How to configure account driver registration?

Solved
QY
Qing Ye
meferi2023

Operation Steps:

1. Create a new driver registration policy A.

2. In Apple Business Manager, select an MDM server and register policy A as the default driver registration policy.

3. Return to the registration policy list and download the JSON file for policy A.

4. Place the JSON file in a discoverable endpoint that is the same as the domain name of policy A's AppleID account.

5. On your Apple phone: General > VPN & Device Management > Sign in to your work or school account > Enter the AppleID of policy A to log in. 

6. Return: Sorry! Your device couldn't be enrolled. Unexpected error occurred.

23 days ago
SOTI MobiControl
ANSWERS
DR
Darius Russell
23 days ago

Hi Qing Ye,

Just to confirm, have you got an APNS (Apple Push Notification Service) certificate on the portal?

Many thanks,

Darius

QY
Qing Ye
22 days ago

An APNS certificate is in place. It was observed that when creating an enrollment policy—specifically by setting it as the default policy for an ABM account and selecting an Apple Business Manager account—the downloaded enrollment JSON file includes an encoded suffix in the BaseURL (e.g., https://domain/enrollment/apple/accountDriven/userEnroll/95444d5f-e7ae-4f23-9095-0ce7eb242e9b). Placing this specific JSON file at the discovery endpoint successfully initiates enrollment. However, if the JSON is downloaded via the action menu in the enrollment policy list, or by clicking "Download JSON" on the final page while editing the policy, the resulting file lacks that suffix (e.g., 95444d5f-e7ae-4f23-9095-0ce7eb242e9b). Placing this suffix-less JSON at the discovery endpoint fails to trigger enrollment and results in an error.

K
KJMOD@soti.net
20 days ago

Hi Qing Ye,

Thanks for posting on SOTI Pulse, Thanks Darius for responding to the post, your expertise and willingness to help are greatly appreciated!

The ABM‑bound enrollment JSON that works contains a UUID suffix in the BaseURL, while the JSON downloaded from the policy list / editor lacks that suffix and therefore fails ABM account‑driven discovery. That is almost certainly the root cause — the ABM discovery flow requires the exact ABM/account token URL and won’t map a suffix‑less BaseURL to the account‑driven enrollment policy.

If you have ay further questions, feel free to reply to this post.

Thank you for choosing SOTI.

Regards,

Technical Support | SOTI Inc. |1.905.624.9828 | support@soti.net | www.soti.net

Solution
K
KJMOD@soti.net
13 days ago

Hello Qing Ye,

Could you please confirm if the previous post addresses your concern or you have any further concerns.

Thank you for choosing SOTI.

Regards,

Technical Support | SOTI Inc. |1.905.624.9828 | support@soti.net | www.soti.net