# Apple Re-enrollment — Clean Install

> Re-enroll an Apple device without keeping the apps, groups, and configurations it had before.

Source: https://docs.capaone.com/capaone/enrollment/apple-re-enrollment-clean-install/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

:::note[Important]
**Read Before Starting**
If you are re-enrolling an Apple device and you do **not** want it to keep the same apps, groups, and configurations as before, you must **delete the device from CapaOne before starting the enrollment again**.
:::

## Re-enrolling device without existing apps and configurations

1. Find the iPad/iPhone in [Capaone.com](https://Dash.capaone.com)
2. go to the device page,
3. click on the three dots. and select **Request-> Wipe**

![Device action menu with Wipe option in CapaOne](/attachments/capaone/apple-device-wipe-action-menu.png)

After this the device will reset to factory settings and is ready to be enrolled again.
When the Device is enrolled again it will be a clean install.

## If the device certificate is broken

A device whose MDM certificate has broken or expired can no longer receive the remote **Wipe** command, so the procedure above never completes. A common symptom is DEP re-enrollment that hangs at the Entra ID sign-in step. Erase the device by hand instead:

1. Find the device in [Dash.capaone.com](https://Dash.capaone.com) and open its device page.
2. Click the three dots and select **Delete endpoint data**. This removes the endpoint record in CapaOne without needing a working connection to the device.
3. On the device itself, go to **Settings → General → Transfer or Reset iPhone/iPad → Erase All Content and Settings**.
4. Enroll the device through DEP as usual. See [Apple Enrollment](/capaone/enrollment/apple-enrollment/).

The device now appears in CapaOne as a newly enrolled endpoint.

:::caution[Deleting endpoint data is not reversible]
**Delete endpoint data** removes the device's history in CapaOne. The device re-enrolls as a fresh device and does not keep its previous groups, apps, or configurations. If you want to keep those and the certificate still works, use [Apple Re-enrollment — Keep Profiles and Apps](/capaone/enrollment/apple-re-enrollment-with-existing-profiles-and-apps/) instead, which does not delete the endpoint.
:::

If you hit this certificate error across many devices at once, the cause is more likely an Apple Business Manager or DEP token problem than a fault on each device. See [Apple DEP Integration](/capaone/mobile-manager/apple-mdm/apple-dep-integration/).

## Related

- [Apple Re-enrollment — Keep Profiles and Apps](/capaone/enrollment/apple-re-enrollment-with-existing-profiles-and-apps/) — re-enroll while keeping groups, apps, and configurations
- [Apple Enrollment](/capaone/enrollment/apple-enrollment/) — enroll an Apple device from scratch
- [Apple DEP Integration](/capaone/mobile-manager/apple-mdm/apple-dep-integration/) — connect Apple Business Manager and renew the DEP token
- [Apple Endpoints Overview](/capaone/mobile-manager/apple-mdm/apple-endpoints-overview/) — find a device and its available actions
- [Integrate CapaOne with Entra ID](/capaone/integrations/integrate-capaone-with-entra-id/) — the sign-in step DEP enrollment depends on
