Enrolling Devices With the Apple Device Enrollment Program


This topic provides a brief summary of the steps you need to follow to enroll iOS devices in MobiControl via the Apple Device Enrollment Program.

What Is the Apple Device Enrollment Program?

The Apple Device Enrollment Program (DEP) provides a fast and streamlined way to enroll company-issued iOS and OSX devices. Enrolling an iOS device in MobiControl is much easier, and requires much less user interaction, when the device has already been enrolled in the Device Enrollment Program.

For MobiControl administrators, the benefits of the Apple DEP are:

Refer to Apple's support documentation for more information about the Apple Device Enrollment Program.

Enrolling Devices In MobiControl Via the Device Enrollment Program

Using the Device Enrollment Program (DEP) to enroll iOS devices in MobiControl involves performing setup steps on both the Apple DEP side and the MobiControl side. You will need to refer to Apple's documentation on DEP for specific instructions and requirements regarding the Apple portion of the setup process.

The following are the general steps required to enroll devices in MobiControl via the Device Enrollment Program:

  1. Enroll your organization in the DEP and set up administrator accounts.

  2. Set up a virtual MDM server and link it to a MobiControl deployment server.

    You can create multiple virtual MDM servers and link them to different MobiControl deployment servers.

    See Apple Device Enrollment Program and the Device Enrollment Program Guide, on Apple support, for more information.

  3. Assign your iOS devices to your virtual MDM server.

  4. In MobiControl, create an Add Devices rule for the iOS devices you assigned to the virtual MDM server.

    When you create the Add Devices rule, the wizard will enable you to configure the rule as a DEP enrollment profile. See Adding iOS Devices for more information.

    Note:

    DEP-enrolled devices are enrolled to MobiControl using the default Add Devices rule. If you want to re-assign some or all your devices to other Add Devices rules, refer to Managing DEP Assignments for more information.

If the device has not yet been activated by the user, the device will be enrolled in MobiControl via the Device Enrollment Program when the user activates the device. If the device has previously been activated, you must first wipe the device before it can be enrolled. To wipe an iOS device in the MobiControl Web Console, open the Devices tab, right-click on the device, and select Action > Wipe.

To identify in the MobiControl Web Console which iOS devices have been enrolled via the Device Enrollment Program, on the Devices tab click a device to select it. If the Information pane for that device includes an Apple Device Enrollment Program section, then it is a DEP device.

Note:

If you unenroll a device from a virtual MDM server, the device can be enrolled later to a different virtual MDM server (or even re-enrolled to the same server). If you disown the device, then it is permanently removed from the Apple Device Enrollment Program and cannot be added back.
Perform both actions on the Apple DEP server.

MobiControl automatically updates the list of DEP devices that are assigned to a particular instance of MobiControl every 24 hours. If you need to update the list immediately, you can sync DEP devices manually through the Apple Device Enrollment dialog box available in the Global Settings on the Servers tab.

Note:

Ensure your Apple devices can access the hosts listed at Apple MDM documentation or MobiControl will not be able to use Apple Push Notifications.

Manage DEP Assignments

The Manage DEP Assignments option allows you to re-assign DEP devices to different Add Devices rules. Since all DEP devices are enrolled using the default Add Devices rule, this option provides you with an opportunity to tailor specific enrollment settings to the various requirements of your devices. Access the Manage DEP Assignments option by right-clicking an Add Devices rule. A dialog will open to display a list of all DEP devices enrolled to this instance of MobiControl. You can filter devices based on which Add Device rule they are assigned to, their enrollment status, and their DEP profile status. You can also search for specific devices by device name or serial number.

Re-Assigning DEP Devices

Follow these instructions to re-assign a DEP device to another Add Devices rule. You can only re-assign devices to existing rules, you cannot create a new Add Devices rule during this process.

  1. On the iOS tab, select the Rules tab.
  2. Right-click the Add Devices rule that currently targets the devices that you want to re-assign and select Manage DEP Assignments.
  3. Devices that are currently assigned to the selected Add Devices rule are displayed.
    Select All DEP Devices from the dropdown to display all of the DEP devices in this instance.
  4. Click Manage Assignments to open the Manage Assignments dialog.
  5. Click Add and enter the serial number of the device you want to re-assign in the Serial Number field. MobiControl matches the serial number with an existing device in the database and then populates the rest of the fields with the corresponding information.
  6. Repeat until you have entered all the devices you want to re-assign.

    If you have a large number of devices to re-assign, you can import an .csv file of your devices' serial numbers by clicking Import File. Use the following format when creating your .csv files:

    • Column 1: Serial Number
    • Column 2: Device Type (iPad or iPhone)
  7. Errors caused by duplicate entries, missing information, or invalid devices (devices that are not assigned to this instance of MobiControl) are flagged and the re-assignment will not proceed until the errors have been resolved.
    Use the Edit and Delete buttons to resolve errors.
  8. Once you are satisfied with the list of devices, select a new Add Device rule from the Choose Action dropdown.
  9. Click OK to save your changes and close Manage Assignments. You can review the statuses of your re-assigned devices.
  10. Repeat as necessary to organize the rest of your devices.
  11. Click OK to close the Manage DEP Assignments dialog box.

The re-assignment will go into effect when the device next activates.

Review Device Assignments

You can generate an .csv file that lists all DEP devices assigned to this particular instance of MobiControl by their serial numbers and type.

  1. On the iOS tab, select the Rules tab.
  2. Right-click any Add Devices rule and select Manage DEP Assignments.
  3. Select All DEP Devices from the dropdown to generate a list of all your DEP devices.

    You can refine the device list by applying filters based on which Add Device rule they are assigned to, their enrollment status, and their DEP profile status.

  4. Click Export Devices and save the .csv file to your machine.
  5. Click OK to close the Manage DEP Assignments dialog window.

Manage DEP Assignments Fields

The Dropdown allows you to filter devices based on which Add Devices rule they are assigned to.

The Manage Assignments button allows you to re-assign devices.

The Export Devices button allows you to generate a list enrolled devices. Note: Any filters that are applied when the button is selected will continue to apply when the .csv file is generated.

Column Name Name Serial Number Add Devices Rule Type Enrollment Status DEP Profile Status
Description The name of the device in MobiControl. The serial number of the device. The Add Devices rule that the device is currently assigned to.

Note: This column is only visible when All DEP Devices is selected in the dropdown.

The type of iOS device. Options consist of iPad, iPhone, and Unknown. The status of enrollment of the device. Options consist of Enrolled, Unenrolled, and Not Enrolled.

Enrolled devices are devices that are currently enrolled to this instance of MobiControl.

Unenrolled devices are devices that were previously enrolled and subsequently unenrolled but not disowned.

Not Enrolled devices are devices that have never been enrolled to this instance of MobiControl.

The status of the DEP profile on the device. Options consist of Assigned, Empty, Pushed, and Removed.
© SOTI Inc.
Contact us