Skip to content
Avanet

Sophos Mobile: Check Apple Business or enroll an iPhone/iPad directly with Configurator

For company-owned devices, first choose the enrollment path: Apple Business with Automated Device Enrollment (ADE) or direct Sophos enrollment of an iPhone/iPad with Apple Configurator and a device group’s URL. For Apple Business, this article remains a preflight guide, not a complete rollout guide; the separate direct enrollment section describes the documented preparation steps. Personal devices (BYOD) and the execution of an offboarding process are not covered by this guide. Sophos still calls some of the ADE interfaces Apple DEP.

Clarify the enrollment path and data risks first

  • Device already in Apple Business: Check its assignment there to the external device management service Sophos Mobile. In Sophos Mobile, a suitable Apple Business profile must be assigned to that device class, either as the default or individually, before the device goes through ADE at its next setup. None as the default, without an individual assignment, does not result in automatic Sophos enrollment.
  • Device missing from Apple Business: Sophos describes manual addition of an iPhone/iPad using Apple Configurator for Mac; this resets the device to factory settings. Apple also describes Apple Configurator for iPhone, including for eligible Macs with Apple silicon or a T2 chip and macOS 12.0.1 or later. A Mac that has already been set up must be erased before it can be added this way. Sophos’s statement that Macs cannot be added manually does not apply to this other Configurator path. Before any erase: Confirm ownership, backup, and Activation Lock; for the actual addition, first check the appropriate device- and Configurator-specific path in the local addition procedure below.

Do not continue setting up a manually added device prematurely: For the Apple Configurator for Mac path, Apple warns against continuing Setup Assistant on the device after its assignment to the management service if ADE is intended. When adding an iPhone/iPad with Apple Configurator for iPhone, however, Apple calls for continuing after checking the device’s entry with the management service; Macs added with this Configurator follow a different process. Follow the device-specific local addition procedure below; none of this establishes that Sophos enrollment has succeeded.

30 days is not permanent enforcement: For devices added manually through Configurator, Apple specifies a 30-day provisional period after successful assignment and enrollment during which users can remove the device from Apple Business, supervision, or the device management service. Apple’s German- and English-language pages use different conjunctions here (“or” and “and,” respectively); do not infer separately effective release steps from this wording.

Warning – conditional data loss when removing a profile: On an iPhone/iPad running iOS/iPadOS 14 or later that was added to Apple Business using Apple Configurator for Mac, removing the device management service’s enrollment profile resets the device to factory settings and automatically releases it from Apple Business, according to Apple. Back up data before such a decision and check the path on a disposable pilot device. This does not apply to all ADE devices as a blanket rule; changing a Sophos profile assignment is not the same as removing the profile from the device.

Direct enrollment instead of ADE: Sophos enrollment of an iPhone/iPad through Configurator and a device group’s Sophos auto-enrollment URL does not in itself add devices to Apple Business and does not replace ADE assignment; this does not rule out a separate addition to Apple Business. For the direct path, use the following section. For Apple Business/ADE, continue afterward at “Prerequisites for ADE before handover.”

Add devices manually to Apple Business after separate authorization

These steps add devices to Apple Business; they do not use the direct Sophos group URL. First verify device identity, ownership, a current backup, Activation Lock, and explicit erase authorization. Do not replace existing management without checking it. An authorized Managed Apple Account and internet access are required. The 30-day period and profile-removal risks above still apply.

iPhone/iPad with Configurator for Mac – addition without immediate enrollment completion:

  1. Connect the device by USB to the Configurator Mac. For a device already in use, sign out of iCloud and turn off Find My before erasing. Keep it connected, select it in Configurator, and open Actions > Prepare.
  2. Select Manual Configuration and addition to Apple Business. Clear Activate and Complete Enrollment, choose Next, then New Service in the management service menu and Next. This path leaves individual user enrollment for later; the immediate-completion alternative requires an already managed device record and is not described here.
  3. Enter Apple Business as Name, leave the supplied service URL unchanged, and choose Next. Failure to verify this URL is part of this addition path; do not enter the Sophos group URL here. Choose Next again, add no certificate, and choose Next.
  4. Select the intended organization, or New Organization for an authorized first setup; choose Next and sign in with the Managed Apple Account authorized to manage devices; choose Next and complete sign-in with Continue. Generate a new supervision identity belongs to the documented first setup: Do not use it to replace an existing supervision identity; stop on identity conflicts.
  5. Choose the setup pages to skip and a suitable Wi-Fi configuration profile, continuing with Next each time. Authenticate with the macOS administrator account and choose Update Settings; unlock the device if prompted. Confirm Erase only within the previously approved erase scope. Wait for preparation to reach Setup Assistant.
  6. Check the Apple Business service assignment below. For this Mac Configurator path, do not continue Setup Assistant afterward if ADE is intended; clarify the Sophos prerequisites and profile assignment first.

