Apple requires every DEP (Automated Device Enrollment) server token (.p7m) to be renewed once a year. If it lapses, devices stop syncing with Apple Business Manager (ABM) and freshly unboxed Macs/iPads won’t auto-enroll. Trio flags the token 30 days before expiration and walks you through a quick three-step wizard.
Before You Start
APNs certificate must be active.
If APNs is missing or expired, renew it first—DEP can’t work without push-notification traffic.Use the same Apple ID you created the token with. A different Apple ID = a brand-new token = broken device link.
Renewal Flow
Open the renewal modal
MDM Setup → Apple → Automated Device Enrollment (DEP) → Renew Token.
A pop-up shows:Click Start Renewal — the side panel opens:
① Download Server-Token Request (Public Key)
② Go to Apple Business Manager
Link in the wizard launches https://business.apple.com.
In Settings → MDM Servers, click the existing Trio server → Edit.
Upload the
...publickey.pem, then click Save → Download Token to grab the fresh.p7m.
③ Upload your Server Token back to Trio
Drag-and-drop the
.p7mfile (or Upload) in Step 3.Click Confirm Renewal.
Green confirmation toast — “DEP token renewed. Device sync and automatic enrollment will continue without issue.”
What happens if you miss the window?
Already-enrolled devices stay managed, but no new devices can enroll via DEP.
ABM-to-Trio inventory sync stops (serial numbers & assignment states freeze).
Renewing after expiration is identical to the steps above—just expect a brief gap in new-device automation.
Troubleshooting Tips
Symptom | Fix |
Upload button greyed out | Ensure the file extension is |
Status shows “Not Connected” after upload | Wait up to 10 min. If still disconnected, re-upload the same |
Accidentally used wrong Apple ID | Create a new MDM server in ABM with the correct Apple ID, download its token, then upload to Trio. Reassign devices in ABM to the new server. |
Keep Ahead of Expiration
Trio emails Org Admins at 30, 15, 7, and 1 day before the token lapses. Add a calendar reminder or set a Slack/Teams alert so you never scramble on launch-day.



