Menu

Use the Apple Device Enrollment Program (iOS devices only)

The Apple Device Enrollment Program (DEP) allows you to quickly and easily enroll a large number of organization-owned Apple devices. Devices added by DEP will be enrolled automatically without user intervention with the configured device management profiles.

NOTE—Apple has announced a new consolidated platform—Apple Business Manager. Visit their website to learn more about how to upgrade from DEP.

To enroll devices using DEP, the following procedures must be performed.

Before using the Apple Device Enrollment Program

To use the Apple Device Enrollment Program (DEP) properly, you must meet the following prerequisites:

  • Prepare a device from an Apple store, Apple authorized reseller, or carrier.
  • Make sure the devices are running iOS 10 or higher.
  • Register for an Apple Business account in Apple Business Manager or upgrade from DEP. To learn more about upgrading from DEP to ABM, see https://support.apple.com/en-us/HT208817.

Issuing a DEP token

To use Apple Device Enrollment Program (DEP), you must request for a DEP token issued by Apple through a public key, and then set up DEP in the Knox Manage Admin Portal.

To issue a DEP token and set up DEP, complete the following steps:

  1. Navigate to Setting > iOS > DEP Server Setting. If you have issued a DEP token before, the previously issued DEP token’s information and its expiration date are displayed.
  2. On the DEP Server Setting page, click Download Public Key to download a public key in the .pem format required to create a new MDM server in the Apple DEP Portal.
  3. Visit the Apple Business Manager website at https://business.apple.com.
  4. Sign in using your Apple Business account, and then enter the 6-digit verification code sent to the mobile device registered to your Apple ID. The start window of the ABM site opens.
  5. On the Apple Business Manager website, navigate to Settings > Device Management Settings at the bottom of the site, and then click Add MDM Server on the right of the screen.
  6. Configure the MDM server settings, upload the public key file in the .pem format downloaded from the Knox Manage Admin Portal, and then click Save.
  7. Click Download Token on the right of the screen and download the Apple token file in the .p7m format on to the computer.
  8. NOTE—We recommend using a single token to enroll the DEP devices for one organization or company.
  9. On the DEP Server Setting page of the Knox Manage Admin Portal, click Upload DEP Token and then select the DEP token file with .p7m format downloaded from ABM.
  10. Click OK. If the DEP token file is uploaded successfully, the authentication processes between the Knox Manage server and the Apple’s DEP server is completed.
  11. Click Set Default Profile to set up a profile to be assigned to the DEP devices by default, and then click OK.
  12. Note—For more information on setting a general profile, see Setting DEP profiles.
  13. Click Set DEP Device Sync Interval to set the sync interval of DEP devices.

Registering DEP devices

After the Device Enrollment Program (DEP) server is all set up, you can register iOS devices on Apple Business Manager website with either your authorized reseller or Apple Configurator app downloaded from your MacOS PC.

To register iOS devices in the Apple Business Manager website, complete the following steps:

  1. Before you begin, you must sign in to Apple Business Manager with your Apple ID, and add the KM server to Preferences > Organizations and Servers tab on the Apple Configurator app.
    TIP — For the KM server URL, add /ios/depenroll after the KM admin console URL.
  2. Connect iOS devices to your PC. The devices should be reset.
  3. Select the device to enroll and click Prepare.
  4. On the dialog that opens, select Manual Configuration > Add to Apple School Manager or Apple Business Manager, and Allow devices to pair with other computers and then click Next.
  5. Select the Knox Manage server and click Next.
  6. Select the organization and click Next.
  7. Choose the Setup Assistant options you want to show to the device users, and click Next and then Prepare on the next dialog.
  8. The device activating dialog opens. The activation process takes about 10 minutes to complete.
  9. After the configuration process on Apple Configurator, proceed to use the setup assistant on the device. Make sure to sign in with Apple ID so that the Knox Manage agent is activated and the VPP apps are installed.

Setting DEP profiles

After the iOS devices are registered to the Apple Business Manager website, you must set the DEP profile to be assigned to the devices through the Knox Manage Admin Portal.

The DEP profile is applied to the DEP devices when the DEP devices are enrolled.

To set a DEP profile, complete the following steps:

  1. Navigate to Setting > iOS > DEP Server Setting.
  2. On the DEP Server Setting page, click Set DEP Default Profile.
  3. On the Set DEP profile window, set the following items in the DEP profile:
    • Supervised Mode—Click the check box next to Apply to enable the supervised mode that is only available on iOS devices and must be applied to the DEP devices.
      • Delete MDM profile—Click the check box next to Allow to allow users to delete the MDM profile.
      • Supervising host certificate list—Click Add to add the registered certificate to the Apple device you want to pair with the DEP devices.
    • Pairing—Click to allow other Apple devices to pair with the DEP devices.
    • Skip Settings—Select the items that appear during the device setup process after users turn on their DEP devices for the first time. If the items are checked, they do not appear on the window.
  4. Click Save to save the set DEP profile.

