iOS, iPadOS and tvOS device setup
Supervision let you to completely manage iOS device with high level permissions.
Enrollment is the procedure that connects your device to the MDM and allows the remote management (Over
The Air).
Supervision and enrollment follows Apple standards.
[edu]
Supervision and enrollment are necessary if students have to use Chimpa Learn.
[/edu]
Any in-depth information on the tools indicated can be found on Apple materials, available at these links:
• https://www.apple.com/en/support/business-education/apple-configurator/
• https://help.apple.com/configurator/mac/2.2/
iOS (9.3 or newer)
To supervise and enroll iOS devices you can:
- Use an Apple Deployment Program (Apple Business Manager / Apple School Manager). In Apple School
Manager you can also configure Shared iPads. - Use Apple Configurator 2.
[noWhitelabel]
- Use Chimpa Apple Configurator Helper for the first configuration of iOS devices.
[/noWhitelabel]
To enroll a device in use (not supervised) follow:
- Enroll iOS device with an enrollment profile
- Enroll iOS device with iOS 13.1 User enrollment (ABM and Managed Apple ID needed).
[edu]
NOTE: Teacher’s iPad cannot be supervised. Enrollment is recommended to get better experience with Apple
Classroom or Apple Volume Purchase Program integration in Chimpa Bazaar.
[/edu]
Supervision and Enrollment over-the-air with an Apple Deployment Program
To supervise and enroll iOS devices you can:
- This procedure is reserved only for orders done through Apple resellers or devices added on DEP manually with Apple Configurator 2.
- Apple Push Certificate services and ABM or ASM must be configured.
- Check if license slots are available under Ermetix Admin > License.
- On Apple Deployment Program site (business.apple.com o school.apple.com), click on Device Assignments and specify serial numbers / order numbers to “Assign to server” Ermetix UEM.
- In Ermetix Admin in Global Settings > Apple > Deployment Program select options “Supervise” (needed only for iOS versions older than 13), “Do not allow user to skip enrollment step”, “Prevent unenrollment”. If you want to set and iPad as a “Shared iPad” you can select them from the list of compatible devices.
- Follow the Setup Assistant on the device and i twill be supervised and enrolled automatically. Ermetix UEM server will start to set policies and deploy apps. If device is already set you have to wipe and restart the Startup Assistant passing through Remote Management screen. App auto installation could need an Apple ID.
[noWhitelabel]
Supervision/Enrollment with Chimpa Apple Configurator Helper
- This operation need a MAC (Macbook, iMac, Mac Mini, Mac pro…) with OS X 10.11.5 or newer and configuration applies only on iPad devices.
Alternatively you can use a Virtual Machine, in respect of Apple license agreeement: some virtualization software can have problems simulating USB interfaces. - Apple Push Certificate services must be configured.
- Check if license slots are available under Chimpa Admin > License.
- Disable “Find my” on your iOS devices.
- Download and install Apple Configurator 2 from the Mac App Store: https://apps.apple.com/us/app/apple-configurator-2/id1037126344?mt=12
- Devices will be wiped (all data will be removed).
- Login into Chimpa Admin as an Admin, go in “Devices Enrollment”, under “Apple” click on “Chimpa Apple Configurator Helper” to start the download.
- [ADVANCED] You can import Organization in Apple Configurator 2 if you have set up previously iOS devices from an other Mac. (http://help.apple.com/configurator/mac/2.0/#/cadE65ABDCD).
- Connect devices via USB to the Mac (you can use USB hubs to make multiple configurations at the same time)
- Unzip file “ChimpaAppleConfiguratorHelper.zip”.
- Move “ChimpaAppleConfiguratorHelper.app” in Applications folder.
- Secondary click (or ctrl + click) on “ChimpaAppleConfiguratorHelper.app”, select “Open” and click on “Open” from the dialog. This operation is needed only the first time you run this app.
- Follow wizard steps, this utility will supervise and configure enrollment for iOS devices. If you get some error try with manual configuration via Apple Configurator 2.
[/noWhitelabel]
Supervision/Enrollment with Apple Configurator 2
- This operation need a MAC (Macbook, iMac, Mac Mini, Mac pro…) with OS X 10.11.5 or newer. Alternatively you can use a Virtual Machine, in respect of Apple license agreement: some virtualization software can have problems simulating USB interfaces.
- Apple Push Certificate services must be configured.
- Check if license slots are available under Ermetix Admin > License.
- Disable “Find my” on your iOS devices.
- Download and install Apple Configurator 2 from the Mac App Store: https://apps.apple.com/us/app/apple-configurator-2/id1037126344?mt=12
- Devices will be wiped (all data will be removed). You cannot restore from a backup so is recommended to sync iCloud data. If you have additional data save on cloud services like Google Drive or Dropbox.
- Connect devices via USB to the Mac (you can use USB hubs to make multiple configurations at the same time)
- Select devices you want to configure, right click > Advanced > “Erase all content and settings” to speed up the preparation, if you need to update iOS you can use right click > Restore (more time needed to download latest version of iOS).
- Now you can click “Prepare”
- On “Configuration” select “Manual”
- On “Enroll in MDM server” select “New server...”
- Login into Ermetix Admin as an Admin, go in “Devices Enrollment”, under “Apple” click on “Enrollment URL” to copy the URL in the clipboard.
- Insert the Name “Ermetix UEM %SCHOOL_ID%”, and paste the clipboard into the “Hostname or URL” field.
- Select checkbox “Supervise” and, if needed, “Allow pairing with any Mac”
- If you haven’t one create a new “Organization” specifying organization information.
- In “Configure iOS Setup Assistant” customize settings or leave default option “Show all steps”.
- [ADVANCED] If you also have an Apple Deployment Program, you can export supervision identities from “Apple Configurator 2” > Preferences > Organizations, select the and click on “Export Supervision Identity” from the gear action menu. Save file to P12 format leaving empty password. Upload this file to the Ermetix Admin, in the section “Supervision Identities” of Global Settings > Apple > Deployment Program.
Enroll iOS device with an Enrollment profile
- Login into Ermetix Admin as an Admin, go in “Devices Enrollment”, under “Apple” click on “Enrollment profile management” to create a profile to send to the device manually or via email (with QR Code)
- Apple Push Certificate services must be configured.
- Check if license slots are available under Ermetix Admin > License.
- Enrollment profile can be deployed:
a. using Apple Configurator 2, when you Prepare devices;
b. using Apple Configurator 2, selecting devices > secondary click > Advanced > Add > Profiles;
c. sending an email attachment, using Airdrop or generating a link on a cloud provider; - Open the enrollment profile onto the device. If you have any problem opening, copy it to Apple Files and open it directly from there. Now tap on the profile into Settings > Downloaded profiles.
- Procede with the requested steps: agree, authenticate, confirm.
- On iOS and iPadOS 15+, Chimpa Agent will be installed automatically; when done open it and allow requested pemissions.
Enroll iOS user with User enrollment profile (iOS 13.1 and newer)
- Apple Push Certificate services and ABM or ASM must be configured.
- Check if license slots are available under Ermetix Admin > License.
- Login into Ermetix Admin as an Admin, go in Management > Users and authorize the account related to the Managed Apple ID. Managed Apple ID can be created on ABM or ASM. If you don’t find the account on Ermetix Admin you can add them specifying the same username used for the Managed Apple ID.
- At this point, verify if user is already authorized from user info view or click “Enable Apple User Enrollment” from the action menu of the user.
- Login into Ermetix Admin as an Admin, go in “Devices Enrollment”, under “Apple” click on “User Enrollment profile” > select the user to start the download.
- Enrollment profile can be deployed sending an email attachment, using Airdrop or generating a link on a cloud provider.
- Open the enrollment profile onto the device. If you have any problem opening, copy it to Apple Files and open it directly from there. Now tap on the profile into Settings > Downloaded profiles.
- Procede with the requested steps: agree, authenticate, confirm.
- On iOS and iPadOS 15+, Chimpa Agent will be installed automatically; when done open it and allow requested pemissions.
User-driven iOS enrollment via Settings (iOS 15 and newer)
- Apple Push Certificate services and ABM or ASM must be configured.
- Apple Autodiscovery must be configured on Managed Apple ID's domains. Apple Autodiscovery setup for user-driven enrollment
- Check if license slots are available under Ermetix Admin > License.
- Login into Ermetix Admin as an Admin, go in Management > Users and authorize the account related to the Managed Apple ID. Managed Apple ID can be created on ABM or ASM. If you don’t find the account on Ermetix Admin you can add them specifying the same username used for the Managed Apple ID.
- Login into Ermetix Admin as an Admin, go in “Devices Enrollment”, under “Apple” click on “User Enrollment profile” > select the user to start the download.
- On device, go to Settings > General > VPN & Device Management and tap on Sign in to Work or School Account
- Procede with the requested steps: agree, authenticate, confirm.
- Chimpa Agent will be installed automatically, when done open it and allow requested pemissions.
NOTE: On Devices Enrollment in Ermetix UEM you can have access to all links an tools needed for device enrollment and configuration. If you want to block and increase the security of enrollment you can enable Global Settings > “Enable Guest Device Enroll” to restrict only placeholders or DEP authenticated devices.