Skip to main content

Renew Automated Device Enrollment (DEP) Token

Renew your Apple DEP server token: Download public key, upload in Apple Business Manager, download new .p7m, upload to Trio.

Apple requires every DEP (Automated Device Enrollment) server token (.p7m) to be renewed once a year. If it lapses, devices stop syncing with Apple Business Manager (ABM) and freshly unboxed Macs/iPads won’t auto-enroll. Trio flags the token 30 days before expiration and walks you through a quick three-step wizard.


Before You Start

  1. APNs certificate must be active.
    If APNs is missing or expired, renew it first—DEP can’t work without push-notification traffic.

  2. Use the same Apple ID you created the token with. A different Apple ID = a brand-new token = broken device link.


Renewal Flow

  1. Open the renewal modal
    MDM Setup → Apple → Automated Device Enrollment (DEP)Renew Token.
    A pop-up shows:

    • Apple ID tied to the current token

    • Exact expiration date & days remaining

  2. Click Start Renewal — the side panel opens:

    ① Download Server-Token Request (Public Key)

    • Trio generates trio-mdm-publickey.pem. Save it locally; you’ll upload it to ABM.

    ② Go to Apple Business Manager

    • Link in the wizard launches https://business.apple.com.

    • In Settings → MDM Servers, click the existing Trio server → Edit.

    • Upload the ...publickey.pem, then click SaveDownload Token to grab the fresh .p7m.

    ③ Upload your Server Token back to Trio

    • Drag-and-drop the .p7m file (or Upload) in Step 3.

    • Click Confirm Renewal.

  3. Green confirmation toast“DEP token renewed. Device sync and automatic enrollment will continue without issue.”


What happens if you miss the window?

  • Already-enrolled devices stay managed, but no new devices can enroll via DEP.

  • ABM-to-Trio inventory sync stops (serial numbers & assignment states freeze).

  • Renewing after expiration is identical to the steps above—just expect a brief gap in new-device automation.


Troubleshooting Tips

Symptom

Fix

Upload button greyed out

Ensure the file extension is .p7m and under 8 MB.

Status shows “Not Connected” after upload

Wait up to 10 min. If still disconnected, re-upload the same .p7m and click Confirm Renewal again.

Accidentally used wrong Apple ID

Create a new MDM server in ABM with the correct Apple ID, download its token, then upload to Trio. Reassign devices in ABM to the new server.


Keep Ahead of Expiration

Trio emails Org Admins at 30, 15, 7, and 1 day before the token lapses. Add a calendar reminder or set a Slack/Teams alert so you never scramble on launch-day.

Did this answer your question?