swif to Apple Business

Make sure Swif is linked to Apple Business and that the required Apple Push Notification service certificate and device management service token are valid.

2. Prepare Devices in Swif

Before reassigning devices:

  1. Sync the devices from Apple Business to Swif.

  2. Confirm that each serial number appears in Swif.

  3. Assign the appropriate Automated Device Enrollment profile.

  4. Assign the device to the correct user or device group when required.

  5. Confirm that the destination enrollment profile is active.

If Swif does not recognize an incoming device or cannot return the appropriate enrollment profile, re-enrollment may fail.

3. Re-create Existing Management Settings

MDM configurations do not transfer automatically between vendors. Re-create and assign the required settings in Swif, including:

  • Wi-Fi and network certificates

  • VPN and proxy settings

  • FileVault configuration

  • Passcode and security restrictions

  • Platform SSO or identity settings

  • System extensions and privacy permissions

  • Applications and application licenses

  • Software update policies

  • Web filtering and endpoint security settings

  • Compliance policies

Pay particular attention to Wi-Fi profiles. If the previous MDM removes the device’s only network configuration before Swif delivers a replacement, the device may lose connectivity during enrollment.

4. Review FileVault and Activation Lock

Before migrating Macs:

  • Securely retain any required FileVault recovery information from the previous MDM.

  • Confirm that Swif is configured to escrow the FileVault Personal Recovery Key.

  • Confirm that bootstrap-token handling is working.

  • Review the current Activation Lock state.

During migration, the previous MDM’s Activation Lock bypass codes become invalid. The new MDM service creates new bypass codes after reenrollment.

5. Prepare Managed Applications

For iPhone and iPad, Apple can preserve managed applications and their associated managed data when the destination MDM installs the applications before completing device configuration.

Application preservation depends on the destination MDM workflow and application assignments. Confirm the required applications and licenses in Swif before migration.

If your deployment uses Apps and Books applications:

  1. Remove the content token from the previous MDM when appropriate.

  2. Upload or configure the token for Swif.

  3. Reassign the required application licenses.

Apple recommends that a migration involving volume-purchased applications not use a deadline longer than 30 days.

6. Run a Pilot Migration

Start with a small group representing your production environment, including:

  • Different device models

  • iPhone, iPad, and Mac devices

  • Different users and locations

  • FileVault-enabled Macs

  • Devices using certificate-based Wi-Fi

  • Devices with business-critical applications

Confirm successful enrollment, policy delivery, application availability, network access, FileVault escrow, and inventory reporting before expanding the migration.


Migrate a Device to Swif

Migrate One Device

  1. Sign in to Apple Business with an account permitted to assign devices and manage device management services.

  2. Go to Devices > Inventory.

  3. Search for and select the device.

  4. Select Assign Device Management.

  5. Select the device management service associated with Swif.

  6. To enforce completion by a specific date, select Add Deadline.

  7. If adding a deadline, choose a date more than one day and less than 90 days away.

  8. Select Continue.

  9. Review the confirmation carefully.

  10. Select Confirm.

  11. Monitor the resulting activity until it completes.

  12. Reassign any applications or licenses that require action.

Migrate Multiple Devices

  1. In Apple Business, go to Devices > Inventory.

  2. Search for and select the devices.

  3. Choose the device management service associated with Swif.

  4. Optionally select Add Deadline.

  5. Select a deadline more than one day and less than 90 days away.

  6. Select Continue.

  7. Review the affected devices.

  8. Select Confirm.

  9. Monitor the migration in the Apple Business activity log.

Apple Business supports searching for multiple devices by pasting up to 1,024 comma-separated serial numbers.

Important: A deadline is optional. Add one when you need Apple to enforce completion by a specific date. Without a deadline, there is no administrator-defined date on which Apple forces the user to complete reenrollment.


User Experience

Before the Deadline

After a deadline is set, Apple displays migration notifications on the device:

  • Notifications appear daily.

  • During the final 24 hours, notifications appear hourly.

  • During the final hour, notifications appear at approximately 60, 30, 10, and 1 minute before the deadline.

The user can follow the prompt and complete migration before the deadline.


Before deadline is reached, you can Renewing MDM Enrollment on an ADE Mac Device.

sudo profiles renew -type enrollment

At the Deadline

If the user has not completed migration:

  • iPhone and iPad: The device restarts and begins enforced reenrollment.

  • Mac: A nondismissible full-screen enrollment prompt appears.

