IBM Support

DEP iOS Backup and Restore Guide

Troubleshooting


Problem

Backup and restore capabilities are among the most important features on mobile devices being used today. iOS has capabilities both in the cloud (iCloud) and on physical machines (iTunes/Finder). Backup and restore options leveraged in enterprise deployments – BYOD or company owned – often cause confusion with seemingly inconsistent behavior. It’s important to remember that, while leveraged by enterprises worldwide, these are consumer features first, and will behave accordingly. The following scenarios should help organizations understand some of the expected behavior when handling iOS data restores and device management.

Resolving The Problem

About the scenarios – The scenarios below were created based on testing two iPhones, both running the latest public version of iOS 16. 

The device and the backup are just as important as the device you are restoring data to. Restoring data to the same device (matching Serial Number) has drastically different results than restoring to a different device (non-matching Serial Number). The Serial Number is not the only factor taken in to consideration but it is the most easily identifiable. Also in each scenario, the device was enrolled using DEP with no profile restrictions or steps skipped and was listed as a Supervised profile.  

Please note the following limitations when skipping items in the DEP Profile:

  • If your new device is enrolled in Apple School Manager or Apple Business Manager, you can't use Quick Start to transfer data from your current device. More information here
  • Skipping the Restore option entirely will not allow iTunes or iCloud restores during the setup assistant
  • Skipping the Apple ID will remove iCloud restore as an option
  • Restricting iTunes pairing as part of the DEP profile will remove iTunes restore as an option
Scenarios yield the same results for both iTunes and iCloud restores, however the setup assistant will behave with slight differences due to the input of an Apple ID for iCloud. 
Device A Backup Device A Restore Device A Results
Yes Yes Settings and the enrollment profile are restored. After connecting to the internet, the device checks in with the MaaS360 for approval. If the backup has app data or enterprise books, they are also restored. App placeholders might appear if the app isn't present but its data is in the backup.
Device A Backup Device B Restore Device B Results
Yes Yes The management setup and MDM enrollment are removed during the restore. If the device's serial number is in Apple School Manager or Apple Business Manager, it checks for a management setup and applies it if found. Managed app data such as Web Clips and Enterprise Books will be restored from the backup. Data like private keys or VPN certificates linked to a specific device are unusable if restored to a different one.
Device A Backup Device B Restore Device B Results
Yes No Re-enrollment is necessary, along with data synchronization via iCloud, iTunes, or other corporate tools.

Device backups are primarily a consumer driven feature. There is no guarantee that this functionality will not change drastically in the future or even potentially become off-limits on enterprise (DEP) enabled devices. EMM services can already provide much of what the backups themselves do – placing apps, information, and configurations on the device – and much of the same content can be restored post setup with a simple iCloud sync. While IBM understands why some environments prefer using these features, IBM ultimately suggest temporarily removing control from the device and creating a iCloud or iTunes backup that does not include any management features. You can then use this backup to restore your new device. You may also re-enroll your previous device if you plan to continue using it with MaaS360,  or complete an erase from within the device settings.

For more info, please visit Backup and restore managed iPhone and iPad devices.

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSYSXX","label":"IBM MaaS360"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
28 September 2023

UID

ibm10967391