Configurator for iPhone – iPhone/iPad or an eligible Mac:

  1. Provide iOS 16 or later on the Configurator iPhone, check internet access, and sign in with the authorized Managed Apple Account. Under Settings, choose the network handover deliberately: Share Wi-Fi, Configuration Profile, or Don’t Share. For service assignment, choose Specific with Sophos, the verified Default, or None followed by manual assignment.
  2. The target iPhone/iPad needs iOS/iPadOS 16 or later: Stop at Choose a Wi-Fi Network in Setup Assistant. An eligible Mac needs Apple silicon/T2 and macOS 12.0.1 or later: Provide power and internet, choose the language, and stop at Select Your Country or Region. A previously configured Mac must first be erased under separate authorization; this section does not execute a Mac erase. Restart the target device if you pass the relevant page.
  3. Bring the Configurator iPhone close to the target and scan the displayed image; alternatively, choose Pair Manually on the target, Manual Pairing in Configurator, and use the six-digit code. If the pairing page is missing on an iPhone/iPad, return to the Home Screen on the Configurator iPhone and reopen the app. Wait for the upload.
  4. On a Mac, choose Shut Down. On an iPhone/iPad, choose Erase and Shut Down only with erase authorization. First verify service assignment and the Sophos device record with its profile; then, for this iPhone/iPad path, continue Setup Assistant and ignore any offered proximity setup. Keep the Mac off until ADE handover has been clarified.

Service assignment in Apple Business: In the Apple Business portal, open Devices > Inventory with device-management permission. Find added devices through Search Filter > Source > Apple Configurator > Search and select the intended devices by identifier. Choose Assign Device Management for one device or Assign for several, select the intended Sophos service, choose Continue, review the dialog, and choose Confirm. Check the activity through completion. Only verify an existing automatic assignment; do not change it without checking. Then synchronize the Sophos list and assign the platform profile as described below. Addition and service assignment alone do not prove successful enrollment; stop on discrepancies rather than erasing or releasing again.

Enroll an iPhone/iPad directly with Sophos Mobile using Apple Configurator

This procedure applies to company-owned iPhones and iPads that are to be enrolled directly with Sophos Mobile during activation. It uses the Sophos device group’s Auto-enrollment URL, not an Apple Business profile. The ADE profile fields and status values described below are not part of this procedure.

Prerequisites and authorization to erase

  • According to Sophos, the user who activates the device must be registered for the Sophos Fusion Self Service Portal (SSP). The ADE profile option Assign user to device > No does not remove this prerequisite for the direct path.
  • Provide a Mac with a suitable Apple Configurator version and a USB connection to the iPhone/iPad. The Apple guide reviewed specifies macOS 15.7 or later for Apple Configurator 2.20; do not infer a minimum version for other Configurator releases from this. Sophos calls the application Apple Configurator 2, while Apple calls it Apple Configurator for Mac.
  • Provide an internet connection for activation. Apple specifies Wi-Fi or internet sharing from the Mac over Thunderbolt/USB; a configuration profile with a Wi-Fi payload can be selected in Prepare Assistant.
  • Before preparation, confirm the device identifier, company ownership, backup, Activation Lock, and authorization for any erase that may be required. Do not prepare the device without confirmed access and authorization to erase. Do not replace existing management without checking it first. Check the edition, license, administrator permissions, and actual interface in your own tenant; this guide does not confirm their availability.

