Return to Service for Mobile Devices

Jamf Pro Documentation 11.29.0

Solution
Application
Content Type
Technical Documentation
Utilities & Services
version
11.29.0
ft:locale
en-US
vrm_version
11.29.0

Return to Service is an option within the Wipe Device remote command that automates device reset and re-enrollment. Return to Service instructs a wiped device to automatically reconnect to the Wi-Fi network and re-enroll with Jamf Pro using Automated Device Enrollment. During device reset, all Setup Assistant screens are skipped, and devices remain on the same operating system.

This process eliminates the need for manual setup because the device automatically returns to a ready-to-use state for the next user while ensuring user privacy and security. For example, if multiple students use the same iPad, you can quickly reset the iPad between students without having to manually walk through setup screens or reconnect to the Wi-Fi network.

Return to Service works with Shared iPad.

Implementing Return to Service in Jamf Pro involves the following main steps:

  1. Create a mobile device configuration profile that includes a Wi-Fi payload.

  2. Enable the Return to Service option for the Wipe Device remote command in a PreStage enrollment and select the Wi-Fi configuration profile.

  3. Include the Return to Service option when sending the Wipe Device remote command to mobile devices.

Requirements
  • Mobile devices enrolled with Jamf Pro using Automated Device Enrollment through Apple Business or Apple School Manager

  • Mobile devices with iOS 17 or later, iPadOS 17 or later, tvOS 18 or later, visionOS 26 or later

  • A mobile device configuration profile with a Wi-Fi payload

  • No Enrollment Customization Configuration selected
    Note:

    Return to Service will fail if an enrollment customization configuration is selected in a PreStage enrollment. If you are configuring Return to Service in an existing PreStage enrollment with an enrollment customization configuration, ensure it is removed before proceeding.

  • Activation Lock disabled. If Activation Lock is enabled on the devices, clear Activation Lock by doing one of the following:
    • (Recommended) Select the Clear Activation Lock checkbox and the Return to Service checkbox within the same Wipe Device command.

      Note:

      Jamf does not recommend sending a Wipe Device command using only the Clear Activation Lock option if you want to return the device to service. This action will remove the device from management in addition to erasing all content and settings.

    • Sign out of iCloud on the device. Signing out of iCloud effectively disables Activation Lock, which is helpful if user-based Activation Lock was allowed and Find My was signed in.

    • Send the Set Activation Lock remote command, and select the Disable and prevent Activation Lock checkbox.

  1. In Jamf Pro, click Devices in the sidebar.
  2. Click Configuration profiles in the sidebar.
  3. Create a configuration profile with a Wi-Fi payload. For instructions, see Configuring Wi-Fi for Mobile Devices.

    Configure the settings for your Wi-Fi network as needed. If your environment requires an enterprise security type with an 802.1x RADIUS server, you can add additional payloads to accommodate additional network configuration settings.

  4. Create or edit a PreStage enrollment. For instructions, see Creating or Editing a PreStage Enrollment.
  5. In the PreStage enrollment settings, select the Allow use of the Return to Service option during device reset checkbox.
  6. Click the Wi-Fi configuration profile pop-up menu, and select the name of the configuration profile that contains the Wi-Fi payload.
  7. (Optional) (iOS 26, iPadOS 26, and visionOS 26 only) Select the checkbox for Preserve Managed Apps to preserve all managed apps on the device.
    Note:

    Keep the following in mind when using the Preserve Managed Apps function:

    • A bootstrap token for the device must be escrowed with Jamf Pro.
    • Managed apps must remain scoped to the device.
    • If you select the Preserve Managed Apps checkbox, devices with iOS 26 or later or iPadOS 26 or later that are enrolled using the PreStage enrollment will not be able to install software updates. Managed software updates can be used to update these devices on an ongoing basis if they are erased and re-enrolled using a PreStage enrollment without the Preserve Managed Apps checkbox selected. For more information, see Manage software and app updates with Return to Service in Apple Platform Deployment. Software updates can also be enforced during Automated Device Enrollment by configuring a minimum required OS version in PreStage enrollments.
  8. Click Save .
  9. Send the Wipe Device remote command to a single device or multiple devices:
    Note:For Apple Vision Pro devices, you can initiate the Return to Service workflow directly from the device by selecting "Reset for Next User" in Control Center.
  10. In the Wipe Device dialog, select the Return to Service during device reset checkbox.
  11. (Optional) Select the checkbox for Preserve Managed Apps in the Wipe Device dialog.

The Wipe Device command is sent to the target devices.

Return to Service instructs a device to perform the following actions:

  1. Reset using the Erase All Content and Settings feature.

  2. Securely wipe all data.

  3. Cache the Wi-Fi configuration profile and remove the MDM profile.

  4. Restart.

  5. Apply the previously configured language and region settings.

  6. Install the Wi-Fi configuration profile.

  7. Reconnect to Wi-Fi.
    Note:

    If Wi-Fi is unavailable, devices can also connect to the Internet via an alternate method, such as a tethered connection.

  8. Re-enroll with Jamf Pro using the configured PreStage enrollment and install the MDM profile.
    Note:

    If your PreStage enrollment is configured with minimum OS enforcement settings, the settings will not be applied and devices will complete enrollment without requiring an update. Devices remain on the previously installed operating system.

  9. Display the Home Screen. The device is now ready for the next user.