Blog Post

Intune Customer Success
5 MIN READ

Apple making device migration to Microsoft Intune easy with upcoming OS 26 release

Intune_Support_Team's avatar
Intune_Support_Team
Silver Contributor
Aug 04, 2025

By: Iris Yuning Ye – Product Manager | Microsoft Intune

 

Apple recently announced a major update at their Worldwide Developers Conference 2025 that solves one of the biggest headaches for admins: migrating macOS and iOS/iPadOS devices from one mobile device management (MDM) solution to another without factory resets, manual re-enrollment, or missing configurations. With the new MDM Migration capability in macOS 26 and iOS/iPadOS 26, built directly into Apple Business Manager, IT admins are able to transition devices from third-party MDMs to Microsoft Intune seamlessly, and without user disruption. Migrating devices to Intune helps IT admins consolidate device management across platforms, enforce consistent security policies, and reduce operational complexity.

 

In this blog, learn how to start using Apple’s MDM migration feature to easily move your macOS and iOS/iPadOS fleet to Intune.

 

Prerequisite: macOS/iOS/iPadOS 26 and enrollment into a device management service is required to use the Apple MDM migration feature.

 

1. Pre-migration – preparation and set up

Pre-Migration preparation and setup steps

Before starting the migration process, there are five major steps to follow for preparation.

 

1.1 Keep a record of your devices

Start by creating a detailed inventory of all devices in your organization. This should include each device model, the version of OS it’s running, and whether it’s corporate-owned or user-owned. This step is critical because Apple’s new migration feature has specific OS version requirements. Knowing which devices are eligible helps you scope the migration accurately and avoid surprises later.

 

1.2 Document configurations in current MDM   

Before making any changes, document all existing configurations in your current MDM platform. This includes:

  • Configuration profiles: Capture all profiles related to Wi-Fi, VPN, email, and certificates. These are essential for maintaining connectivity and access post-migration.
  • Compliance policies: Note any rules that enforce password complexity, encryption, or device health checks.
  • Security baselines: Record settings such as FileVault encryption, Gatekeeper, and the macOS firewall to ensure security standards are preserved.
  • Custom scripts: List any scripts used for automation, monitoring, or maintenance tasks.
  • Deployed applications: Document all apps currently deployed, including how they’re delivered (Volume Purchase Program, App Store, or custom packages).

This documentation will serve as your blueprint for rebuilding these configurations in Intune.

 

1.3 Configure the Apple MDM push certificate

Navigate to the Intune admin center, create and upload an Apple MDM push certificate. This certificate allows Intune to securely communicate with Apple devices. Without it, device management and policy enforcement can’t function.

 

1.4 Add Microsoft Intune to Apple Business Manager (ABM) or Apple School Manager (ASM)

Next, integrate Microsoft Intune with ABM or ASM, by following these steps:

  1. Download the public key from Intune.
  2. Upload that key to ABM or ASM when creating a new MDM server.
  3. Then, download the server token from ABM or ASM and upload it back into Intune.

This allows ABM to recognize Intune as a valid MDM server and enables device assignment.

 

1.5 Set up MDM Configurations in Intune

Using the configurations documented in step 1.2, begin replicating existing configurations in Intune. This includes but is not limited to:

  • Rebuilding configuration profiles for network access and security.
  • Reapplying compliance and security policies.
  • Re-deploying applications.
  • Rewriting or importing scripts as needed.
  • Identify the other controls to implement that improves Zero Trust.

Call to action: Please make sure testing the MDM configurations on a test device before assigning them to the devices you plan on migrating. And before initiating any migration, communicate with your endpoint users first, keeping them informed to avoid any confusion.

 

2. Migration – Admin step-by-step flow

Migration – Admin step-by-step flow.

 

The admin experience starts from ABM or ASM. After logging into ABM or ASM, navigate to the Devices section. Select the device or group of devices targeted for migration to Intune. Selecting the ellipsis on the top right of device overview interface unveils the “Assign Device Management” button.

 

Apple Business Manager device overview page – Assign Device Management.

Select the server you want to migrate the device to. In our case, it’s Intune.

 

Apple Business Manager device overview page – Assign Device Management pop-up window – select device management service to migrate to.

 

Apple Business Manager device overview page – Assign Device Management pop-up window – Specify enrollment deadline.

 

Confirm device assignment.

 

Apple Business Manager device overview page – Assign Device Management pop-up window – confirm device management service change.

 

Apple Business Manager device overview page – Assign Device Management confirmation window – ABM confirms device management service update.

 

3. Migration – Endpoint step-by-step flow

Migration – Endpoint step-by-step flow.

 

After completing the device management assignment, the device user receives a notification informing them that a management change is required.

 

macOS

iOS/iPadOS

Mac device notification – management change is required.

 

iOS/iPadOS device notification – management change is required.

 

Mac device settings – Enrollment required.

 

When the user selects the notification, they are guided through a simple approval process. If the user doesn’t initiate enrollment before the admin set enrollment deadline, an enforced migration occurs, which results in a non-dismissible and full-screen prompt that must be completed by the user before using the device.

