Category filter
Apple’s Automated Device Enrollment
Automated Device Enrollment (ADE) streamlines the deployment of your corporate Apple devices into an MDM environment. Once a device is activated, it is immediately configured, eliminating the need for the IT team to configure it physically. The following documentation shall explain how to use Apple Business Manager with Hexnode.
Automated Device Enrollment Settings
The following steps are to be followed to integrate Hexnode with Apple Business Manager for device enrollment.
- Go to Enroll > All Enrollments > No-Touch > Apple Business / School Manager.
- Create an ADE Account and download the certificate file.
Here an ADE server token file is required which is to be uploaded to the portal.
Follow the steps below to download a server token:
-
- Log in to Apple Business Manager page.
- Click your name at the bottom left of the screen, and go to Preferences > MDM server assignment.
- Click on Add MDM Server button and name the server.
- Upload the public key obtained from the MDM console while setting up ADE and click Save.
- Click on Download Token.
- Log in to the Hexnode portal. Upload the downloaded server token and click on Next and Finish.
Renew the ADE Server Token
Apple ADE Server tokens need to be renewed every year. Therefore, renew the ADE token before the previous one expires.
Pre-approve DEP synced devices
To add ADE-enrolled devices as Pre-approved devices, check the option Add as Pre-approved Device under ADE Settings.
Apple ADE Devices
Under Enroll > All Enrollments > No-Touch > Apple Business/School Manager > Devices, you can view the list of enrolled devices with ADE. The list will include information such as the serial number, model along with the enrollment profiles applied to the device, if any.
Associate profiles with devices
- Select the device.
- Click on the Associate Enrollment Profile button at the top. The following window pops up.
- Search for the profile you want to associate to the device and then click on Assign.
Sync with Apple Device Enrollment Program
To import devices enrolled in the configured Apple ADE account to the Hexnode portal you have to initiate an ADE sync.
Go to Enroll > All Enrollments > No-Touch > Apple Business/School Manager > ADE Devices > Sync with ADE.
Enrollment Profile
With Hexnode UEM, you can configure Enrollment Profiles and associate it with devices enrolled in Apple’s ADE. By navigating to Enroll > Platform-Specific > iOS/macOS/tvOS > Apple Business/School Manager > Enrollment Profiles, you can view, edit or create new enrollment profiles.
You can also edit the profile on this page and save it again.
Add a new profile
- Navigate to Enroll > Platform-Specific > iOS/macOS/tvOS > Apple Business/School Manager.
- Go to Enrollment Profiles.
- Click on Create Enrollment Profile.
- Fill out all the necessary fields and click on Save.
The following screen pops up with detailed information about the profile.
The following parameters are available to configure in Enrollment profiles:
-
General Settings
By adjusting the general settings of an enrollment profile, you can configure device settings, choose the authentication mode for enrollment, manage activation lock settings, and set a custom EULA, among other options.
The following fields lets you fill in the basic details related to the enrollment profile,
- Display name – A display name of the enrollment profile.
- Department – Name of the department to which the devices are assigned.
- Support Phone Number – A contact number for users to reach out to if they need help during setup.
- Support Email Address – An email address for the users to request support during setup.
Device Settings
- Edit device name: Select this setting to edit the device name for the devices to be enrolled. Enter the name for the device in the field provided.
- Append number: Select this setting to append numbers to the device name specified under the Edit device name setting. Enter the name for the device in the field provided.
- Enroll devices in MDM: Enabling this option prevents users from bypassing “Remote Management” during initial device setup screen.
- Enable Supervision: Check this option to make the device supervised upon enrollment.
- Allow MDM Profile Removal: Check this to make the profile removable after device enrollment. If disabled, users will be blocked from manually removing the MDM profile from the device.
- Allow iTunes pairing: Check this option to allow users to sync their devices with iTunes. Disabling this option will prevent every iTunes related action. To re-enable it, the device will have to be wiped and re-enrolled.
Authentication
Choose the authentication method to be used for enrollment. The following options are available,
- No authentication: When selected, the admin must choose the Domain and a Default user (available within the chosen domain) to assign the device.
- Enforce Authentication: When selected, admins must choose the type of users to be enrolled (AD/Microsoft Entra ID/Local/OKTA/Google user). Users will be required to enter their directory or local credentials while enrolling the device.
