Integrating and Configuring Workspace ONE UEM With Apple Business Manager (ABM/DEP) and Volume Purchase Program (VPP)
Integration with Apple Business Manager / Apple School Manager is a key step when using Workspace ONE to manage Corporate owned Apple devices. This extra step allows you to ensure that your devices are enrolled, and remain to be enrolled, in Workspace ONE. It also simplifies the enrollment process in that the the device is automatically enrolled into Workspace ONE UEM as part of the device setup process.
Part 1: Integrating UEM and DEP
Requirements: Apple Business Manager (ABM) or Apple School Manager (ASM) tenant.
- In the Workspace ONE UEM console, go to Settings > All Settings > Device and Users > Apple > Device Enrollment Program
- Click Configure
- Download the public key
In ABM, Click the Organization and then Preferences and the + to add an MDM Server
Give the MDM Server a Name and Upload the public key downloaded from the UEM console
Download the Token (sToken)
Configure Default Device Assignment
Upload the token into the UEM console
Configure authentication settings for the DEP profile.
Note: Custom enrollment settings create a popup window on the device that can used to customize the enrollment as opposed to the standard Username and Password prompt that would be typically seen. This is shown in the enrollment screens towards the end of this document.
Device organization group can be overruled based on OG logic. Refer to https://kb.vmware.com/s/article/83132 for more details.
Configure MDM settings for DEP profile
Configure setup assistant screens
These are the screens that are shown during the device setup wizard. Note only Location Services is enabled here.
Configure Sync and Assignment settings for DEP profile
DEP Profile is complete
Part 2: Integrate UEM and VPP
In Apple Business Manager, go to Preferences and Payments and Billing. Download the Server Token (sToken)
In UEM, go to Settings > All Settings > Devices and Users > Apple > VPP Managed Distribution.
Provide a friendly name for the description and upload the sToken.
Part 3: Adding a device to Apple Business Manger
Requirement: Apple Configurator 2 & macOS device
Connect your iOS device to the mac and launch Apple Configurator.
Select the device to make it active and click Prepare
Uncheck Activate and complete enrollment. Click Next.
Select New Server and Click Next.
Enter the name Apple Business Manager. Leave the URL as is and click Next
Click Next on the warning
Click next without entering any certificates
Select New Organization and click Next
Sign into Apple Business Manager. There will be a browser popup windows that you will need to sign into.
Select Generate a new supervision identity and click Next
Select Show all steps and click Next (They will be controlled in UEM)
Click Prepare on the Network Profile screen
Authenticate on the mac
Apple Configurator will prepare the device and register it Apple Business Manager. You may need to factory reset your device after this process is complete.
In Apple Business Manager, select Devices to verify that the device was added
In UEM, click Fetch All Devices to sync with Apple Business Manager
Go to Devices > Lifecycle and verify that the device is listed
Part 4: Add Intelligent Hub as a purchased app
In Apple Business Manager, go to Apps and Books and search for Intelligent Hub
Enter a license count and click Get
In the UEM Console, Apps > Native > Purchased and click Sync Assets. Then select Intelligent Hub and click Enable Device Assignment (this will allow the app to be pushed without the user having to enter a Appstore Account ID).
Using the regular assignment group method, assign Intelligent Hub to the iOS devices.
Part 5: Enrolling the DEP device
Reset factory device and work through the device setup process
In this example, Token based enrollment is in use. The Custom Enrollment setting popup is shown. If this setting was not used, the standard DEP Username/Password prompt would be displayed.
Note the only setup screen to be shown was Location Services, as per the settings in the DEP profile
Device enrollment is complete and Intelligent Hub downloads.
Comments
Post a Comment