Registering devices with Intune for management and policy enforcement
The device appears under the Apple Enrollment Program token but not under Devices > All devices because it has been assigned and synced from Apple Business/School Manager, but it has not yet completed Intune enrollment and check-in.
Intune can only push apps to devices that are fully enrolled and visible under All devices. Use these checks and steps:
- Confirm the device has completed Automated Device Enrollment
On the iPad, go through the full setup wizard until all Company Portal / management screens are completed and the home screen is reached. If the device is stuck on an enrollment screen, follow the token and device steps below. - Verify the enrollment program token and VPP token are healthy
In the Microsoft Intune admin center:- Go to Devices > iOS/iPadOS > iOS enrollment > Enrollment program tokens > [token name] > Profiles > [profile name] > Manage > Properties.
Check for errors such as:- "This token has expired."
- "This token is out of Company Portal licenses."
- "This token is being used by another service/tenant."
- "This token was deleted."
- Fix any token issues found. If the token is invalid or expired, correct it before retrying enrollment.
- Go to Devices > iOS/iPadOS > iOS enrollment > Enrollment program tokens > [token name] > Profiles > [profile name] > Manage > Properties.
- Identify whether the device is blocked by the VPP token
Still in Intune:- Go to Devices > iOS/iPadOS > iOS enrollment > Enrollment program tokens > [token name] > Devices.
- Filter Profile status by Blocked and check if the iPad’s serial number appears there.
- If the device is blocked, wipe and re-enroll
After fixing token issues:- Go to Devices > All devices and add the Serial number column.
- For each blocked device found earlier, select it and choose Wipe > Yes.
- Have the user go through the setup process again so the device completes enrollment. Once enrollment is complete and the device checks in, it will appear under All devices, and app deployment will work.
- If the device shows as supervised but still not in All devices
- Open the Company Portal app on the iPad (if present).
- The app will attempt to sync; if it reports Unable to sync, select Set up and follow the prompts to complete enrollment.
- After a successful sync, the device should move to a healthy state and appear in All devices.
Once the device is visible under Devices > All devices with a healthy management state, assign the app to that device or its user and wait for the next check-in for the app to install.
References:
- iOS or iPadOS device is stuck on an enrollment screen
- iOS or iPadOS devices aren't checking in with the Intune service
- Troubleshooting iOS/iPadOS device enrollment errors in Microsoft Intune
- Step 5 – Enroll devices in Microsoft Intune
- Deployment guide: Manage iOS/iPadOS devices in Microsoft Intune
- Manage Apple mobile devices and tokens for automated device enrollment