Enrolling devices is the first stage in managing a mobile device and here you can know the various steps involved in enrolling Apple devices. Before enrolling any Apple device, it is mandatory you upload an APNs certificate in MDM as explained here.
Endpoint Central offers the following types of Enrollment methods:
The major advantage of using Admin enrollment methods, is that users cannot revoke management from the device end whereas that is not the case when enrolled using user enrollment methods. Hence it is recommended to utilize Admin enrollment methods like ABM to exercise full control over the devices besides the benefits offered by the traditional methods. These benefits include:
Supervising the devices offer added advantages such as full control over policies and configurations, silent app installation without user intervention, Kiosk support, etc. Considering the devices to be enrolled are already in use, the devices are reset during enrollment. In case you do not prefer the devices being reset, you can either:
Admin enrollment methods can be preferred if the devices to be enrolled are corporate owned devices whereas the latter can be settled on in case the devices are employee owned. If the devices to be managed are corporate owned, it is certain that complete device management is preferred. In case of employee owned devices, it is adequate to manage just the workspace. To learn the differences between complete device management and container management, click here.
Follow the steps mentioned below to enroll both Mac and iOS devices.
In case you want to seamlessly enroll Apple devices in bulk, you can enroll using DEP and Apple Configurator.
Ensure that you configure your Proxy settings, and the mail server settings, so that you the user can receive the email with the OTP. (This is not applicable for Endpoint Central Cloud)
In case of Endpoint Central Cloud, users will be sent 2 mails, one for account creation with MDM (joining the organization) and the second with the enrollment invitation.
After enrollment users receive an email with the enrollment instructions and the link to enroll the devices. Based on the authentication policy defined for enrollment, users receive the OTP. Users need to manually install the MDM Profile by clicking on the enrollment request. All enrolled devices are listed in the Devices Tab in the Endpoint Central console under Groups and Devices.
You can enroll multiple devices for the same user. In case a user has more than one mobile device that needs to be managed, you can enroll those devices by following the steps mentioned below;
The mail to enroll additional device would be sent to the specified user.
The admin can choose to either send out an SMS along with the email or just an SMS to users to enroll their devices.
Endpoint Central provides organization free SMS credits to enroll devices. An organization get 20% extra credits on the number of licensed mobile devices. For Example: An organization with 100 devices will have 120 free SMS credits.
Following are a few points to be kept in mind while using SMS enrollment:
This option facilitates you to enroll many devices at a same time. You can simply create a csv file with the User Name, Domain Name, Email, Platform and Owned by details and upload the same. Multiple entries should be in separate lines. Refer the below mentioned csv file for example,
USER_NAME,DOMAIN_NAME,EMAIL_ADDRESS,PLATFORM_TYPE,OWNED_BY,GROUP_NAME,UDID
ANDREW,,andrew@mobiledevicemanagerplus.com,iOS,Personal,IOS_Group,00f0ba8f7a6c41cca9cc5fd6b7ee666b
Follow the steps mentioned below, to enroll devices through Bulk Enrollment.
Enrollment mail is sent to all the users listed in the csv file.
The users, upon receiving the enrollment requests, can enroll their device as given below. The steps differ for devices running iOS 12 and above versions.
Follow the steps given below to enroll devices below iOS 12.0 and later versions.
The device enrollment process has been successfully completed and the device is listed in Endpoint Central.
Follow the steps given below to enroll devices running iOS 12.0 and later verisons.
Once the device enrollment is completed, the device is be scanned and the users receive an App Catalog and MDM Profile . All the Apps that are distributed by Endpoint Central are listed in the App Catalog. Users can choose the App and install them by clicking on it. Incase of App store App, by clicking on the App users are prompted to enter their Apple ID and password and the App is downloaded from the App store. MDM Profile is the profile used by Endpoint Central to manage the mobile device, if the user removes the MDM Profile, then all the Apps that has been installed through Endpoint Central and the policies applied are reverted.
When ME MDM App is installed on the device, you get advanced control over the device. Using ME MDM App helps administrators to identify Jail broken devices and also helps in location tracking. You can view where the device is geographically located by using this App. This App can be distributed to all the managed devices by following the steps mentioned below:
You have successfully distributed Apps to groups. The distributed Apps are listed in the App Catalog of the user's mobile device. Users can click on it and install the App. If this App is installed on a device running iOS 7 or later versions, then the app is automatically fetch Server Name, Port number and Enrollment ID. On the devices running iOS versions lower than 7.0, users should provide the Server Name, Port number and Enrollment ID which was sent to them via email. After installing the ME MDM app, you can see that the App Catalog is moved inside the app automatically. You can track the geographic location of the device by configuring location tracking.
Removing the device removes all profiles and apps associated with the device. ME MDM app is also removed if installed through Endpoint Central.
If you are using Endpoint Central as a plug in to Endpoint Central, then you can open the ports 8020/8383 for the communication.
This message is displayed if a SSL certificate is not uploaded on the server. If this has no effect on the enrollment or the device security, you can ignore the message and continue with the enrollment process.
This message is displayed if a SSL certificate is not uploaded on the server. This has no effect on the enrollment or the device security. You must click on Show details and select visit this website to access the enrollment request.