Skip to main content

DEP/ADE Forbidden Error

Description

OnWhen creating an ADE (Formerlly known asformerly DEP) Associationassociation or fromrunning any otheranother ADE synchronisationsynchronization action, the following errorFileWave may beshow observed:this error: DEP error: Forbidden.

The most likely causes are:

  • The FileWave Server SSL certificate change.changed. Check Preferences > Mobile tab to ensureconfirm that the server SSL certificate is not revoked or expired.
  • A change to theThe external IP address of the FileWave Server.Server changed.

Apple storestores the external IP address of the FileWave Server from the last successful contact. If thisthat IP address differs atduring the time of a synchronisation ,synchronization, the action willcan fail and the ADE Server Token will need tomust be replaced.

TheYou can check the stored IP mayaddress be observed fromin the relevant ADE account:

The Last Date and IP Connected may be seen fromIn the Apple portal, open Settings view;, select the MDM Serverserver, and choose Edit.Edit. The Last Date Connected and Last IP Connected values appear in the MDM Server Information view.

n1RUQ73gSehzqQt1-embedded-image-pnhjtfqf.pngn1RUQ73gSehzqQt1-embedded-image-pnhjtfqf.png

Requirements

  • FileWave MDM ADE Certificatecertificate

Resolution

A Forbidden error requires replacing the tokenADE beServer replaced andToken, not updated.updating it in place.

FromIn FileWave AdminCentral, >go to Preferences > VPP & ADE:ADE:

  1. Choose 'Download certificate'certificate (requires the fwadmin password) toand save the certificatecertificate.

FromIn the relevant Apple ADE accountaccount, Apple Business Manager or Apple School Manager:

  1. Select 'Settings'Settings.
  2. Highlight the MDM server from the list and choose Edit.
  3. Select 'Upload New...' and select the savedcertificate downloaded file from aboveFileWave.
  4. When prompted, select to download the ADE Server TokenToken.

FromBack in FileWave AdminCentral, go >to Preferences > VPP & ADE:ADE:

  1. Click 'Configure Accounts'Accounts (requires the fwadmin password).
  2. Select the Forbidden token and use the '-' button to remove that tokenit.
  3. Select the '+' button toand selectchoose the ADE Server Token downloaded from AppleApple.
  4. Run aan ADE Synchronisation Full SyncSync. (Hold downAlt/Option ALT(macOS),while Option(Windows)),choosing then select to synchronise (the namesynchronization ofaction; the button willname change)changes to indicate a full sync.

AtAfter thisthe stagetoken synchronisationis replaced and the full sync completes, synchronization should now be successful.succeed.

If the ADE Server Token is currently configured in the Education tab of Preferences, thisremove that association will need to be removed prior tobefore removing the ADE token,token. butYou maycan beadd re-addedit again afterwards.afterward.