VSA 10 MDM: enrollment
NAVIGATION Modules > Integrations > Connectors
NAVIGATION Modules > Devices > MDM Enrollment
SECURITY Connectors > Full access to all Connectors pages
SECURITY Device Management > Add Devices
SECURITY Administrative privileges to manage software on the device to be enrolled and any endpoints assisting in the enrollment
In addition to traditional endpoint management, VSA 10 includes mobile device management (MDM) for supported devices. This article provides compatibility, prerequisite, and process information related to using VSA 10 as your MDM solution.
To learn how to migrate to VSA 10 from another MDM solution, refer to VSA 10 MDM: Migrating from another MDM solution.
Prerequisites
Compatibility
Our MDM solution currently supports enrollment for the following Apple operating systems:
- iOS 4.0 and above
- iPadOS 4.0 and above
- macOS 10.7 and above
Permissions
To complete this process, you'll need the following permissions:
- Full access to all Connectors pages, as described in User functions and permissions.
- Ability to log in to appleid.apple.com with the Apple ID of the device or devices you'd like to enroll.
- If configuring Automated Device Enrollment (ADE), ability to log in to Apple Business Manager with Administrator or Device Enrollment Manager credentials.
Device Enrollment vs. Automated Device Enrollment (ADE)
The two types of Apple MDM connectors available in VSA 10 drive your enrollment strategy. For a basic overview, refer to Types of Apple MDM connectors in the Connectors article.
Device Enrollment
To enroll devices in MDM using QR code or USB enrollment methods, you'll perform the following steps:
- Configure an Apple MDM Push Certificate connector in VSA 10. Refer to Create an Apple MDM Push Certificate connector in VSA 10.
- Create a push certificate in the Apple portal and upload it to VSA 10. Refer to Create a push certificate.
- Enroll devices one at a time into VSA 10 MDM. Refer to Manually enroll a device in MDM.
ADE
To configure automatic MDM enrollment of devices assigned to a dedicated server in Apple Business Manager, you'll perform the following steps:
- Configure an Apple MDM Push Certificate connector in VSA 10. Refer to Create an Apple MDM Push Certificate connector in VSA 10.
- Create a push certificate in the Apple portal and upload it to VSA 10. Refer to Create a push certificate.
- Create an Apple Automated Device Enrollment connector in VSA 10, and generate an MDM server token in Apple Business Manager to upload to VSA 10. Refer to Configure Automated Device Enrollment (ADE).
ADE behavior
After configuring ADE, every device assigned to the newly added MDM server in Apple Business Manager automatically appears in VSA 10 and is added to the agent group specified in the connector. The following applies to devices processed through ADE:
- These devices are enrolled in supervised mode, granting full control over device configurations and ensuring compliance with organizational policies. Refer to VSA 10 MDM: Supervised vs. non-supervised devices.
- These devices will receive all the assigned configuration profiles, ensuring consistent and secure device management across the organization.
- Non-activated devices appear on VSA 10 device pages as offline with an Enrollment status of Unenrolled. They do not consume licenses (mobile licenses for iOS devices nor regular licenses for macOS devices) until activated.
- These devices are activated in VSA 10 once they are turned on and undergo standard Apple device setup/activation. During this process, the Remote Management screen will show that the device is enrolling into remote management by your VSA 10 instance. Once activated, the Enrollment status on VSA 10 device pages changes to Enrolled, and MDM Commands become available. Refer to VSA 10 MDM commands.
Agent installation
During MDM enrollment for macOS computers, VSA 10 automatically installs the macOS agent as part of the process. This installation occurs silently, without requiring any user interaction. The macOS agent expands management capabilities, including remote control and workflow automation.
How to...
You'll start the MDM enrollment process by creating a new entry for the device on the Connectors page. To do so, perform the following steps:
- From the left navigation menu in VSA 10, navigate to Integrations > Connectors > Apple MDM.
- Click Create Connector.
- On the Create Connector page, select the Apple MDM Push Certificate connector type from the Type drop-down menu.
- Select the organization with which the new device will be associated.
- Click Next.
- Click Next.
- In the Download CSR File section, click Download CSR. VSA 10 will transfer a Certificate Signing Request (CSR) file named CertificateSigningRequest.plist to the default download location on your computer.
- In the Create the Apple Push Certificate section, click Go to Apple portal.
- Without closing the Create Connector page, perform the steps described in Create a push certificate to continue.
