Create an Automated Device Enrollment Library Item
To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article.Universal Settings
In this section, configure universal Automated Device Enrollment settings that apply across supported Apple device types. The platform-specific sections that follow provide additional settings for each Apple platform.Require Authentication

Allow MDM Profile Removal

Override organization details

Options Common to Platform-Specific Sections
These Automated Device Enrollment options work the same way on every Apple platform. Open the platform section you need in the Library Item and configure the setting there. Anything that only applies to certain platforms is documented under that platform later in this article.Install Library Items during Setup Assistant
For Mac, iPhone, iPad, Apple TV, and Vision, the Automated Device Enrollment Library Item includes Install Library Items during Setup Assistant. When you enable it, you build a list of eligible Library Items that must finish installing while the device is still in Setup Assistant.- Eligible Library Items for the platform appear in the drawer regardless of the device’s Blueprint.
- Library Items that always install during Setup Assistant appear in the drawer and cannot be deselected.
- Library Items that cannot install during Setup Assistant do not appear in the drawer.
- Library Items configured for Self Service only (for example some App Store or in-house app setups) do not appear in the drawer; those installs are user-initiated after setup, not during enrollment.
Enable the option for each platform you use
Add Library Items to the list

Review the automatic release timeout
Compared with Liftoff
Compared with Liftoff
- Enrollment scope: Install Library Items during Setup Assistant applies only to devices enrolled through Automated Device Enrollment (ADE). It does not run on manually enrolled devices. Liftoff supports manual enrollment, ADE, or both, depending on the Enrollment trigger you choose in the Liftoff Library Item.
- What gets installed: For ADE, you explicitly choose which eligible Library Items install during Setup Assistant using Select Library Items to require during Setup Assistant. Liftoff does not offer that kind of pick list; it presents installation for the Library Item types Liftoff covers (see How Liftoff Works), and all assignments of those types on the Blueprint follow Liftoff’s flow without per-item selection in Liftoff.
- Using both on one Blueprint: If you enable Install Library Items during Setup Assistant and assign Liftoff to the same Blueprint, Setup Assistant installs only the Library Items you selected for ADE. After Setup Assistant completes, Liftoff installs any Blueprint-assigned items within Liftoff’s scope that were not already installed during Setup Assistant.
Larger lists, apps, and network conditions
Larger lists, apps, and network conditions
Installers and scripts that can interrupt Setup Assistant
Installers and scripts that can interrupt Setup Assistant
- Mac Custom App: Restart after successful install; Pre- and post-install scripts
- Custom Script: Restart after a successful execution (under Restart Options)
- macOS Auto App: Options (includes Add to Dock during install, Run preinstall script, and Run postinstall script)
Manually release devices held in Setup Assistant
When a device is held in Setup Assistant, it stays on the Configuring screen while Apple reports it as awaiting configuration. The hold ends when required work finishes, when Automatically release device after is reached, or when you release it manually. You can release any device that reports as awaiting configuration. That usually matters when:- The device is enrolling with Automated Device Enrollment and Install Library Items during Setup Assistant is enabled, and a Library Item stalls (for example a large app download, a pending Apps and Books license, or poor connectivity).
- The device is migrating into Iru Endpoint with App Preservation, and Setup Assistant is waiting while managed apps are preserved.
Open the device record
Release the hold
Check status
Review the hold banner

- Use manual release when a device is stuck, not as the usual way to finish enrollment. Library Items that had not finished installing continue through the device’s Blueprint after Setup Assistant completes.
- Release hold appears only while the device reports as awaiting configuration. If the device is not held, the command returns an error, including when you send it through the Enterprise API.
- The banner does not refresh on its own. Use Check status or reload the page to confirm the device was released.
- For Apple’s command reference, see DeviceConfigured.
Require Minimum OS Version
In the Mac, iPhone, and iPad sections of the Automated Device Enrollment Library Item, Require minimum OS version tells the device to finish an operating system update before enrollment completes. You set the required minimum OS version in those sections. Apple runs that update during Setup Assistant. This is separate from Managed OS policies you configure for after enrollment. Choose Version must be greater than or equal to for a specific OS version, Latest public release for the newest public release from Apple (Mac, iPhone, and iPad), or Custom with This is a beta version and a Seed Token for beta enrollment. This is the same flow as Managed OS Enforce a Specific Version. For beta targets, Iru applies Software Update Settings (beta enrollment) and then Software Update Enforcement (to the specified version) during enrollment. Use this option when the beta upgrade or update must finish before the device enrolls into Iru Endpoint. For Managed OS and Software Update Library Item options after enrollment, see Testing Apple Beta Releases.
App Preservation
For iPhone and iPad devices running iOS 26+ and iPadOS 26+, you can enable Preserve managed apps during migration so that when devices are migrated from another device management service to Iru Endpoint, any apps installed on the migrating device that are also present in the device’s new Iru Blueprint (and their associated data) remain installed and configured on the device after migration. This avoids re-downloading business-critical apps and preserves user data. Use the Preserve managed apps during migration checkbox in the iPhone and iPad device sections. For more information, see App Preservation in the Device Management Migration article. While apps are being preserved, the device can be held in Setup Assistant. See Manually release devices held in Setup Assistant if you need to end the hold early.
Mac
Customize the setup experience and configuration for Mac computers. It is recommended not to skip the Location Services unless your organization has a specific need. Location services are leveraged to set the Time Zone and other location-dependent settings.Configure Setup Assistant screens

Install Library Items during Setup Assistant (optional)

Configure Activation Lock

Configure primary account type
Provision local administrator account (optional)

Hide additional administrator account (optional)
Configure MDM-enabled user

Require minimum OS version (optional)

