Menu

Use the Apple Device Enrollment Program (iOS devices only)

The Apple Device Enrollment Program (DEP) allows you to quickly and easily enroll a large number of organization-owned Apple devices. Devices added by DEP will be enrolled automatically without user intervention with the configured device management profiles.

NOTE— Apple has announced a new consolidated platform—Apple Business Manager. Visit their website to learn more about how to upgrade from DEP.

To enroll devices using ZTE, the following procedures must be performed.

Before using the Apple Device Enrollment Program

To use the Apple Device Enrollment Program (DEP) properly, the followings must be prepared:

  • Prepare a device from an Apple store, Apple theorized reseller, or carrier.
  • Make sure the devices are running iOS 10 to 13.
  • Register for an Apple Business account in Apple Business Manager or upgrade from DEP. To learn more about upgrading from DEP to ABM, see https://support.apple.com/en-us/HT208817.

Issuing a DEP token

To use Apple Device Enrollment Program (DEP), you must request for a DEP token issued by Apple through a public key, and then set up DEP in the Knox Manage Admin Portal.

To issue a DEP token and set up DEP, complete the following steps:

1. Navigate to Setting > iOS > DEP Server Setting. If you have issued a DEP token before, the previously issued DEP token’s information and its expiration date are displayed.

2. On the “DEP Server Setting” page, click Download Public Key to download a public key in the .pem format required to create a new MDM server in the Apple DEP Portal.

3. Visit the Apple Business Manager website at https://business.apple.com.

4. Sign in using your Apple Business account, and then enter the 6-digit verification code sent to the mobile device registered to your Apple ID.

  • The start window of the ABM site will appear.

5. On the Apple Business Manager website, navigate to Settings > Device Management Settings at the bottom of the site, and then click Add MDM Server on the right of the screen.

6. Configure the MDM server settings, upload the public key file in the .pem format downloaded from the Knox Manage Admin Portal, and then click Save.

7. Click Download Token on the right of the screen and download the Apple token file in the .p7m format on to the computer.

Note: Using a single token to enroll the DEP devices for one company is recommended.

8. On the “DEP Server Setting” page of the Knox Manage Admin Portal, click Upload DEP Token and then select the DEP token file with .p7m format downloaded from ABM.

9. Click OK. If the DEP token file is uploaded successfully, the authentication processes between the Knox Manage server and the Apple’s DEP server is completed.

10. Click Set Default Profile to set up a profile to be assigned to the DEP devices by default, and then click OK.

Note: For more information on setting a general profile, see Setting DEP profiles.

11. Click Set DEP Device Sync Interval to set the sync interval of DEP devices.

Registering DEP devices

After the Device Enrollment Program (DEP) server is all set up, register iOS devices with the MDM server in the Apple Business Manager website.

To register iOS devices in the Apple Business Manager website, complete the following steps:

1. Visit the Apple Business Manager website at https://business.apple.com, and then enter your Apple ID and password to log in.

2. On the Apple Business Manager website, navigate to Device Assignments to assign iOS devices to the MDM server you have already created.

3. Select the method for registering iOS devices from Choose Devices:

  • Assign Device by Serial Number: Enter a list of device serial numbers to register the iOS device.
  • Assign Devices by Order Number: Enter the Apple Purchase Order number so that the devices are added automatically.
  • Upload a .csv File: Upload a .csv file that includes the serial numbers.

4. Select Assign to Server as Action, and then select the MDM server group.

5. Click Done. If the iOS devices are registered successfully in the Apple DEP, navigate to View Assignment History to view the registered device information and its assignment history.

Setting DEP profiles

After the iOS devices are registered to the Apple Business Manager website, you must set the DEP profile to be assigned to the devices through the Knox Manage Admin Portal.

The DEP profile is applied to the DEP devices when the DEP devices are enrolled.