Prepare the device group and Auto-enrollment URL

  1. As a one-time step, create the device group to which devices will be assigned during direct enrollment: Go to Device groups > Create device group, enter a name and description, select the appropriate Compliance policies for company-owned and personal devices, and select Save. Group and policy scope are described under Prepare the device group and check its scope.
  2. Enable Enable iOS auto-enrollment in this group’s properties. This option is for enrollment with Apple Configurator; it is not a general prerequisite for ADE or other platforms.
  3. Record this group’s URL shown under Auto-enrollment URL and have it ready for preparation. Use this exact URL, not an assumed tenant address or another group’s URL. Do not include complete tenant-specific URLs in public screenshots or broadly accessible tickets.

Prepare the device in Prepare Assistant

  1. Connect the iPhone/iPad by USB to the Mac running Apple Configurator. In Configurator, select the correct device and choose Actions > Prepare or the Prepare button. This opens Prepare Assistant.
  2. Choose the manual path: Sophos calls it Manual Enrollment, while the Apple guide reviewed calls it Manual Configuration. These different labels do not constitute a tested click path that is identical across versions. In the version you use, check the manual enrollment path and the connection to the management service; Do not enroll in Device Management is not appropriate for the intended Sophos enrollment.
  3. Enter the Sophos device group’s Auto-enrollment URL recorded earlier for enrollment. Apple describes selecting an existing management service or New Server in the assistant; saved services are under Apple Configurator > Settings > Servers. Apple’s general description using an FQDN/IP does not replace Sophos’s specific requirement to use the group URL. If service discovery does not return correct enrollment information, do not continue with guessed addresses: Check the group URL and Configurator version with the responsible Mobile administration team and escalate to Sophos as the management service provider. Apple refers users to the management service developer in this case.
  4. Work through the remaining preparation steps and decide on the optional settings before completion:
    • Supervision: Enable it if needed; direct enrollment alone does not guarantee supervision. According to Apple, changing this selection later requires erasing, preparing again, and supervising again.
    • USB hosts: Decide which computers the device may connect to. Apple specifies Allow devices to pair with other computers for synchronization with a Mac or PC over a cable. This is the Configurator selection, not the CER upload in the ADE profile described below. Before applying a restriction, check the intended authorized host and recovery path.
    • Supervision identity: For supervised devices, create an identity (Generate a new supervision identity) or select Choose an existing supervision identity, continue with Next, and select the existing identity from the keychain. Use a consistent identity across the intended Configurator and management instances. Use your own identity files only with an understood certificate chain and a thoroughly checked solution. Changing the identity later requires erasing, preparing, and supervising again; it is not a simple way back.
    • Setup Assistant: Select the Setup Assistant pages to skip and continue with Next. This selection belongs to Prepare Assistant, not the ADE tabs iOS setup or macOS setup. A skipped dialog is not evidence of a permanently enforced policy.
    • Apple Business: Adding the device to Apple Business as well is a separate decision. Do not treat it as a necessary consequence of using the group URL; if it is intended, first clarify the Apple Business addition path described above and its risks.
  5. After checking your selections, start preparation with Prepare. Monitor progress through Window > View Activity. Do not turn off the Mac during preparation: Apple warns of possible device damage. If you cancel, allow Configurator the time it needs to end the operations safely.

Handover, activation, and device name

Once preparation is complete, hand the device over to the intended user. According to Sophos, setup and enrollment take place as configured when the device is first turned on. Completed preparation is not yet evidence of successful Sophos enrollment: View Activity shows preparation, not its subsequent completion in Sophos Mobile.

Before a broad rollout, perform activation on a disposable pilot device with the user registered in the SSP, then check the specific Sophos device entry, the expected device group, and, where applicable, supervision on the device. If enrollment is missing or the state is inconsistent, stop expanding the rollout and clarify the issue with the Mobile administration team; do not initiate another erase or an Apple Business release as a diagnostic action. This acceptance check is a check to be performed, not a test carried out here.

By default, Sophos uses a name based on the device ID and device type for devices automatically enrolled this way. Alternatively, Sophos can use the name set on the device. To do this, deliberately choose Synchronize device name under Setup > Apple setup > iOS & iPadOS; the effects when the setting is enabled or disabled, and the subsequent name check, are described under Choose Synchronize device name deliberately. The setting names the device in Sophos’s management inventory; do not infer that it renames the device itself or changes Activation Lock.

Verification limits: This direct procedure is based on vendor documentation. Neither a tenant nor a device was tested here; successful enrollment, supervision status, and a safe way back have not been confirmed in practice.

Prerequisites for ADE before handover

Organization, device, and profile

Check the organization and integration: Check the Apple Business organization and authorized access, an Apple Push Notification service certificate (APNs) uploaded to Sophos Mobile, and the linked Sophos instance.

If the APNs certificate is missing and none has ever been uploaded in the tenant, hand off first-time APNs certificate creation separately to the APNs owner. The owner must document the displayed certificate details, expiration date, and responsibility for the account and renewal; the ADE preflight itself does not authorize creation, upload, or pilot enrollment. APNs is an Apple MDM prerequisite, not just an ADE task. Sophos specifies the Apple roles Administrator or Device Enrollment Manager for linking. The Apple Business service token is under Setup > Apple setup > Apple DEP in Sophos.

Check the device and profile: Check assignment to the correct management service in Apple Business, the device class (iOS & iPadOS or macOS), the default or individual profile, and network access during setup. According to Sophos, devices from resellers may take up to 24 hours to appear in Apple Business. In Sophos, under Devices > Apple DEP, run Synchronize with Apple Business if needed; if there is no default profile, assign an individual profile. Do not proceed to rollout until the assignment is clear.

In both profile types, the device group selected under Device group is assigned during enrollment. Sophos recommends a separate group for Apple Business devices to simplify management; it is not required. The selected Task bundle is also transferred to devices during enrollment. The selection area contains only task bundles without an enrollment task. A bundle from another enrollment path therefore cannot be assumed suitable based on its name alone.

Set up integration after separate change authorization

The preflight above does not authorize a change. Proceed only with separate approval, an existing Apple Business organization, an authorized account, and an uploaded APNs certificate. Do not replace an existing integration without checking it; record the service, account, and previous state. Stop if anything is unclear; do not reset with Reset DEP.

  1. In Sophos, open Setup > Apple setup > Apple DEP and download the public-key certificate with Download public key.
  2. Sign in to Apple Business as Administrator or Device Enrollment Manager and open Devices > Management Services.
  3. For the first management service, choose Get Started; if a service already exists, choose Connect external device management > Continue. Give the intended Sophos instance a unique service name. Do not enable Release Devices without separate approval: this permission is not required for linking.
  4. Upload the Sophos public-key certificate downloaded earlier, choose Next, download the service token with Download Service Token, and choose Done.
  5. Return to the same Apple DEP tab in Sophos, select the service token with Upload a file, and choose Save. Do not store token files publicly.
  6. Check the saved link against the intended Sophos instance and record the account, responsible owner, and expiration date. The token is valid for one year; use the same Apple Account as for the original token when creating a new one. If the service or account is wrong, stop and involve Mobile administration rather than trying a second integration or a reset as a way back.

Saving is not evidence of enrollment. This integration was not tested in a tenant here; safe token replacement or rollback has not been confirmed in practice. APNs renewal and device release remain separate procedures.

Create a platform profile and choose the default deliberately

This change also requires separate approval. Record existing profiles, the default selection, and affected devices beforehand; do not make a new profile the default for further devices without checking its scope.

  1. Under Setup > Apple setup, open Apple DEP profiles and choose Add.
  2. Choose iOS & iPadOS or macOS for the device class. The profile controls enrollment, USB hosts, and Setup Assistant; it does not replace a permanently enforced device policy.
  3. Review the required settings using the platform sections below, particularly user assignment, device group, task bundle, and USB access, as well as the later Setup Assistant section. Then choose Apply.
  4. If there are several profiles, select the appropriate default under Default DEP profile assigned to iPhones and iPads or Default DEP profile assigned to Macs. Devices without an individual profile receive this default. None without an individual profile means no Sophos enrollment during setup.
  5. Choose Save, then recheck the saved profile, platform, and default selection. Next, check device assignment and status in “Assignment is not yet acceptance” below. If the selection is wrong, do not correct it by erasing a device; have the authorized administration team review the documented previous selection.

Profile creation and assignment are not enrollment completion. Validate actual enrollment separately on an authorized pilot device; neither a profile change nor rollback was tested here. The following settings are a focused selection, not a complete catalogue of all profile fields.