 

Regular migration

Enforced migration (past deadline)

Device enrollment kickoff page – regular migration.Device enrollment kickoff page – enforced migration (past deadline).

 

Once the user approves the migration, the device communicates with Apple’s servers to get its new device management assignment. It then downloads and installs the new MDM profile. This migration process happens without rebooting the device.

 

Device enrollment change complete notification page.

 

4. Post-migration – Verification

Lastly, verify the migration and enrollment successfully completed by navigating to the Intune admin center and confirming the new devices are listed.

 

Screenshot of the Microsoft Intune admin center showing the successful enrollment of the new macOS device.

 

Please note, it's important to have test device verifying required configurations running smoothly before migrating large number of devices and test your devices after migration to ensure everything is working smoothly. If you run into any issues, further adjustments may be needed.

 

Special thanks to our Intune MVP, Somesh Pathak, whose content we leveraged in this blog! For more details and a video demo, check out Somesh’s blog at: https://intuneirl.com/mac-admins-your-migration-glow-up-just-dropped

 

Summary

In short, Apple’s new MDM migration in macOS and iOS/iPadOS 26 makes moving Mac, iPhone or iPad devices to Intune now easier than ever.  With careful planning and a few simple steps, you can make the switch smoothly to manage your Apple devices all in one place.

 

For Mac devices that aren’t running OS 26, you can check out our Intune Github for migration scripts and review the blog Managing and migrating Macs with Microsoft Intune.

 

Let us know how your Mac journey is going by leaving a comment below, reaching out to us on X @IntuneSuppTeam, or join our Mac Admins Community on LinkedIn!

Updated Aug 05, 2025
Version 5.0

24 Comments

  • Weihao's avatar
    Weihao
    Copper Contributor

    Hi, 

    Was anyone has successfully tested "Preserving Managed Apps" feature in IOS 26 MDM migration. I did a few tests; normal migration process works great without any issue. Data in Contacts, Note, Photos was preserved after the migration, but none of the managed app was preserved, they need to be reinstalled per enrollment profile. 

    I see something from WorkspaceONE UEM today that "App Preservation" is not currently supported.

    https://community.omnissa.com/technical-blog/latest-release-from-apple-makes-moving-to-workspace-one-uem-simple-r162/

    Is this feature currently support by Intune? This is a really important feature for the MDM migration workflow. 

  • Kristian190's avatar
    Kristian190
    Copper Contributor

    We are going to migrate 400 iPads from JAMF Pro to intune. Intune is setup and connected to ABM and APNS is in place. All of iPads are i ABM and i have one test iPad with iPadOS 26 RC. When i go to ABM and lookup al Eligible iPads for Migration only a hand full shows up even though the don´t have iPadOS 26. And my test iPad with iPadOS 26 won't show up so i can set a "+ Add Deadline"

    help : )

    /Kristian

    • Intune_Support_Team's avatar
      Intune_Support_Team
      Silver Contributor

      Hi Kristian190​

       

      Thanks for sharing context, and it sounds like you're nearly there with the setup, but there may be a few things to clarify first. ABM can take some time to sync newly eligible devices, so if the update was recent, that might explain the delay if you can confirm how long it has been? Also, ensure the test iPad is correctly assigned to the Intune MDM server in ABM, and not still linked to JAMF. If none of that works, a wipe and re-enroll into ABM has helped others force eligibility, and may also help in your scenario. Let us know via DM the answers to the above with any screenshots to help us identify the issue. 

       

      Thanks!

      Intune Support Team

  • Radhamadhab's avatar
    Radhamadhab
    Copper Contributor

    Hi Team
    with this set up does the file vault key also get migrated from other mdm to ms intune ?

    suppose the device is encrypted using mdm solution like jamf and post migration does the recovery key will get escrow to MS Intune ?

    • Intune_Support_Team's avatar
      Intune_Support_Team
      Silver Contributor

      Hi Radhamadhab​ 

       

      Thanks for the question. As stated in section 1.5 of the blog, these configuration would need to be rebuilt in Intune, and once the migration is in process, the device communicates with Apple’s servers to get its new device management assignment. It then downloads and installs the new MDM profile, and the configurations created in Intune take effect. Hope this helps!

       

      Thanks!

      Intune Support Team

  • MBBG's avatar
    MBBG
    Copper Contributor

    Will this apply to changing configuration profiles within Intune? For example device A is enrolled with profile 'MacMDMOld'. If I change this to 'MacMDMNew' (which has minimal changes) will device A receive a prompt to reenrol and will there be any loss of data for the user?

    • Intune_Support_Team's avatar
      Intune_Support_Team
      Silver Contributor

      Hi MBBG​ 

       

      Thanks for the question. The answer would be no, as changing configuration profiles within Intune doesn't trigger a re-enrollment or causing data loss. The new migration feature is primarily used for migrating devices between different MDM providers, and in which case creating configuration profiles is part of the process along with enrollment as per diagram in section 3. Hope this helps!

