Apple devices can be automatically enrolled in a device management service during setup,
but reenrollment typically requires a factory reset. Apple devices now support seamless migration
from one Mobile Device Management (MDM) to a new device management service through the Apple
Business Manager. Administrators can set enrollment deadlines, enforce migration, and preserve apps
and data during the process.
About this task
Administrators can assign and update device management for Apple devices by using Apple Business
Manager and integrate them with IBM®
MaaS360® for automated device enrollment. The steps include selecting a device management token, setting an enrollment deadline, confirming the assignment, and completing the enrollment on the device. By following this procedure, administrators ensure that devices are properly migrated in MaaS360 MDM, enabling secure management and compliance with organizational policies.
Procedure
-
Login to Apple Business
Manager.
- Go to .
- On the Inventory, search for the iOS or macOS device and select
the device.
Note: To search for iOS or macOS devices to migrate, click the filter icon to the right of the
search field. Under Device Management, select the MDM server where the
devices are currently managed, and then click Search. Select multiple
devices, or click Select All to migrate all devices.
You can also find devices in
Apple Business Manager.
- Select Devices and click Management Services.
- Select the MDM server that is tied to your ADE or DEP connection.
- Click the menu icon
and choose
Show Devices.
- Click Assign Device Management.
- From the Device Management Service drop-down list, select the
token file for Automated Device Enrollment.
Locate the token file that you downloaded
from the MaaS360 portal.
- Click Add Deadline to set the enrollment deadline. The user
receives a notification to enroll. If not enrolled by the deadline, enrollment is enforced
.
- Click Continue.
- A confirmation pop-up appears. Click Confirm to change the device
management service.
- The service assignment for device management is updated. Click
Done.
- On the Device Overview page, review the updated device management
details.
- From the IBM
MaaS360 Portal home page, go to
.
- On the Apple Device Enrollment page, click Add
Token.
- On the Add Token page, enter a Token Name and
select the Token File that was created in ABM.
- Click Add.
- On the Tokens page, review the token details.
- On your iOS or macOS device, a notification appears to indicate that enrollment is
required.
- Tap .
- After the device restarts, the Device Management screen displays the
organization name that is registered with your Apple Business Manager (ABM) account.
- Tap Enroll this iPhone for iOS devices. For macOS device, click
Enrol. The device unenrolls from the current management and begins
reenrollment.
Note: If DEP profile has authentication that is enabled, then on the device an auth prompt appears
for the user to input auth details.
- After enrollment completes, an Enrollment Complete notification
appears.
- On your iOS device, go to
and tap MaaS360 MDM
Profile.
The MaaS360 MDM
configuration is successfully installed on the device.
- On your macOS device, go to
.
The MaaS360 MDM configuration is successfully
installed on the device.
Results
After completing the procedure, the system automatically assigns the default iOS policy to
the device. However, if a pre-configured policy was previously assigned to either the All Devices
group or the iOS Devices group, that policy takes precedence and is applied instead. Following
migration, all iTunes, B2B, Enterprise, and VPP-licensed apps that were pre-assigned to these groups
are installed on the device. Similarly, any rules that were pre-assigned to the relevant groups are
enforced once migration is complete.