Device Actions
This page covers the Device Actions that are accessible from the Actions button in the Device Details screen.
Available Device Actions will vary by device type, enrollment type/method, and Supervision status, and in some cases, the SimpleMDM plan you are on.
There are additional actions that can be taken from other sections of a Device record documented in our Device Management documentation section.
Mac Device Actions
The following is a list of all potentially available Device Actions that can be taken from the Actions dropdown on macOS hardware enrolled in SimpleMDM. Items marked with an asterisk (*) are not in the Actions dropdown, but are instead accessed from the info panel on the Device Details page; they are included here for completeness.
| Device Action | Functionality |
|---|---|
| Refresh Inventory | Requests updated information from the Mac, subject to Rate Limiting |
| Push Assigned Apps and Media | Installs Apps and Media assigned to the device |
| Enable and Disable Remote Desktop | Enables/Disables Apple Remote Desktop access (Apple Remote Desktop is a separate paid application available in the Apple App Store). Supervised Macs only |
| Lock | Sends a Lock Device command to the target, with additional options depending on hardware specifics |
| Enable/Disable Bluetooth | Available on Supervised devices only. Use caution when deploying "Disable Bluetooth" as it will disconnect connected devices on command arrival |
| Disable Activation Lock | Only available on devices with Activation Lock enabled. Additional information on Activation Lock can be found in Apple's Platform Deployment Documentation |
| Trigger Enhanced Logging | Sends an AppleCare-provided token to a supervised Mac running macOS 27+ to start enhanced diagnostic log collection and upload for an AppleCare case |
| Wipe |
Only available on hardware enrolled via Automated/Device Enrollment. Depending on hardware model this will either fully erase the drive on the target Mac, or remove everything outside of the base operating system Be Advised: this is a highly destructive command and will result in data loss |
| Restart | Reboots the target Mac. Please see the full article at Device Action: Restart Device for in depth information on the command |
| Re-Install SimpleMDM Munki |
Re-installs the built in SimpleMDM Munki configuration that manages Shared Apps to the target Mac. Please see the full article at Device Action: Re-Install SimpleMDM Munki for in depth information on the command and when to utilize it Please note: certain legacy SimpleMDM account types do not have access to Shared Apps and SimpleMDM Munki tooling. Please use our Contact Us page if you would like to discuss upgrading your SimpleMDM instance |
| Run Script |
Takes you to the "Create Job" page to assign a Script to run on the target Mac. Please note: certain legacy SimpleMDM account types do not have access to Scripts. Please use our Contact Us page if you would like to discuss upgrading your SimpleMDM instance |
| Unenroll |
Unenrolls the Mac from SimpleMDM and removes the Device Management Profiles from the target Mac. Does not unassign hardware from Automated Enrollments associated with Apple Business or Apple School Manager accounts. Please note: Unenrolled devices are still billed. |
| Remove | Sends an Unenroll command to the target Mac and removes the Device record from the Devices page. Device Secrets will be moved to a Deleted Device record that can be found at https://a.simplemdm.com/admin/deleted_devices on your SimpleMDM instance |
| Rotate FileVault Recovery Key* | Generates a new FileVault recovery key for the Mac. Only available when a FileVault recovery key is present |
| Clear Firmware Password* | Removes a firmware password configured on the Mac. Only available when a firmware password is set and can be cleared |
| Set Admin Password* | Sets a local admin account password on the Mac |
| Rotate Admin Password* | Generates a new local admin account password on the Mac. Only available when an admin password is set |
| Clear Recovery Lock Password* | Removes the Recovery Lock password on Apple Silicon Macs. Only available when a Recovery Lock password is set and can be cleared |
Mobile Device Actions
The following is a list of available Device Actions that can be taken from the Actions dropdown menu of an iPhone, iPad, Apple TV, or Apple Vision Pro Device page in SimpleMDM. Not every action is available on every platform; platform restrictions are noted below.
| Device Action | Functionality |
|---|---|
| Refresh Inventory | Requests updated information from the target device, subject to Rate Limiting. Available on iPhone, iPad, Apple TV, and Apple Vision Pro |
| Push Assigned Apps and Media | Installs Apps and Media assigned to the device. Available on iPhone, iPad, Apple TV, and Apple Vision Pro |
| Send Message |
Allows you to send a Message to the target device. Message length is a maximum of 255 characters. Only available on iPhone/iPad with the SimpleMDM for iOS App installed, please see Device Action: Send Message for a complete list of requirements |
| Enable/Disable Lost Mode |
Places the device into Lost Mode, allowing for a message, phone number, and a footnote to be displayed while locking device functionality. Supervised iPhone/iPad enrolled via Automated Enrollment only, please see Device Action: Enable Lost Mode for complete details |
| Lock |
Locks the device. Allows you to send a Message and contact Phone Number to be displayed on the device. Available on iPhone and iPad only. Please see Device Action: Lock device for complete details. |
| Enable/Disable Bluetooth | Available on supervised iPhone/iPad only. Use caution when deploying "Disable Bluetooth" as it will disconnect connected devices on command arrival |
| Disable Activation Lock | Only available on supervised iPhone/iPad enrolled via Automated/Device Enrollment with Activation Lock enabled. Additional information on Activation Lock can be found in Apple's Platform Deployment Documentation |
| Clear Passcode | Removes the passcode currently on the device, unlocking it if it was locked locally. Available on iPhone, iPad, and Apple Vision Pro enrolled via Automated/Device Enrollment |
| Clear Restrictions Password | Removes the Restrictions passcode from the device. Available on iPhone/iPad enrolled via Automated/Device Enrollment |
| Trigger Enhanced Logging | Sends an AppleCare-provided token to a supervised iPhone, iPad, or Apple TV running OS 27+ to start enhanced diagnostic log collection and upload for an AppleCare case |
| Wipe |
Erases all data on the device, causing it to reinitialize. Only available on hardware enrolled via Automated/Device Enrollment. Available on iPhone, iPad, Apple TV, and Apple Vision Pro Be Advised: this is a highly destructive command and will result in data loss |
| Restart | Reboots the device. Available on supervised iPhone, iPad, and Apple TV enrolled via Automated/Device Enrollment. Please see the full article at Device Action: Restart Device for in depth information on the command |
| Shut Down | Shuts down the device without prompting the user. Available on supervised iPhone/iPad enrolled via Automated/Device Enrollment only; not currently available for Apple TV |
| Set Time Zone | Sets the device's time zone remotely. Available on iPhone, iPad, and Apple TV |
| Refresh Cellular Plan |
Adds or updates an eSIM cellular plan on the device using a carrier URL obtained from your cellular provider. Available on cellular-capable iPhone/iPad For more information on managing eSIMs, see Apple's documentation |
| Unenroll |
Unenrolls the device from SimpleMDM and removes the Device Management Profiles from the target device. Does not unassign hardware from Automated Enrollments associated with Apple Business or Apple School Manager accounts. Please note: Unenrolled devices are still billed. |
| Remove | Sends an Unenroll command to the target device and removes the Device record from the Devices page. Device Secrets will be moved to a Deleted Device record that can be found at https://a.simplemdm.com/admin/deleted_devices on your SimpleMDM instance |