Facing Enrollment Hurdles with New iPhones in Intune? Here’s What We Learned
Enrolling the latest iPhones into Microsoft Intune has left many admins scratching their heads. Devices vanish mid-process, DEP syncs stall, and error messages offer little guidance. After wading through hundreds of comments, here’s a clear picture of the problem—and the fixes that actually work.
The Frustration Is Real
Most posts start with a tale of sudden failures. Hundreds of iPhones once enrolled without a hitch now refuse to appear in the Intune portal. Devices pop in for a second, then disappear again. Audit logs show no deletions. Azure AD still lists the devices. It feels like magic—just not the helpful kind.
Common Missteps: Backups and Restores
Several admins discovered the culprit wasn’t Intune itself, but the way devices were being reset:
- iCloud Restores Break Enrollment
“If you wipe and start again it should work. Just no backups or restores,” warned one IT pro. - Factory Reset, Skip the Restore
Setting up as a fresh device—no backup, no restore—solved the problem instantly for many.
It turns out that restoring iCloud data can corrupt the MDM payload and break DEP handshakes, so skip that step when re-enrolling.
Apple’s Agreements and iOS 26
A handful of comments pointed out two more factors:
- Apple Business Manager Terms
When Apple updates its DEP/ASM agreements, you must accept those changes in both ASM and Intune. Otherwise, existing devices can get orphaned. - iOS 26 Support Gaps
The brand-new iPhone 17 Pro ships with iOS 26, which Intune isn’t fully ready for yet. Early adopters may hit enrollment bugs until Microsoft releases an update.
The One-Two Punch Fix
Based on the community feedback, here’s the reliable workflow to get those iPhones back in line:
- In Apple Business Manager, confirm you’ve accepted the latest DEP/ASM agreement.
- On the iPhone, go to Settings and perform a full factory reset.
- When prompted, set up as a new device—do not restore from any backup.
- Enroll via the Company Portal or automated DEP process.
Devices should appear immediately and stay visible.
Final Tips from the Trenches
- Check Your APNs Certificate: An expired push certificate can hide devices. Renew in Intune and Apple Business Manager.
- Clean Up Azure AD: Old, stale device objects can conflict. Remove duplicates before re-enrolling.
- Watch for Apple Security Features: Stolen device protection or location locks can delay DEP syncs. Temporarily disable if needed.
- Monitor Intune Service Health: Rare backend issues can cause devices to vanish in waves.
Wrap-Up
Enrollment headaches with new iPhones often boil down to backup restores, outdated agreements, or early OS compatibility gaps. By performing a true factory reset—no restores—and accepting Apple’s latest terms, you’ll restore stability. Until Intune officially supports iOS 26, this approach will save the day.


