Before you begin
Let's get your iPad set up so you can get to work right away. Watch the video in each section, then follow along.
Check your personal email for an email from mission-control@squareup.com — it contains a temporary link to set your initial Block password. Follow the prompts to create your password, then close that window and come back here.
The full Okta Verify setup is covered in the next section of this guide. Continuing it from the email will cause issues with your setup.
Install the Okta Verify app on your personal phone before proceeding.
Set up Okta Verify on your phone
Your first login happens on your personal phone using the Okta Verify app. Follow these steps to add your Block account.
Open Okta Verify on your phone and tap the + icon near the top of the screen to add a new account.
On the "Choose Account Type" screen, select Organization (Work, school, company).
On the "Add Account from Another Device?" screen, tap Skip. On the next screen asking about a QR code, tap No, Sign In Instead — a QR code cannot be used at this step.
Enter login.block.xyz as your organization's sign-in URL, then tap Next.
Enter your Block username (e.g. jsmith), then enter your Okta password when prompted.
If your phone supports biometrics, tap Enable to set up Face ID confirmation. This protects your account when signing in via Okta Verify.
You should see an "Account Added — @block.xyz" confirmation screen like the one below. Keep the app installed — you'll need it to sign in.

Set up your iPad
Power on your new iPad and walk through the initial configuration to enroll it into Block's device management.
Turn on the iPad and select your preferred language, country/region, and appearance (Light or Dark Mode).
When prompted, select Set Up Without Another Device, then connect to a Wi-Fi network.
After connecting to Wi-Fi, the Remote Management screen should appear automatically. Tap Enroll this iPad.
Contact mission-control@squareup.com and include the Asset Tag (6-digit number on the back of the iPad) and the Serial Number.
Enter your Block username and password. When prompted for authentication, select Get a Push Notification, then on your personal phone choose the number that matches the one displayed on the iPad.
The iPad will enroll into device management, install required configurations, and apply security settings and policies. Allow several minutes for this to complete. Once finished, you'll be prompted to set up Touch ID and create an iPad passcode.
Enable Location Services and select your preferred display mode. Then go to Settings → General → Software Update and make sure iPadOS is fully up to date before proceeding.
Add Okta Verify on the iPad
Open the Okta Verify app on the iPad.
Tap Add Account, select Organization, then choose Add Account from Another Device. A QR code will appear on the iPad.
In Okta Verify on your phone, tap the > arrow next to your login.block.xyz account, scroll down, and select Add Account to Another Device. A QR code appears on your phone — scan it with the iPad.
Set up Cloudflare One (VPN)
Open the Cloudflare One app on the iPad.
Cloudflare One may take some time to appear. Do not install it manually via Self-Service. The same applies to Slack EMM.
Follow the prompts to install the VPN profile and tap Allow when prompted. You may be asked for your iPad passcode. Once completed, the VPN connects automatically.
Gmail and applications
Open the Gmail app, select Google, tap Continue, enter your Block email address (e.g. johndoe@block.xyz), and complete Okta verification when prompted.
Use the Self-Service app to download approved applications and install updates.
Please contact your lead.
Your Block iPad is fully configured. You now have access to Block email, VPN connectivity, and approved applications. Setting up a laptop as well? Head to Select your device.
iPad FAQ
Common questions about your Block iPad setup and day-to-day use.
Quick start
What do I need before I start setting up my Block iPad?
Set your initial Block password first, and have Okta Verify already set up on a personal or Block-issued device.
How do I start setting up the iPad?
Follow the steps on this page, starting from Before you begin at the top.
Common questions
Can I use Google Chrome on a Block-issued iPad?
No. Chrome is not currently available on Block-issued iPads because it does not support the required device certificates on iOS. Safari is the supported browser.
Can I open go-links on a Block-issued iPad?
Not in the same way as on laptops or Block-issued iPhones. On iPads, enter the full URL in Safari instead.
What can I access from a Block-issued iPad?
You should be able to access Block email, VPN, and approved applications once setup is complete.
My VPN app or Slack EMM is missing during setup. What should I do?
Wait a bit first. Cloudflare One and Slack EMM may take time to install automatically during setup — do not install them manually via Self-Service.
I forgot my iPad passcode. Can IT unlock it?
IT may be able to send a passcode wipe command, but the iPad must have internet access for that to work. If it's connected, email mission-control@squareup.com with the Asset Tag and Serial Number.
- If the iPad is not connected to Wi-Fi and has no cellular data, put it into DFU mode and reset it using Apple's steps: support.apple.com/en-gb/119858
- After the reset, re-enrol by following this page again from the top
I cannot access Block apps after setup. What should I check first?
Check that the device finished enrollment, Cloudflare One is connected, Okta Verify is configured on the iPad, and the iPadOS version is fully up to date.
Apps and access
How do I download apps on a Block-issued iPad?
Use the Self-Service app to download approved apps and install updates.
What if the app I need is not in Self-Service?
Please contact your lead.
Can I use the App Store?
No, the App Store is blocked. Only use the Self-Service app.
Which apps are usually needed on day one?
The main first-day apps are Okta Verify, Cloudflare One, Gmail, and Self-Service for approved apps and updates.
How do I access my Block email on the iPad?
Open the Gmail app.
How do I get VPN access?
Open Cloudflare One and install the VPN profile. The app may take a little time to appear automatically — do not install it manually from Self-Service.
Get help from the IT team in real time; the meeting link is in your welcome email. Ireland & UK: 9:00–10:00 AM GMT · US East: 10:00 AM–12:00 PM ET · US West: 10:00 AM–12:00 PM PT.