Jump to:navigation, search
Wiki





























De.png
En.png
Fr.png






Enrollment of iOS / iPad devices with Apple's Device Enrollment Program (Apple DEP)
New article with version: 1.24
Last updated: 
04.2024
notempty
This article refers to a Resellerpreview
Access: portal.securepoint.cloud  Mobile Security iOS/iPadOS Devices

Introduction

This HowTo describes the enrollment of iOS / iPad devices in the Securepoint Mobile Security Portal. This integrates these iOS / iPad devices into the Securepoint Mobile Device Management (MDM) portal.
The configuration of the device profile and the assignment of the user profile and the apps can already be carried out, even if the iOS / iPad device is not yet with the end customer.
As soon as the iOS / iPad device is activated and connected to the Internet for the first time, these configurations are automatically downloaded and installed.


Requirement

  • iOS / iPad device with iOS 15 or higher
  • iOS / iPad device must be registered in Apple Business Manager.
    • If it was purchased from a DEP dealer, the dealer enters the device in the Apple Business Manager
    • If it was purchased from another retailer, you enter the device yourself in the Apple Business Manager
  • An Apple DEP profile must be available





























Requirements

The following requirements are necessary:


MSP v1.5.3 Infos DEP-Token-en.png

Establish connection to DEP (Device Enrollment Program)

Um Apples DEP (Device Enrollment Program) nutzen zu können, muss eine Verknüpfung des Securepoint Mobile Security Portals mit dem Apple DEP hergestellt werden.

The connection is done in three steps at  Mobile Security Settings Apple DEP  Add profile
1. download the Apple push certificate (*.pem file)
2. upload this certificate in the Apple Business Manager or Apple School Manager menu Settings

  •  ABM: If no corresponding MDM server has been created yet:
  •  ABM: Menu Settings/ Organization Settings / ABM Einstellungen Geräteverwaltung Icon.PNG Device Management Settings / ABM MDM-Server Icon.PNG] Add MDM server
  •  ABM: MDM Server Name Unique name
  •  ABM: MDM Server Settings Select File: Upload the .*.pem file previously downloaded from the Securepoint Mobile Security Portal and Secure
  •  ABM: Selection of the corresponding MDM Server ABM Einstellungen MDM-Server Icon.PNG ttt-point-mdm-Server-123456.sms
  •  ABM: Download the dep token ABM Token Icon.PNG Load token (*.p7m file) in the Apple Business Manager or Apple School Manager in the menu

3. upload the *.p7m file in the dial window opened under point 1 in the Securepoint Mobile Security Portal. Finish with  Done

notempty
DEP tokens have a term of 12 months and must be updated regularly!


Problem / Error message Cause Solution
DEP token has become invalid
  • The account of the Aple Business Manager or Apple School Manager user who created the token is locked or deleted.
  • The ABM/ASM user who created the token has changed his/her password
Renew DEP token with a valid account
Message when logging in to https://portal.securepoint.cloud :
Check your Apple business account
We retrieved an error while fetching your data from Apple
This could happen due to updated software license agreements.
Please check your apple business account, for further information.
Apple has changed its T&Cs. Login to Apple Business Manager or Apple School Manager and confirm the new terms and conditions.
  •  Mobile Security Settings Apple DEP Setting Enable Apple Re-Enrollment must be active   

Enrollment

notempty
The enrollment procedure described here only works with DEP devices.
Enrollment for Non-DEP devices is described in the following wiki article.
MS 1.24 iOS Geräte Enrollment-en.png
The details of the device tile of the placeholder profile.
The name can be customized.
If the above requirements for the iOS / iPad device are met, a placeholder device profile tile appears under  Mobile Security iOS/iPadOSdevices .
  • this has the labels new, DEP and logged out
  • Required configurations of apps, tags and users can be made and assigned to the placeholder
  • When the iOS / iPad device is started for the first time and has established an Internet connection, it automatically downloads the placeholder device profile
  • The placeholder device profile tile is then automatically replaced by the device tile of the iOS / iPad device
    The labels of the device tile are adjusted accordingly. The logged out label is then no longer displayed
      .

The enrollment of the iOS / iPad device in the MDM portal is complete.


Re-Enrollment

notempty
The re-enrollment described here only works for DEP devices.
MS 1.24-Einstellungen-Apple-DEP-en.png
Apple Re-Enrollment must be active under  Mobile Security Settings .
If the MDM profile of an enrolled iOS / iPad device has been deleted (e.g. due to a factory reset), this device can be reintegrated into the MDM portal without having to be re-enrolled.


Once the device is back in operation and connected to the Internet, it automatically downloads the configurations from the MDM portal.

notempty
Requirement:
  • Enable Apple re-enrollment is active   
    see above. Requirement
      
  • The profile used for the device under  Mobile Security iOS/iPadOS  Profiles is available and has not been deleted
    The label logged out is displayed on the profile tile