User assignment and unresolved activation prerequisite

The Assign user to device setting links sign-in during enrollment to user assignment. The documented options differ by platform:

  • iOS/iPadOS: Yes - LDAPS authentication uses the configured Active Directory connection over LDAPS. Yes - Self Service Portal authentication opens the sign-in page of the Sophos Fusion Self Service Portal (SSP) and supports Sophos Fusion sign-in methods, including federated sign-in and multi-factor authentication. Both Yes values assign the signed-in user to the device.
  • macOS: According to Sophos, Yes - LDAPS authentication allows sign-in with a Sophos Fusion email address and password or, if an LDAP connection is configured, with Active Directory credentials. Here, too, the signed-in user is assigned to the device. Do not apply the separate iOS/iPadOS SSP option to the macOS profile.
  • Both platforms: According to the profile pages, No means no sign-in and no user assignment during enrollment. Assigning a user later if needed is a separate action.

Activation remains unresolved before rollout: Sophos’s preparation guidance lists users registered in the SSP as a prerequisite for activation. This sits alongside the profile information for No. Check how or whether these statements interact in your own tenant on a pilot device before rollout; do not infer either a universal SSP requirement or guaranteed activation without sign-in. The profile options described here do not resolve this open prerequisite.

MDM assignment and removability

Decide whether users may use User can skip MDM policy assignment to skip assignment to mobile device management (MDM) during setup. For iPhone/iPad, also check whether the enrollment profile should be removable: According to Sophos, User can remove MDM policy can be disabled only for supervised devices. This prerequisite does not guarantee universal non-removability. The conditional reset described above and automatic Apple Business release when the profile is actually removed remain limited to the Configurator path specified there.

Safeguard USB access and the supervision identity

Provide the host certificate after change authorization: On the intended Configurator Mac, select the correct existing organization; create a new organization only as a separately authorized first setup. Open Keychain Access > My certificates, select exactly that organization’s certificate, and export it as CER (.cer). Export only the certificate, not a private key or a P12 file for this upload. In the appropriate iOS/iPadOS profile under Setup > Apple setup > Apple DEP profiles, open USB pairing and upload this CER file with Upload host certificate. Clear Allow USB pairing with all hosts only after clarifying certificate matching, the authorized Mac, and recovery access; save with Apply and Save. Before wider restrictions, test pairing on the authorized pilot device with this Mac; stop on discrepancies. Optional sharing of organizations or P12 identities between Macs is separately administered and is not performed here.

On iPhone/iPad, do not disable Allow USB pairing with all hosts until an authorized Mac with a suitable host certificate and a recovery path have been checked. When the option is enabled, pairing with any computer is possible. When it is disabled, pairing is limited to appropriately authorized Macs; USB pairing with Windows computers is then not possible. Clarify affected Windows workflows before making the change.

Before applying the restriction, identify the specific organization in Apple Configurator and its certificate: Each organization configured there has its own certificate. Sophos describes uploading this organization certificate, exported as CER, in the USB pairing area of the Apple Business profile. The uploaded supervision identity certificate must match the identity in the keychain of the intended Macs; Macs with this certificate in their keychain can supervise the device. Multiple uploaded certificates can authorize multiple hosts. If pairing with all hosts is turned off and no certificate is uploaded, connecting to Apple Configurator 2 is not possible. Do not roll out a USB restriction without a tested, authorized Mac.

Sharing a supervision identity as P12 is different: Additional Configurator stations with the same identity can securely configure supervised devices. Sharing therefore expands the set of authorized stations and must be limited to authorized recipients, using an encrypted, password-protected PKCS-12 export. It is not the same as another CER upload. Replacing a supervision identity is not a harmless way to reverse a USB setting: Apple requires devices to be erased, prepared again, and supervised again. Before such a change, clarify data and responsibility; neither an identity change nor recovery has been tested here.

SMC app and enrollment completion

Confirm app behavior on a pilot device: If Install SMC app is enabled, Sophos gives two alternatives: On the iOS setup tab, turn off the Apple ID option (which skips account setup) so users sign in with their Apple Account during setup, or add Sophos Mobile Control to Apple Business apps and configure automatic app assignment to devices in Sophos Mobile. For the Apple Business apps path, explicitly check before handover that licenses for Sophos Mobile Control are available in the relevant Apple Business location and that automatic device assignment is configured. This does not guarantee installation or completion. To complete enrollment, users must open the SMC app and let it synchronize with Sophos Mobile; merely making the app available is not enough. Check the behavior of the chosen alternative in your own tenant on a pilot device; do not assume it has been tested.

