Enrolling a Device with Your MDM
Enrolment happens by scanning a QR code your device management system produces. It must be performed on a device in its factory-fresh state, which is the requirement most often overlooked.
Before you start
Get the enrolment token from whoever runs your MDM. It is a large, dense QR code. It is not something you can generate on the device.
Make sure the token carries staging Wi-Fi credentials. The device cannot be put on Wi-Fi by hand before enrolment, so the network details have to be inside the code. A token without them will scan and then stall.
A staging network is a plain WPA network with a name and a password and nothing else. A phone hotspot works well. A guest network with a sign-in page will not, and neither will a corporate network with tight firewall rules. You can forget the staging network once enrolment is finished.
Step 1: reset the device, if it has been used
Skip this if the device is new out of the box.
- Say "MY PROGRAMS", then "ADVANCED SETTINGS".
- Say "SYSTEM", then "RESET OPTIONS".
- Choose the option to erase all data.
- Confirm it. The device asks twice, deliberately.
The device erases itself and restarts. Everything on it is gone, so make sure anything worth keeping is off it first.
Step 2: scan the token
The device starts on its first-run setup.
- Choose a language. The volume buttons move through the list and the Action Button confirms.
- Work through the setup screens until you reach the option to scan a code.
- Say the command to start scanning and hold the enrolment token in front of the camera.
- Centre the whole code in view. If the code is large, zoom out to get all of it in frame.
The device downloads the management app and works through the enrolment screens. Accept the prompts as they appear.
Enrolment stalls at the download step
The device has failed to join the staging network. Check the following, in this order.
The Wi-Fi name and password inside the token. This is the most common cause. The device cannot prompt you to correct it, because the network settings are no longer editable before the code is scanned.
The kind of network. A guest network that requires a sign-in page will not work, because nothing on the device can complete that sign-in. Neither will a corporate network with restrictive firewall rules. The staging network needs to be a plain WPA network with a name and a password and nothing else.
The network itself. Confirm another device can reach the internet through it.
Correct whichever applies and scan the token again.