Menu

Use the Apple Device Enrollment Program

The Apple Device Enrollment Program (DEP) allows you to quickly and easily enroll a large number of organization-owned Apple devices. Devices added by DEP enroll automatically without user intervention with the configured device management profiles.

NOTE — Apple has announced a new consolidated platform called Apple Business Manager. Visit their website to learn more about how to upgrade from DEP.

To enroll devices using DEP, the following procedures must be performed.

A diagram demonstrating the Apple Device Enrollment Program flow

Before using the Apple Device Enrollment Program

To use the Apple DEP properly, you must meet the following prerequisites:

  • Prepare a device from an Apple store, Apple authorized reseller, or carrier.
  • Make sure the devices are running iOS 10 or higher.
  • Register for an Apple Business account in Apple Business Manager or upgrade from DEP. To learn more about upgrading from DEP to ABM, see https://support.apple.com/en-us/HT208817.

Issue a DEP token

To use the Apple DEP, you must request for a DEP token issued by Apple through a public key, and then set up DEP in the KM console.

To issue a DEP token and set up DEP:

  1. Go to Setting > iOS > DEP Server Setting. If you have issued a DEP token before, the previously issued DEP token's information and its expiration date are displayed.
  2. On the DEP Server Setting page, click Download Public Key to download a public key in the .pem format required to create a new MDM server in the Apple DEP Portal.
  3. Visit the Apple Business Manager website at https://business.apple.com.
  4. Sign in using your Apple Business account, and then enter the 6-digit verification code sent to the mobile device registered to your Apple ID. The start window of the ABM site opens.
  5. On the Apple Business Manager website, go to Settings > Device Management Settings at the bottom of the site, and then click Add MDM Server on the right of the screen.
  6. Configure the MDM server settings, upload the public key file in the .pem format downloaded from the KM console, and then click Save.
  7. Click Download Token on the right of the screen and download the Apple token file in the P7M format on to the computer.
  8. NOTE — We recommend using a single token to enroll the DEP devices for one organization or company.
  9. On the DEP Server Setting page of the KM console, click Upload DEP Token and then select the DEP token file with P7M format downloaded from ABM.
  10. Click OK. If the DEP token file is uploaded successfully, the authentication processes between the Knox Manage server and the Apple's DEP server is completed.
  11. Click Set Default Profile to set up a profile to be assigned to the DEP devices by default, and then click OK.
  12. NOTE — For more information on setting a general profile, see Setting DEP profiles.
  13. Click Set DEP Device Sync Interval to set the sync interval of DEP devices.

Register DEP devices

After the DEP server is all set up, you can register iOS devices on Apple Business Manager website with either your authorized reseller or Apple Configurator app downloaded from your macOS computer.

To register iOS devices in the Apple Business Manager website:

  1. Before you begin, you must sign in to Apple Business Manager with your Apple ID, and add the KM server to Preferences > Organizations and Servers tabs on the Apple Configurator app.
    TIP — For the KM server URL, add /ios/depenroll after the KM admin console URL.
  2. Connect iOS devices to your PC. The devices should be reset.
  3. Select the device to enroll and click Prepare.
  4. On the dialog that opens, select Manual Configuration > Add to Apple School Manager or Apple Business Manager, and Allow devices to pair with other computers and then click Next.
  5. Select the Knox Manage server and click Next.
  6. Select the organization and click Next.
  7. Choose the Setup Assistant options you want to show to the device users, and click Next and then Prepare on the next dialog.
  8. The device activating dialog opens. The activation process takes about 10 minutes to complete.
  9. After the configuration process on Apple Configurator, proceed to use the setup assistant on the device. Make sure to sign in with Apple ID so that the Knox Manage agent is activated and the VPP apps are installed.

Fix Knox Manage agent installation issues

In some cases, during DEP enrollment the device fails to install the Knox Manage agent. If the device user later manually installs and authenticates the Knox Manage agent, the Knox Manage server doesn't recognize the device as belonging to the DEP.