Activation Lock
- Device-based Activation Lock: Enable this option to enforce device-based activation lock on the enrolled devices. The device-based Activation Lock is enabled by Hexnode and is associated with the Managed Apple Account of the user that created the MDM server token in ABM.
- User-based Activation Lock: Enable this option to enforce User-based Activation Lock on the enrolled devices. Users can enable activation lock on their devices using the credentials of their personal Apple Accounts.
Custom EULA
- Choose EULA: Select the necessary EULA. The available options are None, Custom T&C, and Terms of Use.
-
Account Creation
Managed Admin Account
Using the settings given below you can configure and set up a managed admin account on the devices during the enrollment procedure.
- Create managed admin account: Enable this option to automatically create the managed admin account on the device during device enrollment.
- Choose admin account: Choose an admin account to set up on the device. You can select an admin account from the drop-down if one was already set up during the configuration of previous enrollment profiles. You can also create a new admin account on the device by clicking on +Create new Account and fill in the details in the fields described below.
- Full name : Enter the full name of the admin account.
- Password : Enter the password for the admin account.
- Account name : Enter the account name for the admin account.
- Hide account from Login Window and Users & Groups: If this option is enabled, the account will be hidden from System Preferences > Users & Groups on the user’s Mac. Enabling this option will also hide the account name and only display the password prompt on the login window.
Local User Account Creation
Configure this setting to enforce users to create a local account during the device setup process. The following settings are available:
- Account type: Choose the account type for local account creation. The available options are Administrator, Standard or you can choose Skip account creation.
- Autofill user’s full name: Enable this option to auto-populate Full name and Account Name for the local user account with the admin credentials specified under Managed Admin Account.
- Lock user’s full name: If enabled, Full name and Account name of the user cannot be edited during account creation.
- Create managed admin account: Enable this option to automatically create the managed admin account on the device during device enrollment.
-
Setup Assistant
Hexnode UEM allows you to configure which panes are shown to the user in the Setup Assistant screen. You can also choose to skip the screen entirely.
- Automatically advance through Setup Assistant: If enabled, the Setup Assistant screen will be skipped during enrollment.
- Default Language: Set the default language for the device.
- Default region: Set the default region.
- Don’t show the selected steps: With Hexnode you can have a customized setup experience for your ABM enrolled devices. Check the boxes corresponding to steps that you want to avoid during Apple devices’ setup.
Available options
All ADE DevicesSetUp Assistant Options Supported versions Description Apple ID - iOS 7.0+
- tvOS 10.2+
- macOS 10.9+
Skip Apple ID setup. Biometric - iOS 8.1+
- macOS 10.12.4+
Skip biometric setup. True Tone Display - iOS 9.3.2+
- macOS 10.13.6+
Skip True Tone Display pane. Apple Pay - iOS 8.1+
- macOS 10.12.4+
Skip Apple Pay setup. Restore - iOS 7.0+
- macOS 10.9+
Disable restoring from backup. Screen Time - iOS 12.0+
- macOS 10.15+
Skip the Screen Time pane. Appearance - iOS 13.0+
- macOS 10.14+
Skip the Choose Your Look window. Diagnostics - iOS 7.0+
- tvOS 10.2+
- macOS 10.9+
Skip sending diagnostic information to Apple. Location Services - iOS 7.0+
- macOS 10.11+
Skip setting up Location Services. Privacy - iOS 11.3+
- tvOS 11.3+
- macOS 10.13.4+
Skips the privacy pane. Siri - iOS 7.0+
- tvOS 10.2+
- macOS 10.12+
Disable users from configuring Siri. Terms and Conditions - iOS 7.0+
- tvOS 10.2+
- macOS 10.9+
Hide terms and conditions from the user.
iOS onlySetUp Assistant Options Supported versions Description Move from Android iOS 9.0+ Remove Move from Android option from the Restore pane. Keyboard iOS 11.0+ Skip the Keyboard pane. Watch Migration iOS 11.0+ Skip the screen for watch migration. iMessage and Face Time iOS 12.0+ Skip the iMessage and FaceTime screen. Passcode iOS 7.0+ Hides and disables the passcode pane. SIM Setup iOS 12.0+ Skip the add cellular plan pane. Onboarding iOS 11.0+ Skip on-boarding informational screens. Software Update iOS 12.0+ Skip the mandatory software update screen. Home Button Sensitivity iOS 10.0+ Skip the Home Button screen. Device to Device Migration iOS 13.0+ Skip Device to Device Migration pane. Zoom iOS 8.3+ Skip the Zoom pane which shows larger text and controls. Welcome/Get Started iOS 13.0+ Skip the Get Started pane.