Once you've completed the steps in Create an Apple MDM Push Certificate connector in VSA 10, follow this process to obtain a vendor-signed version of the CSR file and upload it to VSA 10 to create your new push certificate:
Create the Apple Push Certificate
- The Apple Push Certificates Portal will open and prompt you for credentials. Log in with the Apple ID of the device or devices you'd like to enroll.
- Click Create a Certificate.
- The Apple portal will prompt you to accept the MDM Certificate Agreement Terms of Use. Once you've done so, you'll receive a prompt to upload your CSR file.
- Click Choose File. Select the CSR you generated in Create an Apple MDM Push Certificate connector in VSA 10. Then, click Upload.
- The Apple portal will surface a confirmation that you've successfully created the push certificate. Click Download.
- Continue to the next section of this article.
Upload the push certificate to VSA 10
- Return to the Create Connector page in VSA 10 and locate the Upload the Apple Push Certificate section.
- Add the certificate you downloaded from the Apple portal by dragging it into the Drag your certificate here box or by clicking the box and selecting the file to upload.
- Confirm the ID you used to create the certificate by entering it in the Apple ID field.
- Click Create. Then, proceed to either Manually enroll a device in MDM or Configure Automated Device Enrollment (ADE).
After creating the signed CSR and uploading it to VSA 10, you can enroll the device in MDM manually as follows.
Alternatively, if you wish to configure automatic VSA 10 MDM-enrollment of devices assigned to a dedicated server in Apple Business Manager, skip these steps and proceed to Configure Automated Device Enrollment (ADE).
- From the left navigation menu in VSA 10, navigate to Devices > MDM Enrollment.
- In the Context section, select the organization, site, and group where the device will reside.
- From the Enroll Path drop-down menu, select the method via which you'd like to enroll the device in MDM: QR Code and Link or USB using Apple Configurator.
QR code enrollment is intended for personal (BYOD) iOS and iPadOS devices. Link enrollment is required for macOS devices, but you can also use it for iOS and iPadOS. To enroll a device via either of these methods, perform the following steps:
- Follow the workflow it provides to complete the device enrollment. To send the instructions to a recipient via email, click Send Invite, complete the required contact fields, and click Send.
- Once the enrollment process is complete, the device will become available to manage on VSA 10's Device List page.
IMPORTANT The USB enrollment method will erase your device.
This enrollment type is intended for business or corporate-owned devices and enables additional management capabilities. Currently, it only supports iOS and iPadOS devices. To enroll a device via this method, perform the following steps:
- A USB pane, similar to the example shown below, will appear on the MDM Enrollment page. To send the instructions to a recipient via email, click Send Invite, complete the required contact fields, and click Send. Otherwise, proceed to the next step of this workflow.
- On a separate device, download and install Apple Configurator 2. You'll use this device to enroll the managed endpoint. You can obtain this application from the Mac App Store.
- Once the application is installed, proceed to the next step.
Create a WiFi profile
- In Apple Configurator's top navigation menu, click File > New Profile.
- In the window that opens, on the General tab, enter a profile name in the Name field.
- In the left navigation menu, select WiFi.Then, click Configure.
- Input the settings of the WiFi network to which the device should connect.
- In Apple Configurator's top navigation menu, click File > Save.
- When prompted, save the file in a location that you will be able to access in the next steps of this article.
Create a blueprint
- In Apple Configurator's top navigation menu, click File > New Blueprint.
- Specify a blueprint name.
- Click the blueprint. Then, click Add > Profiles.
- Select the WiFi profile you created in the previous section of this article and click Add.
Prepare the blueprint
- Click the blueprint. Then, click Prepare.
- In the Prepare Devices window, select Prepare with > Manual Configuration.
- Ensure that the Supervise devices check box is selected.
- Click Next.
- On the Enroll in MDM screen, click Server > New Server. Then, click Next.
- On the Define an MDM Server screen, input VSA in the Name field.
- In the Host name or URL field, enter the enrollment link URL from the USB pane on the MDM Enrollment page.
- Apple Configurator will fetch and add your trust anchor certificates. Click Next.
- You may be prompted to sign in to Apple School Manager or Apple Business Manager. You can do so, or you can skip the step.
Create an organization
- On the Create an organization screen, define the name of the organization with which this device will be associated. Then, click Next.
- When prompted, select Generate a new supervision identity and click Next.