To set a DEP profile, complete the following steps:

1. Navigate to Setting > iOS > DEP Server Setting.

2. On the “DEP Server Setting” page, click Set DEP Default Profile.

3. On the “Set DEP profile” window, set the following items in the DEP profile:

  • Supervised Mode: Click the checkbox next to Apply to enable the supervised mode that is only available on iOS devices and must be applied to the DEP devices.
    • Delete MDM profile: Click the checkbox next to Allow to allow users to delete the MDM profile.
    • Supervising host certificate list: Click Add to add the registered certificate to the Apple device you want to pair with the DEP devices.
  • Pairing: Click to allow other Apple devices to pair with the DEP devices.
  • Skip Settings: Select the items that appear during the device setup process after users turn on their DEP devices for the first time. If the items are checked, they do not appear on the window.

4. Click Save to save the set DEP profile.

Assigning users to DEP devices

After the DEP devices are enrolled, you can assign users to them.

To assign users, complete the following steps:

1. Navigate to Setting > iOS > DEP Device Management.

2. On the “DEP Device Management” page, click the checkbox for a device you want to assign the user to.

3. Click Assign User.

  • Click Unassign User to remove the user assignment from the device. The device must be unenrolled before unassigning the user.

4. On the “Select User” window, click the user you want to assign to the device, and then click OK. After the user is successfully assigned, you can send device commands just as you would with other devices controlled by Knox Manage.

Managing DEP devices

In the Knox Manage Portal, the DEP devices registered in the Apple Device Enrollment Program (DEP) are managed. You can synchronize with the DEP server in the Apple Business Manager website to update the DEP device list in the Knox Manage Portal, modify and assign DEP profiles, and control DEP devices.

Viewing the DEP device details

To view the DEP device details in the Knox Manage Portal, complete the following steps:

1. Navigate to Setting > iOS > DEP Device Management.

2. On the “DEP Device Management” page, click the serial number of the desired DEP device on the list to view its details.

3. In the “Device Detail” window, view the selected DEP device information.

Synchronizing with the DEP server

To synchronize with the DEP server and the Apple Business Manager website to update the DEP device list in the Knox Manage Portal, complete the following steps:

1. Navigate to Setting > iOS > DEP Device Management.

2. On the “DEP Device Management” page, click Sync DEP to synchronize with the DEP server.

3. On the “DEP device sync” window, click OK. The DEP device list in the Knox Manage Portal will be updated.

Note: If the server token has expired, you can no longer update the DEP device list.

Modifying and assigning the DEP profiles

To modify and assign DEP profiles to DEP devices, complete the following steps:

1. Navigate to Setting > iOS > DEP Device Management.

2. On the “DEP Device Management” page, click the checkboxes next to the DEP devices on the DEP device list, and then click Set DEP profile to modify the DEP profile.

3. On the “Set DEP profile” window, modify the desired DEP profile items, and then click Save to save the set DEP profile and return to the “DEP Device Management” page. For more information on setting the DEP profiles, see Setting DEP profiles.

4. Click Sync DEP to synchronize with the DEP server to update the DEP device list. The modified DEP profile will be assigned to the DEP devices.

Unenrolling DEP devices

If you want to use DEP devices as general iOS devices or if the DEP devices are no longer required, you can unenroll the DEP devices in the Apple Business Manager website.

To unenroll DEP devices, complete the following steps:

1. Visit the Apple Business Manager website at https://business.apple.com, and then enter your Apple ID and password to log in.

2. On the Apple Business Manager website, navigate to Settings > MDM Servers.

3. On the “Server Details” page, click an MDM server to disable and delete it, and then click Edit > Delete MDM Server.

4. In the popup window, click OK. All the DEP devices on the MDM server will be deleted.

Note: To delete the MDM server and relocate the DEP devices on this server, select Reassign Devices from the drop-down list. Then, select a different MDM server where you want to relocate the MDM devices to and click Delete.

5. On the Knox Manage Portal, Navigate to Setting > iOS > DEP Device Management.

6. On the “DEP Device Management” page, click Sync DEP to synchronize with the DEP server.

7. In the “DEP device sync” window, click OK. The DEP device list in the Knox Manage Portal will be updated according to the DEP server, and the DEP devices on the DEP server in the Knox Manage Portal will be deleted.