Jump to content

Recommended Posts

Posted

I just wanted to double check that my understanding of the tokens / certificates required by an MDM is correct:

 

- x1 APNS certificate that allows MDMs to configure settings such as passcodes etc

- x1 Apps and Books certificate that allows the MDM to access licences from Apple School Manager: Apps and Books

 

?

Posted (edited)

(Using Jamf School as the example).

 

  • Automated Device Enrollment Token - Obtain from Apple School and insert into your MDM of choice
  • Volume Purchasing Token - Obtain from Apple School and insert into your MDM of choice
  • Apple Push Certificate - Create CSR from your MDM, login to https://identity.apple.com/pushcert (using a [email protected] account**) and request the cert. Insert generated push cert into MDM.
  • (Optional*) SCIM Token for Azure AD - Obtain from Apple School, insert into Azure AD.

 

The first three must be renewed every 12 months. The SCIM token is good for 24 months.

 

*wherever possible (assuming 1-2-1 iDevices) we tie authentication into the Office 365 identity.

**don't use a person@school or it@school email

Edited by pete
Posted
(Using Jamf School as the example).

 

  • Automated Device Enrollment Token - Obtain from Apple School and insert into your MDM of choice

 

The 1st time you do this, before you download the server token file from ASM and add it to your MDM, you must download the public .pem file from your MDM and upload this file to ASM, then download the private key from ASM and upload to your MDM.

 

 

  • Volume Purchasing Token - Obtain from Apple School and insert into your MDM of choice
  • Apple Push Certificate - Create CSR from your MDM, login to https://identity.apple.com/pushcert (using a [email protected] account**) and request the cert. Insert generated push cert into MDM.
  • (Optional*) SCIM Token for Azure AD - Obtain from Apple School, insert into Azure AD.

 

The first three must be renewed every 12 months. The SCIM token is good for 24 months.

 

*wherever possible (assuming 1-2-1 iDevices) we tie authentication into the Office 365 identity.

**don't use a person@school or it@school email

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...