       

      Thanks!

      Intune Support Team

  • ManleyDOA's avatar
    ManleyDOA
    Copper Contributor

    What happens if an app or policy is forgotten and not recreated in Intune first? When the ABM MDM re-assignment happens, will that app be deleted or just unusable?

    • Intune_Support_Team's avatar
      Intune_Support_Team
      Silver Contributor

      Hi ManleyDOA​ 

       

      Thanks for the question. When the new management profile takes effect, only the apps/policies specified within the migration process would take effect as per the enrollment process. If you have forgotten, you would need to re-create and assign the app/policy through Intune. Let us know if this helps!

       

      Thanks!

      Intune Support Team

    • LSAdmin_NetInsight's avatar
      LSAdmin_NetInsight
      Copper Contributor

      You should be able to assign it to the user or device group so it appears in the Company Portal, like you do now.

  • C_jucker's avatar
    C_jucker
    Copper Contributor

    We enforce MFA for device registration / intune login with Conditional access. Now when doing this MDM to MDM Migration the Authenticator app can't be used when login to the new MDM/ADE Screen. There is no way to switch to the app or anything else. Any ideas how to solve this ?

    • thalme's avatar
      thalme
      Copper Contributor

      Hi,

      Way to go is Entra TAP!

      Microsoft Entra Temporary Access Pass (TAP) simplifies device enrollment and passwordless authentication by allowing users to register devices and set up MFA methods without needing a password. TAP is a time-limited passcode that enables users to enroll in passwordless authentication and recover access to their accounts. 

      • C_jucker's avatar
        C_jucker
        Copper Contributor

        yeahh.. feared this.. this makes the migration an organizational issue.. we need to perfectly time TAPs and ensure people have them ready even when they have only one device (that is currently being migrated).. this renders the whole thing a difficult migration

  • Amonshie's avatar
    Amonshie
    Copper Contributor

    Works like charme. But: The MDM Migration Popup is only showing up if i set a migration deadline, right? If now the Apple Business Manager API would allow to not only assign a device to another mdm server and allow to set a migration deadline it would be even better.

    • Intune_Support_Team's avatar
      Intune_Support_Team
      Silver Contributor

      Hi Amonshie​ 

       

      Love to hear you're enjoying this feature, and thanks for sharing feedback to help us get even better! We'd be sure to relay this onto the relevant folks.
      That is correct, as part of the migration flow, setting a deadline is required and we hope this blog helps to instruct this action.

       

      Let us know if there's anything else we can help with. Thanks!

      Intune Support Team

       

  • egoodman's avatar
    egoodman
    Brass Contributor

    Would this work for customers who are not only moving to a different MDM but also to a new ABM instance (via a merger/aquisition/divesture)?  Is the OEM/Reseller still required to initially add/move devices into ABM?

    Similarly, what about customers who are already using Intune, but not ABM.  Would a device wipe still be required to onboard the device to ABM or could this process be leveraged?

    • Intune_Support_Team's avatar
      Intune_Support_Team
      Silver Contributor

      Hello egoodman​ 

       

      These are great questions, though ones we'd suggest reaching out to Apple to ask as the scope of migration announced in WWDC was only for devices migrating among MDM vendors, and not to another ABM account entirely. For the question about device wipe, the answer would be yes, it would still require a wipe to onboard the device.

       

      Hope this helps!

      Intune Support Team

  • Absolutely there is a time gap sync (approx. 24 hrs) - but this works perfect. 

    I have tested with multiple scenarios like different MDM to Intune and

    Intune to other different MDM and even with Intune to Intune. Without wiping the device its very much required update.

    Thanks to Apple and Microsoft 👍  for bringing this feature. 

    • Intune_Support_Team's avatar
      Intune_Support_Team
      Silver Contributor

      Hi Sanggaa_Honeywell​ 

       

      Glad to hear this feature is working for you correctly!

      We're always working to improve Intune all out, and we love to hear feedback like this where features work exactly as you would like.

      Feel free to reach out if there's anything we can help with.

       

      Thanks!

      Intune Support Team

  • FrancoisH's avatar
    FrancoisH
    Copper Contributor

    Yes…but after upgrade a device to iOS 26…migration still not available on Apple business side after 24h :) how abm sync this information with «macOS or  iOS devices ?

    • FrancoisH's avatar
      FrancoisH
      Copper Contributor

      If i wipe and re renroll i can migrate…but not so good actually than expected

      • Intune_Support_Team's avatar
        Intune_Support_Team
        Silver Contributor

        Hi FrancoisH​ 

         

        Thanks for the info, and sorry to hear it isn't working for you as expected. We'd love to hear where it's going wrong, and if the issue has been observed with multiple devices upgraded to iOS 26, or a couple? 

        Feel free to reach out to us via DM if you're able to reproduce the issue, and we can help to diagnose where the issue originates from.

         

        Thanks!

        Intune Support Team