- The Configure the iOS Setup Assistant screen will appear. Make any desired selections.
- Click Prepare.
Apply the blueprint to the device
- Via USB, connect the device you're enrolling to your current desktop or laptop computer.
- In Apple Configurator, right-click the device, select Apply, and choose the blueprint you created.
- Click Apply.
- Apple Configurator will apply the blueprint. It may take several minutes for this process to complete and the new device to index in the MDM server. Once the enrollment process is complete, the device will become available to manage on VSA 10's Device List page.
BEFORE YOU BEGIN You must create an Apple MDM Push Certificate connector for the organization you wish to configure ADE for. Refer to Create an Apple MDM Push Certificate connector in VSA 10.
By completing the following steps, every device assigned to a dedicated MDM server within Apple Business Manager will automatically be added to a specified agent group within your VSA 10 account:
Create an Apple Automated Device Enrollment connector in VSA 10
- From the left navigation menu in VSA 10, navigate to Integrations > Connectors > Apple MDM.
- Click Create Connector.
- On the Create Connector page, select the Apple Automated Device Enrollment connector type from the Type drop-down menu.
- Select the organization and site associated with the devices you wish to automatically enroll.
-
NOTE The Organization Name field displays an error message if the selected organization is missing an Apple MDM Push Certificate connector, which you must configure first. Refer to Create an Apple MDM Push Certificate connector in VSA 10.
- Select the specific agent group in which the devices will be automatically enrolled.
- Optionally, enter a phone number and/or email address at which your support team can be reached, which users will see during device activation.
- Click Next.
- Click Download Public Key. VSA 10 will transfer a Privacy Enhanced Mail (PEM) file named ABM_Public_Key.pem to the default download location on your computer.
- In the Generate New Server Token section, click Go to Apple Business Manager.
- Without closing the Create Connector page, log in to Apple Business Manager and proceed to the next section.
Upload the public key to Apple Business Manager
- In Apple Business Manager, click your name at the bottom of the sidebar and select Preferences.
- Click MDM Server Assignment, then click Add .
- Enter a unique name for the server.
-
NOTE If you don’t want this MDM server to have the ability to release devices, refer to Release devices in the Apple Business Manager User Guide.
- Upload the ABM_Public_Key.pem file you downloaded from VSA 10 in the previous section.
- Click Save.
- Click Download MDM Server Token .
- In the confirmation dialog box, click Download MDM Server Token.
Upload the server token to VSA 10
- Return to the Create Connector page in VSA 10 and locate the Upload Server Token section.
- Add the .p7m server token file you downloaded from Apple Business Manager by dragging it into the Drag your server token file here box or by clicking the box and selecting the file to upload. The server token upload success will be validated.
- Confirm the ID you used to generate the server token by entering it in the Apple ID field.
- Click Create.
For more details, refer to ADE behavior.
To unenroll a device from MDM, perform the following steps:
- Locate VPN & Device Management in the device's settings.
- Open the MDM profile.
- Click Remove Management.
- VSA 10 will automatically remove the device from your platform.
VSA 10 MDM commands
Once you've enrolled a device in MDM, the following commands will become available on devices pages in VSA 10.
NOTE Availability of any command is dependent on both the device type and enrollment method used.
Command | iOS/iPadOS | macOS | |
QR code enrollment | USB enrollment | Link enrollment | |
Non-supervised | Supervised | Supervised | |
Restart | FALSE | TRUE | TRUE |
Shutdown | FALSE | TRUE | TRUE |
Enable/Disable lost mode | FALSE | TRUE | FALSE |
Play Lost Mode Sound | FALSE | TRUE | FALSE |
Erase | FALSE | TRUE | TRUE |
Lock | FALSE | TRUE | TRUE |
Next step: Configuring Apple MDM profiles
After a device completes the enrollment process, any configuration or management policies you've defined for its type will automatically apply. For more information, refer to VSA 10 MDM: Apple MDM profiles.
MDM FAQ
The following answers to frequently asked questions will help you get the most out of your VSA 10 MDM experience.
Refer to Compatibility.
No. Currently, you'll see a Device is not supported error when you attempt to do so.
The available enrollment types are as follows:
- Automated Device Enrollment: Leveraging Apple Business Manager, devices can be preconfigured with specific management settings as soon as they are powered on, bypassing manual setup steps and streamlining the onboarding process. This ensures that devices are enrolled in mobile device management (MDM) from the start, offering zero-touch deployment for organizations.
