Failed to install payload 'AppWhiteBlackListSection' in profile 'JTI', because the device is not supervised.

Solved
HE

Dears, I am trying to enroll new IPAD device , but it enrolled partially ,check the below message,

when i check the log i found a message says : (Failed to install payload 'AppWhiteBlackListSection' in profile 'JTI', because the device is not supervised.)

5 years ago
iOS
ANSWERS
RC
Raymond Chan Diamond Contributor
5 years ago

If you device has not been added into your organization account in Apple's Device Enrollment Program (DEP), it is not an enterprise device and any previous "supevised" mode will be cleared when the device is wiped (factory reset).

If your company/organization has no DEP account, you should use Apple's Configurator 2.5+ utility running on MacOS machine to switch your device to supervised mode first before enrolling to Soti MobiControl. 

Solution
J
JCMOD@SOTI Platinum Contributor
5 years ago

Hi Hamza,

Thank you for posting in SOTI Central.

Can you double-check that your device is supervised? That is a prerequisite for this to Profile Configuration to work.

How to check:

Web Console -> Click Device -> Device Details -> Look for "Device Statuses" -> Check "Supervised" row.

Regards,

HE
Hamza Elayan JTI
5 years ago

Dears,

Status says NO , its not supervised , it was supervised before i do WIPE  action on it .

Thank you, i will check it from my side .

Regards;

HE
Hamza Elayan JTI
5 years ago

Thank you Raymond,  i dont have DEP account , i will do it manually .

Many thanks 

 
RC
Raymond Chan Diamond Contributor
5 years ago (edited 5 years ago)

You are welcome. Please note that though you can use the more advanced MDM policies once your non-DEP device has been manually switched to supervised mode,  there is a big security loophole by design that the MDM profile is not locked and can therefore be deleted from Settings tab  by any device end-user (whether the actual end-user or a thief/hacker holding the device) at any time.   

Thus, Apple highly recommends enterprise owned devices having high security requirements to be added under the their DEP program, which supports locking of MDM profiles on the devices.   Recently, Apple requires all DEP devices running their latest firmware to be "supervised".  From the series of ever-tightening security requirements from Apple in the last few years,  I have strong reasons to believe that within the next 1-2 years,  most, if not all, enterprised-grade policies will be availalble only to DEP devices.  As it might take weeks or even months to get the DEP account ready, I suggest your company/organization to apply for such account a.s.a.p.