Specify region

Specify language

iPhone
Customize the setup experience and configuration for iPhone devices. It is recommended not to skip the Location Services unless your organization has a specific need. Location services are leveraged to set the Time Zone and other location-dependent settings.Configure Setup Assistant screens

Install Library Items during Setup Assistant (optional)

Prevent MDM profile installation when restoring from backup (optional)

Configure user-based Activation Lock
Configure device-based activation lock (optional)

Require minimum OS version (optional)

Preserve managed apps during migration (optional)

iPad
Customize the setup experience and configuration for iPad devices. It is recommended not to skip the Location Services unless your organization has a specific need. Location services are leveraged to set the Time Zone and other location-dependent settings.Configure Setup Assistant screens

Install Library Items during Setup Assistant (optional)

Prevent MDM profile installation when restoring from backup (optional)

Configure Shared iPad (optional)

Configure user-based Activation Lock
Configure device-based activation lock (optional)

Require minimum OS version (optional)

Preserve managed apps during migration (optional)

Apple TV
Customize the setup experience and configuration for Apple TV devices. Optionally configure Auto Advance, and specify the Language and Region.Configure Setup Assistant screens

Install Library Items during Setup Assistant (optional)

Specify region

Specify language

Vision
Customize the setup experience and configuration for visionOS devices.Configure Setup Assistant screens

Install Library Items during Setup Assistant (optional)

Prevent MDM profile installation when restoring from backup (optional)

Configure user-based Activation Lock
Configure device-based activation lock (optional)

Change Default ADE Blueprint
The default Blueprint can be changed at any time inside the Iru Endpoint Web App.Open Integrations

Select Apple integrations
Edit defaults
Select default Blueprint
Save changes
Enrollment Portal Link and Enrollment Code
You can also provide the Enrollment Portal link with the Enrollment code embedded in the URL for easier deployment. The format for the shareable link is listed below. The EnrollmentCodeHere portion should be the Enrollment code without the dash between the two sets of numbers.Generating a New Enrollment Code
Iru Endpoint allows you to generate a new random Enrollment code for each Blueprint. Generating a new code is helpful should the code be distributed to unauthorized users. A new code prevents unwanted devices from being enrolled into that Blueprint.Access enrollment settings
Navigate to manual enrollment
Select the Blueprint
Change the code
Distribute the new code
Troubleshooting
Migrating from previous MDM
Migrating from previous MDM
- In Apple Business or Apple School Manager, reassign the device to Iru Endpoint, then erase and re-enroll the device if you need to keep it supervised in Iru Endpoint.
- Remove management for the device in the other MDM, then use the Iru Endpoint Enrollment Portal for manual enrollment. Only macOS devices remain Supervised when you use this path.
Devices skip ADE enrollment
Devices skip ADE enrollment
Enrollment or Setup Assistant takes a long time
Enrollment or Setup Assistant takes a long time
- Remove Library Items from the Setup Assistant install list when they do not need to finish during initial setup. Large applications are the most common candidates; assign them so they install after enrollment instead.
- When downloads or installs are slow, check the device’s Wi-Fi connection, captive portal behavior, and any bandwidth limits during setup.
- If a device is stuck on Configuring, release the hold manually from the device record.
- If users are blocked because an install never completes, lower Automatically release device after (minimum 1 minute) so the device leaves Setup Assistant when the timer ends, even when not every Library Item finished. Raise the value only when you need additional time for a longer list, up to 120 minutes.
Apple-Specific Troubleshooting
Devices not visible in Apple Business or Apple School Manager
Devices not visible in Apple Business or Apple School Manager
- You purchased your devices directly from Apple.
- You may not have registered your Apple Customer Number in Apple’s portal. In Apple Business, choose Devices → Inventory, then Get Started (first number) or Add (additional numbers), pick Apple Customer Number as the type, and finish the prompts. See Manage device suppliers in Apple Business. In Apple School Manager, use Apple’s help for your region to add customer numbers linked to your organization (labels and steps can differ from Apple Business).
- To find your Apple Customer Number, check with your Apple account executive, your purchasing department, or Apple sales support. When using an Apple Customer Number, all devices purchased from Apple since March 1, 2011, will be added to your Apple Business or Apple School Manager account.
- You purchased your devices from an Apple Authorized Reseller or a carrier.
- You may not have established a link between your Apple Business or Apple School Manager account and the reseller.
- Ask your reseller for its Reseller Number (or equivalent identifier) and add it in Apple Business under Devices → Inventory using Get Started or Add, choosing the reseller number type when prompted (Manage device suppliers in Apple Business). In Apple School Manager, follow Apple’s documentation for linking resellers or carriers.
- Provide your reseller with your Organization ID. In Apple Business, open Settings → Organization and find it under Details. In Apple School Manager, locate the organization identifier in your portal using Apple School Manager documentation. Share that ID with your reseller along with the serial numbers or orders you want added to your Apple Business or Apple School Manager account. Your reseller can choose the “Look-Back” period for devices to be added.
- Your devices may not have been purchased through a Device Enrollment-enabled reseller or were not purchased as a business from Apple.
- You may not have established a link between your Apple Business or Apple School Manager account and the reseller.
Missing local files after enrollment
Missing local files after enrollment
- When disallowing iCloud Syncing and access to other iCloud features, we highly recommend informing your team before enrolling in Iru Endpoint so that they can make changes to ensure they have access to any critical data.
- The Restrictions Profile Library Item contains settings related to iCloud that may be disabling the use of various iCloud functionality.
Preferred device enrollment resellers
Preferred device enrollment resellers
- A list of Preferred Device Enrollment Resellers is available here.
Customer numbers and Apple Business or Apple School Manager
Customer numbers and Apple Business or Apple School Manager
- For information about customer numbers and adding devices to Apple Business or Apple School Manager, see Apple’s Using Automated Device Enrollment Support Article.