- QR Code and Link: QR code enrollment is intended for personal (BYOD) iOS and iPadOS devices. Link enrollment is required for macOS devices, but you can also use it for iOS and iPadOS.
- USB using Apple Configurator: This enrollment type is intended for business or corporate-owned devices and enables additional management capabilities. Currently, it only supports iOS and iPadOS devices.
While being powered on doesn't matter, the iPhone should not be initialized. Connect the phone to USB and follow the steps described in the USB using Apple Configurator section of the article. The device will be erased and the new blueprint applied.
Apple recommends clearing the device when it is enrolled as supervised. However, if you back up the primary device to a secondary device before enrolling it, you can restore the backup from the secondary device to the primary device after you complete the enrollment. To do so:
- Ensure that Find My iPhone is off on both devices to avoid problems during enrollment.
- Use AppleConfigurator or Finder to back up the primary device.
- Restore this backup on the secondary device.
- Use AppleConfigurator or Finder to back up the secondary device.
- Restore the backup of the secondary device to the primary device.
- After restoration, when the primary device shows the Welcome screen on activation, connect it to Apple Configurator and enroll it via the USB method.
- After activation, the device should appear in VSA 10 and contain the restored data.
USB enrollment is only available for macOS devices compatible with Apple Configurator.
Supervised mode provides more options to manage the device, such as restarting, shutting down, and enabling or disabling lost mode. The Play Lost Mode Sound will work only for supervised devices.
macOS devices are always supervised. iOS and iPadOS devices are supervised if they have been enrolled via USB with the Supervised option checked. You can find out if a device is supervised in the Asset Info section of the device details pane:
There might be a delay in seeing an enrolled device or its data.
Apple does not terminate its requests. However, VSA 10 has a 20-minute cache and pings MDM services every 15 minutes to get device information.
So, if you enroll, unenroll, change lost mode, or perform any other actions with a device, there may be a delay in reporting this information to VSA 10. If you have been waiting for more than one hour and still do not see a device, please open a ticket with Kaseya Support for assistance. When doing so, be sure to include the device's serial number.
Due to Apple limitations, the following conditions apply to MDM-enrolled devices:
- Devices enrolled via QR Code and Link only have access to the Erase command.
- Devices enrolled via USB using Apple Configurator have access to the following commands:
- Restart
- Shutdown
- Enable/Disable Lost mode
- Play Lost Mode Sound (if Lost Mode is enabled)
- Erase
- macOS devices enrolled in MDM without the VSA 10 agent app installed have access to the following commands:
- Restart
- Shut down
- Erase
Refer to VSA 10 MDM commands for a complete table of commands and their availability.
Yes. To take advantage of full VSA 10 management capabilities, you should both enroll a macOS device in MDM and have an agent installed. There is no preferred order to doing so; the process will not create duplicate devices.
There could be several reasons why a command did not execute:
- To get and process MDM commands, a device must have an internet connection. All types of internet connections are supported; Apple IDs and SIM cards are not required.
- VSA 10 sends commands to Apple right after you click the action button, but we cannot control how long the queued action will take to be relayed to the device and executed. The action may be awaiting processing.
- If a device is in sleep mode or turned off, it can not process commands. In some cases, Apple sends the same command periodically until a device is awake or until the command times out.
- If a command times out, and Apple returns a status that the device is unavailable, our MDM server will try to send the command at the following intervals:
- Five minutes after the first request
- 10 minutes after the first request
- 20 minutes after the first request
- 40 minutes after the first request
- If a command times out, and Apple returns a status that the device is unavailable, our MDM server will try to send the command at the following intervals:
Erasing is similar to a factory reset. All of the device's data, including the MDM profile, is deleted, and the phone is returned to its initial setup state. Erased and unenrolled devices must follow the enrollment process before they can be managed again.
Lost Mode is a feature available on Apple devices that you can use when your device is missing or stolen. When you activate Lost Mode, the device locks to prevent anyone else from accessing its data. You can activate this mode via MDM on iOS and iPadOS device. You can also display a custom message with a contact number on the Lock screen.
No. Apple does not provide a way to set up a passcode for a device with Lost Mode. However, it is possible to set up a lock screen message or phone number in the confirmation popup after you click Enable Lost Mode.
Refer to the Unenroll a device section of this article.