Setup Assistant: Security state and data transfer

The iOS setup and macOS setup tabs skip individual Setup Assistant steps. These settings are not permanent restrictions on functionality: Users can still enable the corresponding option later. A permanent restriction requires the appropriate Restrictions configuration—in an iOS device policy for iOS/iPadOS, or in a macOS device policy or macOS user policy for macOS, depending on scope. These policies are not configured here, and neither default values nor tested enforcement are promised.

Security and diagnostics options

For both platforms, Sophos describes the following effects of skipped setup steps:

  • Passcode skips creating an unlock passcode. Touch ID & Face ID skips biometric setup; biometric sign-in in place of a passcode is not configured in this step.
  • Location services and Siri skip their respective configuration steps; location services or Siri are initially turned off.
  • Diagnostics skips diagnostics configuration. According to Sophos, the diagnostic and usage data described there are not sent to Apple. On macOS, iCloud Analytics separately concerns diagnostic and usage data for the iCloud account.

These are documented effects in the setup context, not a guarantee that every option applies to every device or remains turned off permanently. In particular, they establish neither a general block on telemetry nor a security state confirmed on a pilot device.

Do not confuse FileVault with a skipped dialog: In the macOS profile, skipping FileVault disk encryption specifically means that FileVault is subsequently turned off, according to Sophos. Clarify the intended encryption policy before handover and check the actual FileVault status on the pilot device; do not equate a skipped setup step with effective encryption.

Data transfer and local accounts by platform

On iOS/iPadOS, Restore from backup skips restoring data from iCloud or transferring data from an Android device. The separate Disable “Move Data from Android” setting instead makes the Android data transfer option unavailable. Both concern data transfer, not restoration of the Sophos enrollment profile. Hiding a page is not always effective either: Safety & Handling may appear before the Apple Business profile is retrieved; in that case, according to Sophos, the corresponding skip setting has no effect.

On macOS, Restore from backup skips data restoration from Time Machine or a system migration, not the iOS/iPadOS MDM backup mechanism described below. Registration skips creating a computer account. iCloud Drive skips enabling automatic uploads of files from Documents and Desktop. Before handover, clarify the intended account and data transfer path; these details also describe setup steps, not tested recovery or a permanent block on uploads.

MDM profile from an iOS/iPadOS backup

A backup is no guarantee of MDM enrollment: According to Sophos, in the iOS/iPadOS profile Don’t use MDM policy from backup prevents the Sophos enrollment profile from being restored from a backup during setup only on iOS 26 and iPadOS 26. If a device running iOS 26/iPadOS 26 is set up from a backup containing the old Sophos enrollment profile, Sophos says it tries to reconnect to Sophos Mobile; if the device has already been removed there, Sophos Mobile rejects that connection. Conditional preflight before a planned reset, not a tested recovery procedure: For this case, Sophos says to enable Don’t use MDM policy from backup first and assign the updated Apple Business profile to the device before resetting it; only after those steps should a reset even be considered. From iOS 27/iPadOS 27 onward, Sophos says this profile is not restored from a backup in any case. Separately, Restore from backup on the iOS setup tab skips the data restoration step during setup. After an erase or restore, recheck management and supervision on a disposable pilot device; do not infer that enrollment or supervision is retained from a backup.

Assignment is not yet acceptance

Individual assignment requires separate change authorization: Record device identifiers, platform, previous assignment, and the default profile. These steps do not authorize an erase or reset.

  1. In Sophos, open My Products > Mobile > Devices > Apple DEP and run Synchronize with Apple Business; refresh the browser page if needed.
  2. Verify and select the intended devices by identifier. Choose Actions > Assign profile, select the appropriate platform’s Apple Business profile in the confirmation dialog, and confirm assignment.
  3. Check the saved assignment against Profile, Profile status, and Enrolled device, and the pilot checks below. If the device or profile is wrong, stop and involve the authorized administration team rather than erasing as a correction.

To explicitly withdraw an individual assignment, select the same verified devices and, under separate authorization, choose Actions > Unassign profile. First check the default-profile consequence below; this is not device unenrollment or Apple Business release.

