Newsroom Update

Beginning in May, a special Today at Apple series titled “Made for Business” will offer small business owners and entrepreneurs free opportunities to learn how Apple products and services can support their growth and success. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

iPad Mobile Device Management (MDM) without Apple Configurator, what are public key & MDM server certificates

I'm trying to set up 40 iPads for a primary school.

I understand that Apple released Device Enrollment Plan (DEP) & Mobile Device Management (MDM) in Australia in January 2015 as an alternative to Apple Configurator. I liked the idea of a wireless alternative to Configurator which I think requires the iPads to be tethered to an iMac.

I have a unique Apple ID with two-step security, applied for the Volume Purchase Program (VPP) and Device Enrolment Plan (DEP) and these have been verified by Apple. This was quite a process but I suppose it is necessary for security and to confirm the educational use.

I have ordered a few apps in bulk through the VPP.

The problem I have now encountered is with the Device Enrollment Plan (DEP). When I try to load the serial numbers for the iPads I am asked to Add a MDM server. Giving the server a meaningful name for the school is not a problem but I am asked to upload a "public key certificate". A MDM server certificate file (ending in .pem or .der) is required from my MDM vendor.

Unfortunately, I do not know who my MDM vendor is. Are details of the server for the school required or is it that my iMac requires a certificate from Apple to be be able to securely communicate with Apple for the Volume Purchase Program (VPP). In either case I'm not sure who I should be asking for a public key certificate.

Any help from anyone using Device Enrollment Plan (DEP) & Mobile Device Management (MDM) would be much appreciated.

Thanks

iPad (3rd gen) Wi-Fi + Cellular, iOS 7.1

Posted on Aug 9, 2015 3:38 AM

Reply
Question marked as Best reply

Posted on Aug 11, 2015 7:52 AM

Hi Dried Apple,


It sounds like you don't have an MDM in place... the MDM is the missing piece! There are many different MDM products out there. Apple's MDM is called Profile Manager. Cisco has a free one called Meraki Systems Manager. I am using JAMF's Casper Suite to manage the 2,600+ iPads in our schools. There are dozens of other MDM's available and you can read about them in this article.


The MDM is separate from DEP and VPP. The three work together to allow for wireless management of your iOS devices. DEP enrolls your device into your MDM. The MDM sets up your devices using configuration profiles. Adding VPP to your MDM will enable you to assign VPP apps to users in your MDM. Here is a webinar that may help clarify this process.


Here is another excellent resource that may help guide you through the process. It is long but should help.


Hope this answers your question!

~Joe

8 replies
Question marked as Best reply

Aug 11, 2015 7:52 AM in response to Dried Apple

Hi Dried Apple,


It sounds like you don't have an MDM in place... the MDM is the missing piece! There are many different MDM products out there. Apple's MDM is called Profile Manager. Cisco has a free one called Meraki Systems Manager. I am using JAMF's Casper Suite to manage the 2,600+ iPads in our schools. There are dozens of other MDM's available and you can read about them in this article.


The MDM is separate from DEP and VPP. The three work together to allow for wireless management of your iOS devices. DEP enrolls your device into your MDM. The MDM sets up your devices using configuration profiles. Adding VPP to your MDM will enable you to assign VPP apps to users in your MDM. Here is a webinar that may help clarify this process.


Here is another excellent resource that may help guide you through the process. It is long but should help.


Hope this answers your question!

~Joe

Aug 22, 2015 8:56 PM in response to Dried Apple

Thanks Joe, I followed your suggestion and upgraded the iMac with OS X 10.10 and the latest OS X Server, which includes Profile Manager. I was able to use Profile Manager to start MDM, download a SSL certificate and my server now shows in the DEP window for assigning devices.


Now I am having trouble assigning in DEP my iPads to the server. In DEP > Assign devices I have tried uploading a single serial number and a Windows comma separated .csv file without success. I think I have to leave off the "S" from the start of the serial number listed on the invoices. I also had to ask the Apple Reseller to let Apple know that the iPads were going to be enrolled in DEP, which they tell me they did a few days ago.


Any tips about assigning devices in DEP would be much appreciated.

Aug 23, 2015 5:21 AM in response to Dried Apple

Since my last post I discovered that in Apple Profile Manager in OS X Server I was able to load devices using a .csv file. To upload a .csv file in Profile Manager the file seemed to need two columns, one for DeviceName and the other for SerialNumber. However, the file still wouldn't work with Apple's online DEP.

In Profile Manager > Library I can see the apps that I have ordered on VPP but I can't see how to allocate these to the device groups I have created. I have enabled VPP for the groups and can see where it says Push to devices. The iPads that I previously set up already log into our wi-fi but don't have their own Apple ID or email, so I can't send a group email to ask them to join VPP.

I am wondering whether I should try resetting one of the iPads and see whether the setup assistant now includes an invitation to join VPP.

Aug 24, 2015 9:08 AM in response to Dried Apple

Hi Dried Apple,


DEP is designed for one-to-one deployments where each user has an Apple ID. In the MDM that I use (Casper), I set up a "Pre-Stage Enrollment" where I select serial numbers to be placed into DEP. Once selected, the device will be forced into MDM enrollment. So when a user turns on the device for the first time, they are prompted for a username and password (LDAP). When they log in, configuration profiles start to come down to set up the device. At the same time, their user information gets pulled into the MDM and triggers an auto-generated email with a VPP invitation. I'm not sure exactly how it works with Profile Manager but it's probably similar.


Hope this helps!

~Joe

Sep 8, 2015 6:25 AM in response to nsdjoey

Thanks Joe, your advice was helpful.

As you suggested I had to create Apple IDs for each iPad. I did this in batches because I had trouble running the Apple script in Apple ID Automation Builder.

The cause of my problem uploading the iPad serial numbers in DEP and assigning them to my MDM server was a confusion about our DEP Customer ID. The devices had been ordered through a head office with a different DEP Customer ID.

In my .csv file I also had one serial number incorrect which threw out the block assignment of serial numbers. I assigned small groups of serial numbers before I worked out which serial number was incorrect.

I will keep in mind the pre-stage enrolment before we place our next order for iPads. I'm not sure if Profile Manager has all the features of Casper. The school's head office uses Meraki.

I'm now in the process of pushing apps out to the iPads. It looks like it will take awhile on our little network.

I also need to check that Profile Manager lets me supervise the iPads so that I can turn off some features that we do not want the students to have access to. Configurator allows supervision but I didn't want to use Configurator if I could help it. Apple documentation says that iPads can be supervised if they have been enrolled in DEP.

Sep 8, 2015 8:01 AM in response to Dried Apple

Glad I could help! Yes, iPads can be supervised via DEP. When creating the "Pre-Stage Enrollment" (in Casper...might be a different name in Meraki or Profile Manager), you can select whether you want to supervise the devices or not. In Casper, its just a checkbox that needs to be ticked. Once the device(s) are Supervised, you will have the ability to add more restrictions configuration profiles. These configuration profiles can be deployed automatically once devices are enrolled in your MDM.


Good luck!!!

~Joe

iPad Mobile Device Management (MDM) without Apple Configurator, what are public key & MDM server certificates

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.