Skip to content

Apple Re-enrollment — Clean Install

Re-enrolling device without existing apps and configurations

Section titled “Re-enrolling device without existing apps and configurations”
  1. In CapaOne, find the iPad/iPhone under Apple → Endpoints.
  2. Open the device page.
  3. Click the three dots and select Request → Wipe device.

Device action menu with the Request submenu open and Wipe device highlighted in CapaOne

After this the device will reset to factory settings and is ready to be enrolled again. When the Device is enrolled again it will be a clean install.

Wipe device is available only for supervised devices. For an unsupervised device, use the procedure in If the device certificate is broken: delete the endpoint data in CapaOne and erase the device from its own settings.

A device whose MDM certificate has broken or expired can no longer receive the remote Wipe command, so the procedure above never completes. A common symptom is DEP re-enrollment that hangs at the Entra ID sign-in step. Erase the device by hand instead:

  1. In CapaOne, find the device under Apple → Endpoints and open its device page.
  2. Click the three dots and select Delete endpoint data. This removes the endpoint record in CapaOne without needing a working connection to the device.
  3. On the device itself, go to Settings → General → Transfer or Reset iPhone/iPad → Erase All Content and Settings.
  4. Enroll the device again, through DEP or with an enrollment profile. See Apple Enrollment.

The device now appears in CapaOne as a newly enrolled endpoint.

If you hit this certificate error across many devices at once, the cause is more likely an Apple Business Manager or DEP token problem than a fault on each device. See Apple DEP Integration.