Add an ABM server token

Apple's Automated Device Enrollment, also known as zero-touch enrollment, lets you automate and simplify the initial device setup process by enrolling and configuring a device when the user turns it on. Automated enrollment is possible if your customer has an Apple Business Manager (ABM) or Apple School Manager account, and the devices are new purchases or if they are existing devices that have been wiped.

To set up Automated Device Enrollment for a customer, you generate an ABM server token using your customer's ABM account and add it to Device Management for Apple.

Server-token relationship

Mobile Device Management servers in ABM and their corresponding tokens establish the environment for Automated Device Enrollment. Each ABM server token needs to be associated with a customer and added to Device Management for Apple.

When managing devices, ABM server tokens provide:

Security: ABM server tokens securely link the customer’s ABM account with Device Management for Apple. The token ensures that only authorized MDM servers can enroll and manage devices associated with the ABM account.

Enrollment: When a device is assigned to an MDM server in ABM and activated by the end-user, the ABM server token allows the device to automatically enroll.

Control: Separate ABM server tokens can be generated for each server. This granularity allows management of devices based on their intended use or department association.

Requirements

  • Ensure the Apple Push Notification Service (APNS) certificate for the customer is valid. If it needs to be renewed, see Renew Apple Push Certificate.
  • Ensure the customer has an Apple Business Manager of Apple School Manager account.

Add an ABM Server token for a customer

You can add multiple ABM server tokens to Device Management for Apple from one customer ABM account by repeating this procedure for each token. For example, if a customer has multiple sites, you can add an ABM server token for each site.

You assign devices to specific ABM server tokens by assigning the devices to an MDM server. For more information, see Assign devices to your DMA MDM Server.

  1. On the vertical menu, select Dashboards > Device Management for Apple > Auto-Enrollment.
  2. Select Add ABM server token.
  3. Select the target Customer and Site to associate with this ABM server token and click Next.

    When devices associated with this ABM server token automatically enroll in Device Management for Apple, they display in N-sight RMM under this Customer and Site.

  4. Click Download public key and click Next.

  5. Select Create new ABM server token and click the Apple Business Manager link to sign in with your customer's account.

  6. In Apple Business Manager, follow these steps:
    1. Select the account name and select Preferences.
    2. Select MDM Server AssignmentAdd MDM Server.
    3. Enter the name of the server to associate with the ABM server token.
    4. Under MDM Server Settings, select Choose File and select the public key you downloaded from Device Management for Apple.
    5. Select Save to generate the ABM server token.
    6. Select Download MDM Server Token.
    7. Select Download MDM Server Token from the pop-up window and save to your device.
  7. In the Device Management for Apple wizard, select Next.

  8. Click browse, or drag and drop the new ABM server token from your directory and upload it to Device Management for Apple.

    The Automated Device Enrollment instance is added to Device Management for Apple and the new ABM server token is added to the Apple Business Manager tab.

    You can add as many ABM server tokens to Device Management for Apple as you need because each of your customers will have their own token or multiple tokens.

Next Steps

Related articles

Updated: Jul 05, 2024