If the device loses internet access after unenrolling from the previous MDM, Apple can display a Wi-Fi picker so the user can connect to a network and continue.

On a Mac, all local users can receive the migration prompt. Depending on the destination enrollment configuration, the user who completes migration may become the managed user, or the Mac may initially have no managed user.

Verify the Migration

After migration, confirm that:

  1. The device appears online in Swif.

  2. The previous MDM enrollment has been removed.

  3. The Swif MDM enrollment profile is installed.

  4. The correct user and device group are assigned.

  5. Required policies report as installed.

  6. Wi-Fi, VPN, certificates, and identity services work.

  7. Required applications remain available or reinstall successfully.

  8. FileVault remains enabled on Macs.

  9. The FileVault recovery key is escrowed to Swif.

  10. Activation Lock is in the expected state.

  11. The device continues reporting inventory and compliance information.

  12. Restarting the device does not disrupt management.

Do not migrate the remaining production fleet until the pilot devices pass these checks.

Change or Cancel a Scheduled Migration

A migration can be changed or canceled before it starts.

For a single device:

  1. Go to Devices > Inventory in Apple Business.

  2. Select the device.

  3. Select Change Deadline.

  4. Change or remove the deadline.

  5. Select Save.

  6. Monitor the resulting activity.

Removing the migration before it starts returns the device to its original device management service and cancels the migration prompts.


Troubleshooting

Add Deadline Is Not Available

Confirm that:

  • The device runs iOS 26, iPadOS 26, or macOS 26 or later.

  • The device is organization-owned.

  • The device is enrolled through a supported enrollment method.

  • The Apple Configurator provisional period has ended.

  • The device is not a Shared iPad.

  • Return to Service with application preservation is not enabled.

  • The migration is not to or from Apple’s built-in management service.

Review the Apple Business activity log for the exact failure.

The Device Cannot Enroll in Swif

  • Confirm that its serial number appears in Swif.

  • Confirm that the correct enrollment profile is assigned.

  • Verify that the Apple Business connection and token are valid.

  • Confirm that the device can reach Apple and Swif services.

  • Check for an expired APNs certificate.

  • Review the Apple Business activity log and Swif enrollment status.

  • Verify that network security tools are not blocking enrollment traffic.

The Device Loses Network Access

The previous MDM may have supplied the device’s Wi-Fi certificate or network profile.

  • Connect to another available Wi-Fi network.

  • Use the Wi-Fi picker displayed during enrollment.

  • Confirm that Swif has the replacement Wi-Fi and certificate policies.

  • Test the network transition on a pilot device.

  • Maintain an alternate network during large migrations.

Managed Applications Are Missing

  • Confirm that the applications are assigned in Swif.

  • Verify Apps and Books token configuration.

  • Confirm that sufficient licenses are available.

  • Check whether the previous MDM removed an application during unenrollment.

  • Confirm whether the application was managed or unmanaged before migration.

  • Review the application installation status in Swif.

Apple preserves only managed application data through its managed-app preservation workflow.

FileVault Is Enabled but Swif Does Not Have the Recovery Key

  • Confirm that the Swif FileVault policy is installed.

  • Confirm that the Mac has a valid bootstrap token.

  • Check whether recovery-key rotation or re-escrow is pending.

  • Retain the previous recovery information until Swif confirms successful escrow.

  • Contact Swif Support before removing the last available recovery record.

The Mac Shows a Full-Screen Enrollment Prompt

This is expected when the migration deadline has expired. The prompt is nondismissible because Apple is enforcing reenrollment.

Connect the Mac to the internet and complete the displayed enrollment steps.

Migration Is Pending

  • Confirm that the device is online.

  • Ask the user to open and follow the migration notification.

  • Check whether the deadline has passed.

  • Review the pending migration in Apple Business.

  • Confirm that the device still meets migration requirements.

  • Review the Apple Business activity log for errors.

Important Considerations

  • Native migration avoids a factory reset, but it does not copy the previous MDM configuration.

  • Do not remove the previous MDM integration or records until the migration has been verified.

  • Existing Activation Lock bypass codes become invalid during migration.

  • FileVault recovery information must be handled carefully.

  • Managed application preservation requires correct application and license assignments.

  • Network profiles should be recreated before migration.

  • Migrate in controlled groups to reduce network and support impact.

  • Keep users informed about prompts, restarts, deadlines, and expected downtime.

Related Resources

Did this answer your question?