Enrolling iOS devices using a MobiControl Certificate


After you have created an add devices rule for your iOS devices, you must install profiles on your devices to complete the enrollment process.

Note

If your server has a signed certificate, use the process detailed at Enrolling iOS devices using a Third-Party Signed Certificate.

If your server does not have a signed certificate, you must install a MobiControl-generated certificate called the Trust Profile on your iOS device. The Trust Profile allows your iOS devices to accept the Enrollment Profile.

Furthermore, if you enabled Static Enrollment Change in the Authentication section of the add devices rule, you can download the Device Enrollment and MobiControl Trust Profiles from the MobiControl Console. Right-click on the add devices rule and select either of the profiles to download. You can then install these profiles with the iPhone Configuration Utility.

  1. Go to the iOS Enrollment Service Web Page

    On the device, open the Safari browser and enter the Enrollment URL from the add devices rule in the address bar. If a pop-up appears, stating that it cannot verify the server identity, tap Continue to ignore the warning and proceed with the enrollment process.

    Cannot Verify Server Identity

  2. Download the MobiControl Trust Profile

    Tap Step 1 to begin downloading the MobiControl Trust Profile. This Profile installs the MobiControl Root CA certificate on your iOS device. It is necessary to verify the MobiControl Device Enrollment Profile. On devices running iOS 10.3.3 or later, you will be notified that you are being redirected to Settings. Tap Allow to continue. Your iOS device will display a warning message with a brief description of the purpose of the Trust Profile. Tap Install. Once the Trust Profile has finished downloading, tap Install to install the Trust Profile and continue with the enrollment process.

    The iOS Enrollment Service Web Page

    Settings Redirect Prompt

    The Trust Profile

    Trust Profile Installation Warning

    Successful Installation of the Trust Profile

  3. Explicitly trust the MobiControl Root CA Certificate

    This step is only applicable on devices running iOS 10.3 or later.

    On your iOS device, navigate to iOS Settings > General > About > Certificate Trust Settings and activate Enable Full Trust for Root Certificates for the certificate that was downloaded in the previous step. Return to Safari.

    iOS Certificate Trust Settings

  4. Download the MobiControl Device Enrollment Profile

    Tap Step 2 to download the MobiControl Device Enrollment Profile. On devices running iOS 10.3.3 or later, you will be notified that you are being redirected to Settings. Tap Allow to continue. Tap Install and then Install again to install the MobiControl device enrollment profile.

    The Device Enrollment Profile

    Confirm Installation

  5. Accept Warning

    When you tap Install Now, your iOS device will display a warning message with a brief description of the purpose of the MobiControl Device Enrollment Profile. Tap Trust to continue.

    Warning Message

    Accept Remote Managed

  6. Install Profile

    The installation process of the MobiControl Device Enrollment Profile includes several automatic steps that require no user interaction. Once the profile has finished installing on your device, tap Done.

    13

    MobiControl Device Enrollment Profile Successfully Installed

  7. Finish Enrollment

    Congratulations! You have successfully enrolled your iOS device into MobiControl.

    13

    Successful Enrollment

© SOTI Inc.
Contact us