Setting DEP device names

Follow this procedure if you want to prefix the DEP device names with the users' user IDs. This prefix will only be applied to the devices you enroll after you apply this setting.

  1. Navigate to Setting > iOS > DEP Server Setting.

  2. Click DEP Device Name.

  3. Choose the format you want to use for the DEP device names.

  4. Click Save.

Assigning users to DEP devices

After the DEP devices are enrolled, you can assign users to them. You can either add single users or add users in bulk to DEP devices.

Add single users to DEP devices

To assign users one at a time, complete the following steps:

  1. Navigate to Setting > iOS > DEP Device Management.
  2. On the DEP Device Management page, click the check box for a device you want to assign the user to.
  3. Click Assign User.
    • Click Unassign User to remove the user assignment from the device. The device must be unenrolled before unassigning the user.
  4. On the Select User window, click the user you want to assign to the device, and then click OK. After the user is successfully assigned, you can send device commands just as you would with other devices controlled by Knox Manage.

Bulk add users to DEP devices

To assign users in bulk, complete the following steps:

  1. On the KM admin portal's left hand menu, go to Device enrollment > Apple DEP > DEP Device Management.
  2. On the DEP Device Management screen that opens, click Bulk Assign Users.
  3. On the Bulk Assign Users page that opens, click Download Template to download an xls file with a template that you can customize.
  4. Customize and save the downloaded template file, and then return to the Bulk Assign Users screen to upload it to KM admin console.
  5. Click OK. The users in the uploaded file are added to DEP devices.

Managing DEP devices

In the Knox Manage Portal, the DEP devices registered in the Apple Device Enrollment Program (DEP) are managed. You can synchronize with the DEP server in the Apple Business Manager website to update the DEP device list in the Knox Manage Portal, modify and assign DEP profiles, and control DEP devices.

Viewing the DEP device details

To view the DEP device details in the Knox Manage Portal, complete the following steps:

  1. Navigate to Setting > iOS > DEP Device Management.
  2. On the DEP Device Management page, click the serial number of the desired DEP device on the list to view its details.
  3. In the Device Detail window, view the selected DEP device information.

Synchronizing with the DEP server

To synchronize with the DEP server and the Apple Business Manager website to update the DEP device list in the Knox Manage Portal, complete the following steps:

  1. Navigate to Setting > iOS > DEP Device Management.
  2. On the DEP Device Management page, click Sync DEP to synchronize with the DEP server.
  3. On the DEP device sync window, click OK. The DEP device list in the Knox Manage Portal will be updated.

Note—If the server token has expired, you can no longer update the DEP device list.

Modifying and assigning the DEP profiles

To modify and assign DEP profiles to DEP devices, complete the following steps:

  1. Navigate to Setting > iOS > DEP Device Management.
  2. On the DEP Device Management page, click the check boxes next to the DEP devices on the DEP device list, and then click Set DEP profile to modify the DEP profile.
  3. On the Set DEP profile window, modify the desired DEP profile items, and then click Save to save the set DEP profile and return to the DEP Device Management page. For more information on setting the DEP profiles, see Setting DEP profiles.
  4. Click Sync DEP to synchronize with the DEP server to update the DEP device list. The modified DEP profile will be assigned to the DEP devices.

Select DEP enrollment method

To set an enrollment method for your DEP server, complete the following steps:

  1. On the left hand navigation menu, go to Device Enrollment > Apple DEP > DEP Server Setting.
  2. On the DEP Server Settings page, click DEP Enrollment Method.
  3. On the DEP Enrollment Method page, click to choose one of the following two options:
    • User Assignment—Use this option to assign device users to DEP device before KM enrollment.
    • User Authentication—For this option, device users directly enter their user ID and password upon enrollment.
  4. Click OK to save your settings and return to the DEP Server Setting page.

Unenroll DEP devices

If you want to use DEP devices as general iOS devices or if the DEP devices are no longer required, you can unenroll the DEP devices in the Apple Business Manager website.

To unenroll DEP devices, complete the following steps:

  1. Visit the Apple Business Manager website at https://business.apple.com, and then enter your Apple ID and password to log in.
  2. On the Apple Business Manager website, navigate to Settings > MDM Servers.
  3. On the Server Details page, click an MDM server to disable and delete it, and then click Edit > Delete MDM Server.
  4. In the popup window, click OK. All the DEP devices on the MDM server will be deleted.
  5. NOTE—To delete the MDM server and relocate the DEP devices on this server, select Reassign Devices from the drop-down list. Then, select a different MDM server where you want to relocate the MDM devices to and click Delete.
  6. On the Knox Manage Portal, navigate to Setting > iOS > DEP Device Management.
  7. On the DEP Device Management page, click Sync DEP to synchronize with the DEP server.
  8. In the DEP device sync window, click OK. The DEP device list in the Knox Manage Portal will be updated according to the DEP server, and the DEP devices on the DEP server in the Knox Manage Portal will be deleted.
Share it: