Category filter

Enrollment of Apple devices through ADE

ADE or Automated Device Enrollment (previously known as Device Enrollment Program or DEP) is Apple’s enrollment method to enroll organization-owned Apple devices into MDM. ADE follows a zero-touch approach for setting up and pre-configuring devices, allowing Apple devices to be automatically enrolled in the MDM as soon as they are powered on for the first time. This is made possible by leveraging the capabilities of Apple Business Manager (ABM) or Apple School Manager (ASM).

Apple Business Manager is a web-based platform designed to integrate with MDM systems, enabling efficient management and deployment of Apple devices within your organization. Apple has combined the capabilities of ADE and the legacy VPP (Volume Purchase Program) into ABM, streamlining device and app management. Apple also has Apple School Manager (ASM) to manage devices in an educational institution.

ABM helps in deploying devices in bulk by automatically applying settings and configurations upon the initial device start-up, making it ready for use right out of the box. Over-the-air supervision of devices is possible only if these devices are enrolled in ABM. ABM provides a unified interface to enroll and supervise enterprise-owned Apple devices. ABM requires an MDM solution to supervise it remotely.

Notes:

Configuring ADE with Hexnode

  1. Log in to your Hexnode portal.
  2. Go to Enroll > Platform – Specific > iOS/macOS/tvOS >Apple Business/School Manager.
  3. Note:


    You can also configure ADE with Hexnode from Admin > Apple Business/School Manager > Automated Device Enrollment.

  4. Click Next.
  5. Enter a name for the ADE account and download the certificate file.
  6. Go to Apple Business Manager and sign in to your account.
  7. Click on the account name at the bottom of the left side panel and navigate to Preferences.
  8. Click Add.
  9. Provide an MDM Server Name and upload the Certificate file you downloaded in Step 4.
  10. Click on Save.
  11. Then, click Download MDM Server Token to download a new server token. After downloading the token, you’ll need to upload it to the Hexnode server.
  12. Go back to the MDM ADE settings page and upload the token you have just downloaded. Then, configure the below options:
    • Add as Pre-approved device: Enable this option to add the ADE devices as pre-approved devices.
    • Default Configuration Profile: Select an already created ADE enrollment profile, or you can also create a new enrollment profile.

      Note:


      To view or edit any created enrollment profiles, either go to Enroll > Platform–Specific > iOS/macOS/tvOS >Apple Business/School Manager > Enrollment Profiles or Admin > Apple Business/School Manager > Automated Device Enrollment > Enrollment Profiles.

Assign devices to the Hexnode server

Perform the following steps to assign the ADE devices to the MDM server:

  1. Log in to your Apple Business Manager account.
  2. Click Devices. Search and select the required devices from the list. You can filter devices based on their source, order numbers, device types, etc.
  3. On the top-right portion of the screen, click on the horizontal ellipsis button. Then, click on Edit MDM Server.
  4. Next, click on Assign to the following MDM option and select the MDM server to assign the devices to that server.

Note:


You can also set Hexnode as the default MDM server in ABM to automatically assign newly purchased devices to it. To set Hexnode as the default MDM server on ABM, go to Settings > Device Management Settings > Default device assignment.



Once you’ve assigned devices, you can view several device assignment details in ABM such as serial numbers, order numbers, date of assignment, name of the MDM server, the total number of devices, and so on. On your Hexnode UEM portal, the assigned devices will be listed under Enroll > All Enrollments > No-Touch > Apple Business/School Manager > Devices. If the devices do not appear here, click Sync with ADE to sync with Apple Business Manager.

What happens at the device end?

The configuration settings associated with the device are deployed as soon as the device starts up. Once the user turns on the device, the Apple server pushes the ADE enrollment profile associated with the device. It initiates device enrollment. For devices already in use, these configurations will be applied after the factory reset. Thus, you have to perform a factory reset on an already activated device to get it enrolled in MDM.

Troubleshooting tips

  • Enrolling Devices
  • Managing iOS Devices