Bypass iCloud/Activation Lock using XenMobile

Bypass iCloud/Activation Lock using XenMobile

book

Article ID: CTX226806

calendar_today

Updated On:

Description

An end user may return an iOS device to the I.T. department and does not supply their iCloud account information. After a restore, the I.T. department cannot enroll the device as the device cannot be unlocked without iCloud credentials.

XenMobile can issue a 'Activation Bypass Code' as per Apple MDM APIs.

Note: 
1. This applies only to iOS devices that are Supervised, via Apple Configurator or Apple DEP.
2. The MDMOptions policy must be deployed BEFORE user enters their iCloud / activates Find My iPhone.

This article cannot be used if the iOS device do not meet these conditions


Instructions

Assumptions:
  1. Assure the iOS device you are utilizing is ready to be enrolled and is supervised.
  2. Start by applying the device policy named 'MDM Options' from the XenMobile console. Simply toggle the option to be enabled as seen in the screenshot below.
User-added image
  1. Push the policy to your DEP and/or supervised delivery group.
  2. Once done, proceed with enrolling your iOS device. Proceed with entering the iCloud information
  3. Once the device starts to pull down its assigned policies and apps, the device should have the ability to turn on 'Find my iPhone'
  4. When this option is enabled, the admin will notice the 'Activation Lock Enabled' option set to 'Yes' on the device management page for the device just enrolled.
  5. Whilst viewing the enrolled device in the XM Admin console, a new Device Property will be present, labeled 'Activation Lock Bypass Code'.  This field provides a code that admins can later use to bypass the iCloud setup when restoring a device.
User-added image
  1. If the bypass code field is not viewable in XMS, be sure to click the three dots all the way to left of the device table and choose 'Activation Lock Bypass Code' to add it as a field
User-added image
  1. If the code does not appear, click the device and choose 'Secure'. You will see an option labeled 'Activation Bypass'. Click on this and XenMobile will send a request to the device to generate the bypass code.

Note: When the iCloud login interface appears once after restoring this device, there is no longer need to enter an e-mail addres/user. Instead use the bypass code seen in the XM Admin Console.

Issue/Introduction

This article details how to use the 'Activation Bypass Code' to be able to use iOS devices that are iCloud/Activation locked and unable to re-enroll in to Xenmobile

Additional Information

MDM Options Device Policy: http://docs.citrix.com/en-us/xenmobile/server/policies/mdm-options-policy.html

Apple MDM API Reference: https://developer.apple.com/library/content/documentation/Miscellaneous/Reference/MobileDeviceManagementProtocolRef/4-Profile_Management/ProfileManagement.html

Apple Activation Lock: https://support.apple.com/en-us/HT202804