To prevent this issue, you can optionally install the Knox Manage agent to devices by adding and assigning it as a Volume Purchase Program app. Doing so ensures that after the Knox Manage agent is reinstalled, the Knox Manage server registers the device with the DEP.

Set DEP profiles

After the iOS devices are registered to the Apple Business Manager website, you must set the DEP profile to be assigned to the devices through the KM console.

The DEP profile is applied to the DEP devices when the DEP devices are enrolled.

IMPORTANT — After you sync your DEP devices from ABM to KM, you can't re-sync the DEP profile. If the profile isn't configured or configured incorrectly, you must reconfigure it, factory reset the iPads, and then resync them.

To set a DEP profile:

  1. Go to Setting > iOS > DEP Server Setting.
  2. On the DEP Server Setting page, click Set DEP Default Profile.
  3. On the Set DEP profile window, set the following items in the DEP profile:

    • Supervised Mode — Click the check box next to Apply to enable the supervised mode that is only available on iOS devices and must be applied to the DEP devices.

      • Delete MDM profile — Click the check box next to Allow to allow users to delete the MDM profile.
      • Supervising host certificate list — Click Add to add the registered certificate to the Apple device you want to pair with the DEP devices.
      • Shared iPad — If you want to enroll all your DEP devices as Shared iPads, set to Apply. Then, configure the Shared iPad settings:

        • Partition Type — Choose whether to divide the users' partitions on the device's local storage by the expected number of Resident Users or by a fixed Quota Size (in MB).
        • Expected Number of Resident Users — If you divide the local storage by number of users, enter how many expected users will share this device.
        • Maximum Size (MB) for Each User — If you divide the local storage by partition size, enter the size of each user's parition, in MB.
        • Temporary Session Only — Select Allow if your Shared iPads will only be used for temporary (guest) sessions without assigned users.
        • Temporary Session Timeout (Seconds) — Enter how long a temporary session can stay inactive before it ends.
        • User Session Timeout (Seconds) — Enter how long a user session can stay inactive before it ends.
        • Passcode Lock Grace Period (Seconds) — Enter how long the screen can stay locked before the user must enter a passcode or password to unlock the iPad.
    • Pairing — Click to allow other Apple devices to pair with the DEP devices.
    • Skip Settings — Select the screens to hide in the first-time device setup flow. For a list of screens that can be skipped, see List of skip settings.
  4. Click Save to save the set DEP profile.

Set DEP device names

Follow this procedure if you want to prefix the DEP device names with the user IDs. Prefixes only apply the devices after you apply this setting.

  1. Go to Setting > iOS > DEP Server Setting.
  2. Click DEP Device Name.
  3. Choose the format you want to use for the DEP device names.
  4. Click Save.

Assign users to DEP devices

After the DEP devices are enrolled, you can assign users to them. You can either add single users or add users in bulk to DEP devices.

Add single users to DEP devices

To assign users one at a time:

  1. Go to Setting > iOS > DEP Device Management.
  2. On the DEP Device Management page, click the check box for a device you want to assign the user to.
  3. Click Assign User.
    • Click Unassign User to remove the user assignment from the device. The device must be unenrolled before unassigning the user.
  4. On the Select User window, click the user you want to assign to the device, and then click OK. After the user is successfully assigned, you can send device commands just as you would with other devices controlled by Knox Manage.

Bulk add users to DEP devices

To assign users in bulk:

  1. On the KM console, go to Device enrollment > Apple DEP > DEP Device Management.
  2. On the DEP Device Management screen that opens, click Bulk Assign Users.
  3. On the Bulk Assign Users page that opens, click Download Template to download an xls file with a template that you can customize.
  4. Customize and save the downloaded template file, and then return to the Bulk Assign Users screen to upload it to KM admin console.
  5. Click OK. The users in the uploaded file are added to DEP devices.