macOS onlySetUp Assistant Options Supported versions Description FileVault macOS 10.10+ Disable FileVault Setup Assistant screen. iCloud Storage macOS 10.13.4+ Skip iCloud Documents and Desktop screen. iCloud Analytics macOS 10.12.4+ Skip the iCloud Analytics screen. Registration macOS 10.9+ Prevent users from filling out the registration form and send it to Apple.
tvOS onlySetUp Assistant Options Supported versions Description Screen Saver tvOS 10.2+ Skip setting up screen saver. TV Home Screen Sync tvOS 11.0+ Skip TV home screen layout sync screen. Where is this Apple TV? tvOS 11.4+ Prevent user from selecting the room for the Apple TV. Set up your Apple TV tvOS 10.2+ Prevent users from configuring their Apple TV. Sign In to your TV provider tvOS 11.0+ Skip the TV provider sign in screen. - Automatically advance through Setup Assistant: If enabled, the Setup Assistant screen will be skipped during enrollment.
-
App Packages
To install required app packages on the device during the enrollment procedure,
- Click on Configure.
- Click on +Add to either add an app or a group of apps from the app inventory.
- Select the necessary apps and click on Done.
-
Shared Device Settings
You can configure the settings for shared iPads using the options below,- Enable shared device: Select this option to enable the shared device mode.
- Configuration mode: Configure whether the device allows multiple users or allows temporary sessions only. There are two modes available:
- User mode
- Guest mode
The settings available to configure under User mode are the following,
- Allocate storage based on: Select the method by which the storage allocation per user will be decided. There are two options available:
- Number of users
- Per-user quota
- Expected number of users (for Number of users): Set the expected number of users. The available storage will be equally distributed amongst the specified number of users.
If any additional space is needed for a new user, the local data for the oldest user is removed. - Per-user quota (for Per-user quota): Specify the storage quota allocated to each user. If any additional space is needed for a new user, the local data for the oldest user is removed.
- Domains: Specify the domains to be displayed on the iPad login screen.
- Skip Language and Locale: If enabled, the Language and Locale will be picked by the system for a new user.
- Auto-Lock: Set the period of inactivity after which the device will be locked automatically.
- User timeout: Set the period of inactivity after which the user is logged out.
- Guest timeout: Set the period of inactivity after which the guest is logged out.
- Require Authentication: Specify the period after which a user is required to complete an online authentication (against Apple’s identity server).
- Passcode grace period: Specify the period up to which a user can unlock their account without using passcode.
The settings available to configure under Guest mode are the following,
- Auto-Lock: Set the period of inactivity after which the device will be locked automatically.
- Guest timeout: Set the period of inactivity after which the guest is logged out.
-
Associate Policy
You can configure the devices by associating policies during the device enrollment procedure.- Click Configure.
- Next, click on +Associate Policy.
- Select the required policies and click on Done.
View the details of any profile
- Navigate to Enroll > Platform-Specific > iOS/macOS/tvOS > Apple Business/School Manager.
- Go to Enrollment Profiles.
- Click on the name of the enrollment profile.
- The following screen pops up with detailed information about the profile.
You can also edit the profile on this page and save it again.
ADE Enrollment
If you have a non-activated device, start setting it up and get it connected to the internet. If you have an already activated device, reset the device to its factory settings and then activate it. Once it is connected to the internet, the user will be prompted to enable remote management for the device. This will enable MDM administration on the device. Note that the user can bypass this process if “Enroll Devices in MDM” is not enabled on the ADE Enrollment Profile.
Multiple ADE Account Management
You can configure multiple ADE accounts in Hexnode. So, even if your Apple devices are registered to different ADE accounts, you can enroll them in Hexnode by configuring all the ADE accounts in the Hexnode portal.
To configure multiple ADE accounts,
- Go to Enroll > All Enrollments > No Touch > Apple Business/School Manager > ADE Accounts.
- Click on Add ADE Account.
- Follow the same procedure to complete the configuration.
To sync all ADE accounts to Hexnode, click on Sync all ADE accounts. This will automatically import all the devices associated with the ADE accounts to Hexnode.