Return to Service feature for iOS/iPadOS
What
Even though devices can be erased remotely, getting them back into service is a manual process, as it requires someone to physically touch them and take them through Setup Assistant. Apple is removing the additional manual step with the introduction of Return to Service for iOS and iPadOS. This feature was added in in FileWave version 15.1.0 for iOS 17.0 and iPadOS 17.0.
When/Why
Return To Service is the following process. The MDM server sends an EraseDevice
command to the device. The command includes additional information which allows the device to reset, securely erase all data, connect to Wi-Fi, enroll into MDM, and get back to the Home Screen, ready to be used.
How
With FileWave 15.1.0 support of Return To Service was added. To use Return To Service open Remote Wipe dialog for iOS or iPadOS device. Checkbox Return To Service allows to specify whether feature should be enabled or disabled. It can be checked only if Remove Activation Lock checkbox is checked as well. The feature can be used only if there is at least one configured Wi-Fi profile (fileset containing Network payload with Network Interface “Wi-Fi“). Available Wi-Fi profiles are displayed on combobox.
What happens on the device?
If Return To Service is enabled on FileWave side and then Wipe Device button is pressed, the device will be wiped and then connected to the Wi-Fi network specified in selected Wi-Fi profile without asking password. Also MDM profile will remain on the device, there will be no need to download it, set creds and install (fair only for OTA enrollment, DEP profile will redirect device to the right url which asks for creds).
Related Content
Digging Deeper
When Remote Wipe dialog is opened the list of configured Wi-Fi profiles is loaded in format:
[(<file_id>, <fileset_id>, <fileset_name>, <payload_display_name>, <payload_identifier>),(...)]
fileset_id
and fileset_name
are displayed on the UI, payload_display_name
and payload_identifier
are used for tool tip. file_id
is used as internal data for combobox.
When Wipe Device button is pressed, on the backend side is generated MDM command EraseDevice with dictionary field ReturnToService
and fields Enabled
and WiFiProfileData
according to values specified on the UI, then command is added to command queue.
When command is grabbed from command queue and is being composed for sending to the device MDMProfileData
is added to ReturnToService
dictionary. This data matches the final payload that is provided by MDM server when /ios/profile URL is used for OTA enrollment. MDMProfileData
is not added for DEP devices.