Known Issue: Profile error enrolling iOS devices with Apple Configurator
Published Dec 03 2018 04:02 PM 56.1K Views

By Lee Yan | Intune Sr. Software Engineer on the Enterprise Mobility and Customer Experience Team

 

We recently had a case escalated through all levels of support which took quite some time to troubleshoot. After working with engineering to replicate and then pinpoint the issue, we decided it would be useful to post a known issue just in case you've run into this. We'll update this post when it's resolved. 

 

The scenario: When following the steps in this document (Enroll iOS devices with Apple Configurator) for Setup Assistant enrollment, you get “Invalid Profile: The configuration for your iPad/iPhone could not be downloaded from [Your Organization Name]” error after accepting “Apply configuration” on the device.

 

What is happening behind the scenes: The enrollment URL for the MDM server created with Apple Configurator did not get resolved successfully or was manually edited. A valid URL should start with https://manage.microsoft.com/EnrollmentServer/Discovery.svc/iOS/ESProxy? while an invalid URL usually starts with https://appleconfigurator2.manage.microsoft.com/MDMServiceConfig? which is usually the original profile URL you copied from the Intune console for Setup Assistant Enrollment. The issue does not affect Direct Enrollment scenario.

 

Workaround: Fortunately, there's a relatively simple workaround. Just replace the invalid URL portion with the valid URL portion for the MDM server on the Mac computer, then try preparing the device again.

 

Again, we'll update this post when the issue is fixed. 

18 Comments
Copper Contributor

Any updates on this?

Copper Contributor

10 months later, any update on this?

Steel Contributor

@Mahmoud Taleb  @jjwb96 I noticed that the Apple Configurator will fix this in the back now. When you enter your URL, starting with  https://appleconfigurator2. it will be replaced with the correct URL prefix. You can check that in Apple Configurator under Preferences-> Servers

 

Brass Contributor

@Intune_Support_Team , i'm still getting this error even after replacing the URL? any ideas?

Copper Contributor

@Phillip Shilling I had a similar issue, the URL didn't matter. I had to connect the device to Wi-Fi then proceed.

Brass Contributor

@Mahmoud Taleb , I believe it already had an internet connection via Wi-Fi.

Hi @Phillip Shilling, if you're still experiencing this issue, here are a couple of additional items to check:

Brass Contributor

@Phillip Shilling Did you upload a CSV containing the serial and description of the device and assign a profile in Intune? https://docs.microsoft.com/en-us/mem/intune/enrollment/apple-configurator-enroll-ios#setup-assistant...

 

best regards,

 

Aad Lutgert

vmlabblog.com

Copper Contributor

Hello everyone

I have the same problem.

 

It is possible for me to access the URL.Enrollment.PNG

 

The test devices have also been assigned to the Endpoint Manager, but I do not see a connection here.devices-intune.PNG

 

On both devices I get the message "Invalid Profile"

 

Do you still have ideas for me. 

Brass Contributor

@KolKedo 

 

Just to be sure, did you double check the serials in the csv you uploaded? Are they the same as displayed on the devices?

Here is a link on how to check the serialnumber of your iOS device: https://support.apple.com/en-us/HT204073

 

 

Copper Contributor

I added the devices to the Apple Business Portal using Apple Configuration 2. And then I used the Apple Business Portal to assign the devices to the endpoint MDM server and after syncing in the endpoint manager I assigned the profiles of the endpoint manager to the devices

Brass Contributor

That should work. Have you already checked your device enrollment restrictions? Are iOS/iPadOS devices allowed to enroll?

 

best regards,

 

Aad Lutgert

vmlabblog.com

Copper Contributor

Yes i check this, it is allow: 

 

device-restrictions.PNG

Brass Contributor

@KolKedo  

 

I just tested the enrollment with my own intune tenant and it's working. As far as I can see the error you are seeing is not related to Apple configurator 2, because you have changed device management from Apple Configurator to ADE. You can also see the device appear in Intune so the Sync is working and the Token is still valid. The device is allowed to enroll, because enrollment is not blocked. So that should not be an issue. I think the issue is related to profile in ADE. You could try to create a new profile and try to assign it to the device. Otherwise I would suggest you to open a service request.

 

best regards,

 

Aad Lutgert

vmlabblog.com

 

 

 

 

 

Copper Contributor

I just got off a call with Microsoft and thought I would share a fix that worked for me. After having two iPads enroll fine I started having the same issues as described here. So the steps I have outlined fixed this issue:

Connect the iPad to a Mac running Configurator 2, run restore on the iPad, when finished, while still plugged into Configurator run through the set up on the iPad until you have connected it to the Wi-Fi network, stop there. While still plugged into Configurator run Prepare, when ready start the enrollment process on the iPad.

I would have never thought that this would work but it did. I hope this helps someone else as I have been dealing with this for two weeks on my own while waiting for a call back from MS.

Copper Contributor

Hi @BACSTECH, Could you please share more details about your answer above, regarding restoring the device and rest. I'm facing same issue for a customer now, and have already tried everything what other members suggested on this post. 

 

 

Copper Contributor

Sulfikar Ali, I was attempting to enroll an existing iPad that I have been managing with Configurator to Intunes. To do that I had to completely wipe the iPad and then prepare it in configurator so it will be added to my Apple School Manager(ASM) account. The error I received was because the iPad could not get to the internet to seek out the ASM. I have since learned that if I added a profile to load my WiFi information (I used a WiFi connection that did not require any passwords, just the SSID) on the iPad during Prepare or followed the procedure I described earlier, that it will get an internet connection allowing it to communicate with Apple.

If you describe your scenario and the message you received, I will attempt to help. I know how frustrating this can be and most of the time it is a simple correction that does the trick.

Copper Contributor

I tried all of the processes described in the previous comments, but I still received the error, however, I did manage to find another way to overcome the error, so i decided to post it here aswell.

I reset the iPad (After having restored it and trying to enroll it)

I prepared the iPad choosing "Manual Configuration" and only checking "Add to Apple School Manager or Apple Business Manager" (I would like the emphasize that I do NOT have "Activate and complete enrollment" checked. Why? Because it's just going to make it give the error again, so instead we are just adding to ABM)

After finishing "Prepare"...

I went to ABM and found the device in the list. I changed the mdm server from Apple Configurator to our Intune MDM server by clicking "Edit MDM Server" when the device was selected.

I went to Intune and synced the Enrollment Program Token that was already set up. I checked the list for the device.

I then proceeded with setup, and it enrolled without the error.

 

I came to this conclusion because I had two goals and I realized that the most necessary goal was being completed.

The goals were to add it to ABM and to enroll it in Intune.

It was adding to ABM each time I tried, so I decided to just go that far and then manually enroll it into Intune rather than use Apple Configurator to try to do it automatically.

Version history
Last update:
‎Dec 19 2023 01:23 PM
Updated by: