Managing Apple devices in the University using Apple enterprise programmes.
Apple deployment programmes
Apple provide the following to support managing macOS, iOS and tvOS devices in the enterprise:
- Mobile Device Management (MDM)
- Automated Device Enrolment (ADE)
- Volume Purchasing
- Apple School Manager (ASM)
It is current best practice to use these technologies and it is likely their use will become mandatory at some point in the future.
Mobile Device Management (MDM)
MDM is a protocol comprising of commands that can be used to manage Apple devices. The commands cover installing configuration profiles, App Store apps and device management such as locking, rebooting, remote wipes and software updates.
The MDM protocol is published here. There are many implementations of MDM such as:
The School, Department or College will be responsible for running their own MDM server of choice.
Automated Devlice Enrolment (ADE)
Automated Device Enrolment is a technology that automatically enrols Apple devices into an MDM environment. When integrating an MDM server with ADE, a certificate is generated by the MDM server and then signed by Apple. This is imported into Apple School Manager to create a trusted link between the MDM server and the Device Enrolment pool.
When an Apple device is purchased from one of the Apple Higher Education Framework Resellers it should be automatically added to the Device Enrolment pool for the University of Cambridge and related Institutions. Devices can be then requested to be assigned to an MDM server by an institution.
Eligible devices must be purchased through one of the following channels:
- Apple Higher Education Portal (prior to Apple HE Tender)
- Apple HE Tender Supplier (Academia, XMA etc)
Devices not purchased through one of the above channels cannot be used with Device Enrolment.
During device activation with Apple (this happens when the device joins the network after the first boot of a new device or a wipe and reinstall) the device is directed to enrol with the assigned MDM server. Configuration is then applied with no user interaction required.
UIS has signed up to the Automated Device Enrolment on behalf of the University of Cambridge and related Institutions.
Volume Purchasing
Volume Purchasing originally gave bulk discounts on Apple applications such as the iLife and iWork suites, Logic Pro and Final Cut Pro. Now it is primarily used to purchase App Store apps that can be deployed over the air to devices without use of an Apple ID. Applications can also be removed and redeployed to another device.
UIS has signed up to the Volume Purchasing on behalf of the University of Cambridge and related Institutions.
Apple School Manager (ASM)
Apple School Manager is an Apple-provided web portal that manages MDM server integration with the Automated Device Enrolment pool.
Preparing to manage Apple devices
Steps and responsibilities
Step | Institution action | UIS Apple Support action |
1 | Institution selects and provisions MDM server | |
2 | An Automated Device Enrolment certificate signing request is generated by the MDM server and emailed to UIS Service Desk | |
3 | CSR is uploaded to ASM and certificate is generated by Apple. This is returned to the institution. | |
4 | Volume Purchasing account is created for the Institution and an initial password provided. | |
5 | Volume Purchasing account is added to the MDM server. | |
6 | Serial or IMEI numbers of devices to be managed are provided. | |
7 | Devices are assigned to the MDM server. |
Note: Steps 6 and 7 will be repeated whenever an Institution wishes to add more devices to their managed fleet. Devices can also be unassigned from an MDM server.
Assigning Devices to Institutional MDM Infrastructure
Use the HEAT Self Service Request form to request serial numbers to be assigned to your MDM. Details requested are:
- Serial Number(s)
- Assign or Remove devices
- Institution requesting the the action
- Navigate to https://uniofcam.saasiteu.com/
- Select Self Service Portal
- Select Make A Request
- Enter "MDM" in the search box
- Select "Assign/Unassign Apple Serial Number(s) to MDM" and click Request
- Fill in the details as prompted.
The benefits of Apple's enterprise deployment programmes
Using Apple's enterprise deployment programmes to manage Apple devices is current best practice.
- Devices are provisioned and configured through a secure and trusted channel.
- App Store apps, management and configuration profiles can be delivered to any device connected to the internet.
- The end user can use their own Apple ID to install apps that belong to them.
- Some IT system admin tasks that are now restricted in newer macOS releases are available when a device is provisioned via ADE and MDM – for example, kernel extension whitelisting allowing seamless installs of McAfee AV products, DropBox etc.
- Devices are activation-locked, allowing remote wipe, lost mode etc. and preventing the device from being wiped and sold.
Contact us
For more information please contact Service Desk.