Manage DEP devices

On the KM console, the DEP devices registered in the DEP are managed. You can synchronize with the DEP server in the Apple Business Manager website to update the DEP device list in the KM console, modify and assign DEP profiles, and control DEP devices.

View the DEP device details

To view the DEP device details in the KM console:

  1. Go to Setting > iOS > DEP Device Management.
  2. On the DEP Device Management page, click the serial number of the desired DEP device on the list to view its details.
  3. In the Device Detail window, view the selected DEP device information.

Synchronize with the DEP server

To synchronize with the DEP server and the Apple Business Manager website to update the DEP device list on the KM console:

  1. Go to Setting > iOS > DEP Device Management.
  2. On the DEP Device Management page, click Sync DEP to synchronize with the DEP server.
  3. On the DEP device sync window, click OK. The DEP device list on the KM console updates.
NOTE — If the server token has expired, you can no longer update the DEP device list.

Modify and assign DEP profiles

To modify and assign DEP profiles to DEP devices:

  1. Go to Setting > iOS > DEP Device Management.
  2. On the DEP Device Management page, click the check boxes next to the DEP devices on the DEP device list, and then click Set DEP profile to modify the DEP profile.
  3. On the Set DEP profile window, modify the desired DEP profile items, and then click Save to save the set DEP profile and return to the DEP Device Management page. For more information on setting the DEP profiles, see Set DEP profiles.
  4. Click Sync DEP to synchronize with the DEP server to update the DEP device list. The modified DEP profile assigns to the DEP devices.

Select DEP enrollment method

To set an enrollment method for your DEP server:

  1. On the left hand navigation menu, go to Device Enrollment > Apple DEP > DEP Server Setting.
  2. On the DEP Server Settings page, click DEP Enrollment Method.
  3. On the DEP Enrollment Method page, click to choose one of the following two options:

    • User Assignment — Use this option to assign device users to DEP device before KM enrollment.
    • User Authentication — For this option, device users directly enter their user ID and password upon enrollment.
  4. Click OK to save your settings and return to the DEP Server Setting page.

Unenroll DEP devices

If you want to use DEP devices as general iOS devices or if the DEP devices are no longer required, you can unenroll the DEP devices in the Apple Business Manager website.

To unenroll DEP devices:

  1. Visit the Apple Business Manager website at https://business.apple.com, and then enter your Apple ID and password to log in.
  2. On the Apple Business Manager website, go to Settings > MDM Servers.
  3. On the Server Details page, click an MDM server to disable and delete it, and then click Edit > Delete MDM Server.
  4. In the popup window, click OK. All the DEP devices on the MDM server are deleted.
  5. NOTE — To delete the MDM server and relocate the DEP devices on this server, select Reassign Devices from the drop-down list. Then, select a different MDM server where you want to relocate the MDM devices to and click Delete.
  6. On the KM console, go to Setting > iOS > DEP Device Management.
  7. On the DEP Device Management page, click Sync DEP to synchronize with the DEP server.
  8. In the DEP device sync window, click OK. The DEP device list in the KM console updates according to the DEP server, and the DEP devices on the DEP server in the KM console are deleted.

List of skip settings

You can skip the following screens in the first-time setup flow for DEP devices:

  • Locale
  • Location Service
  • Region
  • Siri
  • Keyboard
  • iPhone Analysis
  • Touch ID
  • Display Zoom In/Out
  • Apple Pay
  • Home Button
  • Passcode
  • True Tone
  • App and data
  • Watch Migration
  • Move from Android
  • Apple ID
  • Privacy
  • SIM Setup
  • iMessage And FaceTime
  • OnBoarding
  • Screen Time
  • Software Update
  • Appearance
  • App Store
  • Device To Device Migration
  • Messaging Activation Using Phone Number
  • Restore Completed
  • Terms and Conditions
  • Update Completed
  • Welcome