Under Devices > Apple DEP, read the Profile, Profile status, and Enrolled device columns together. The displayed assignment is not necessarily the profile already in use:

  • Pushed: The device is enrolled with Sophos Mobile using the profile shown under Profile. At its next setup, it uses the same profile.
  • Assigned: A profile is assigned but is not yet in use. If a device name appears under Enrolled device, the device is already enrolled but uses a different profile or no profile. Without a device name, it is not enrolled. At its next setup, it uses the profile shown under Profile.
  • Removed: The profile assignment was withdrawn after enrollment. This implies neither immediate unenrollment nor release from Apple Business.
  • Empty: No profile is assigned. With a device name under Enrolled device, the device is enrolled but uses no profile; without a device name, it is not enrolled.

With Unassign profile, the configured default profile applies at the next setup. If there is no default profile either, automatic Sophos enrollment does not occur; the same applies to Removed and Empty without a default profile. According to Sophos, a changed ADE profile takes effect on already enrolled devices only after an erase and new setup. This status display is not permission to reset: Before such an action, checks of data, ownership, and Activation Lock remain required. Assigning or unassigning a profile is not a release from Apple Business.

On the pilot device, also check device status and the supervision indicator, and SMC synchronization where applicable. Neither a tenant nor a device was tested for this article.

Handle tokens, certificates, and exit separately

According to Sophos, the Sophos integration’s Apple Business service token is valid for one year. To create a new service token, use the same Apple Account used for the original token; record the responsible person and expiration date. This is not the APNs certificate.

Apple also names a password change for the Managed Apple Account of the person who downloaded the service token, or that person’s departure from the organization, as reasons to replace the token. Clarify responsibility and access before such a change; neither a tested replacement nor a fallback procedure is described here.

For APNs renewal, identify the existing certificate by APNs Topic in Sophos and UID in the Subject DN in Apple’s portal. Sophos warns that renewing the wrong certificate requires re-enrollment: If the topics differ, stop before saving. Have the APNs owner carry out the identity check and APNs certificate renewal separately; this is not a complete renewal guide.

Reset DEP is not routine renewal: It deletes the service token and all Apple Business devices and profiles from Sophos Mobile. This does not establish any immediate effect on already enrolled devices.

Pre-release check for each device, not a release step: Before “Release from Organization,” determine the actual Activation Lock status (on/off) and, if the lock is active, its type (user-based or organization-based). For removal through Apple Business, the device must have been added before the lock was enabled and must not have been released yet; assignment to a management service alone does not prove this. Identify the authorized removal or recovery path and responsible person in advance: With appropriately authorized roles and when device conditions are met, Apple Business can remove either a user-based or an organization-based lock; according to Apple, a linked management service cannot remove a user-based lock but can generally remove an organization-based one. Sophos-specific limitation: The Sophos command to remove Activation Lock requires a device still enrolled with Sophos and, according to Sophos, does not work on devices with at least two SIM/eSIM slots; Sophos says this includes all iPhone models current as of its documentation. Apple’s general statement therefore does not establish that Sophos can remove the lock from an iPhone. Check the role permission to remove Activation Lock separately from permission to release devices. Do not initiate release without a clear device-specific path; a Sophos bypass code has neither been checked here nor promised as a way out.

Offboarding stop before “Release from Organization”: Do not release a device sent to Apple for repair: If Apple replaces a device that has already been released during repair, the replacement device will not be available in Apple Business, according to Apple. Devices the organization no longer owns or controls (for example, after a transfer of ownership), by contrast, must be released under the Apple Business agreement – by a separately authorized offboarding team, and only after a device-specific check of data, Activation Lock, and responsibility. Repair is not a reason for such a release. An Apple Business release is not the reversal of a Sophos profile assignment or merely a change of management service assignment. A confirmed release cannot be undone as a transaction: While the device remains released, it cannot be assigned to a management service; Apple Business can no longer manage its Activation Lock. The device must then be erased and restored. According to Apple, separate re-addition through Apple Configurator or the original authorized reseller/carrier is possible – it does not undo the earlier release. Check whether the linked management service may release devices without signing in to Apple Business: Apple’s help pages contradict each other about the default state of this release permission. Therefore, do not assume a default; verify the linked service’s actual setting in your own tenant before any release procedure. Before disposal or transfer of ownership, address data, Activation Lock, and permissions in a separately owned release and recovery procedure; this article does not provide release steps.