Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi,

 

Hoping someone can help.

 

Ultimately I need to procure an iPad. With being Windows/Android to date; what necessary steps do I need to take to ensure the device it is 'education' compatible and /or can be managed via Intune? (fully aware other MDMs exist, but we use Intune extensively).

By that, does it need to be procured from an Apple Education supplier initially? (to get some Apple / VPP, or other???). Then I presume some form of Apple account needs creating?

 

Whilst the decision to obtain one wasn't mine, I am ensuring that it will be configured/managed correctly and compliantly.

 

Thanks,

Posted

You will need to register with Apple School Manager & get your DEP/VPP code. You can then give this to your reseller who will ensure that any device you buy is pre-locked to your school.

 

If you don't do this, you can register an off-the-shelf iPad into Apple School manager, but anyone can remove it for up to 14 days after install - Avoid this by doing the above.

 

I buy our iPads from KRCS & manage via Intune. We use the smoothwall cloud browser (& block all others) that automatically picks up the student's username & filters them properly when offsite.

 

Don't be scared of them, iPads are some of the easiest things to manage from an education POV & can be made KSCIE compliant fairly easily.

  • Thanks 1
  • 2 weeks later...
Posted

Update, slowly working through this...

 

Apple School Manager account setup, Reseller ID, MDM / VPP certificates all done.

 

Now... I've added our domain(s) and linked to Microsoft Entra ID and was just about to federate and was advised of "XX User Name Conflicts".

 

I believe these relate to Personal Apple IDs that have been created using our school's domain. Further research has concluded that (even as an ASM Administrator) I cannot see the list of conflicting Apple IDs (due to privacy!) and affected user(s) have 60 days to update/change. One method I found to ascertain who these users are, was to monitor emails originating from "[email protected]".

 

Ultimately, I am still only testing (learning) over the coming months in managing Apple (via ASM/Intune), but the next stage (e.g. federation) I am concerned about because I assume that "ALL" accounts within our M365 AAD will sync across (and auto create managed Apple ID accounts?). Even though I only want a test (or specific) accounts initially? Plus I've read that all accounts may be imported (as students)????

 

Essentially, I do not want to sync with our MIS, or potentially (auto) create Managed Apple IDs for all (federated) users. I simply want to be able to manage iPad(s) via Intune for specific user(s) at this current time. Does this mean once "ALL" accounts have been synced, I would have to update Staff accounts to Staff, and disable all the other accounts that I don't want an Managed Apple ID for? And then there's Apple Data Processing & Handling (e.g. DPIA required) too.

 

I appreciate any new system is a steep learning curve, but any advice / guidance would be really appreciated.

Posted

Federation between ASM and Entra only takes place in ASM it makes zero impact on other accounts and while it will create a MAID in ASM you don't have to use these. Users enable the account by signing into an iPad or Mac with their credentials, ultimately you are better off but if you don't want to use Federated account yet you don't have to.

 

With federated any users who have used the schools domain for a Personal Apple ID will have to change this, if they ignore this it will get changed automatically after 60 days.

  • Thanks 1
Posted (edited)
Federation between ASM and Entra only takes place in ASM it makes zero impact on other accounts and while it will create a MAID in ASM you don't have to use these. Users enable the account by signing into an iPad or Mac with their credentials, ultimately you are better off but if you don't want to use Federated account yet you don't have to.

 

With federated any users who have used the schools domain for a Personal Apple ID will have to change this, if they ignore this it will get changed automatically after 60 days.

 

Thanks @Brimstone

 

Whilst I understand that whilst I am still 'testing' there is no requirement to Federate etc., at least by enabling that option this will (eventually) revoke the conflicting users who have created (and are using) school/work emails for Personal Apple IDs (within 60 days time). - Is that correct?

 

For clarity, you mentioned that once federated it will create MAID within ASM - but I don't have to use them. But what about if I didn't want (certain) MAID accounts to be able to log into an iPad/Mac at all? And/or would this only be possible on managed (school) Apple devices as opposed to any Apple device (e.g. personal)? Is the restriction within ASM? Or possibly within Entra Admin Centre > Enterprise Applications > Apple School Manager (e.g. define user / groups?)

 

Sorry for the noob questions, but any advice is much appreciated!

Edited by MYK-IT
  • 5 months later...
Posted (edited)

Due to various circumstances, I have only had opportunity to continue further with this, progress so far:

 

ASM & Intune MDM working (e.g. ASM, Intune, VPP Token etc) following various guide including

https://www.prajwaldesai.com/enroll-ios-ipados-devices-in-intune/

https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-ios-ipados

 

Apple School Manager

I have setup ASM using Managed Apple Account, and configured MDM (Intune) with device(s) showing.

 

I have configured our school sub/domains with some name conflicts alerts (I believe impacted accounts have 60-days to change to personal etc)

Do I need to enable “Sign In with Microsoft Entra ID” too?

 

Intune

Connectors and Tokens | Apple VPP Tokens – Setup and working

iOS/iPadOS | Enrolment – Setup and working

 

Device Restrictions

I have some settings configured.

A combination of obvious and those suggested from

https://learn.microsoft.com/en-us/mem/intune/industry/education/tutorial-school-deployment/common-config-ipads-device-restrictions?tabs=settings

https://learn.microsoft.com/en-us/intune-education/edu-express-config-settings-ios

https://learn.microsoft.com/en-us/intune-education/all-edu-settings-ios

 

But would appreciate some advice of settings / templates that others use.

 

Apps

After initially adding Apps from the Apple Store, and deploying to the test iPad I soon realised this was the wrong way of doing it. As these are from the Apple Store and requires sign-on (which I’ve disabled) and I need to add the Apps via Apple School Manager! Which I have managed to deploy ok.

 

In relation to the default/stock Apps, how do others configure / manage these? As some work, but others need to sign in to Apple Store (as not a VPP deployed APP) so I assume I need to setup Device Configuration to Hide such Apps?

I have tested using Hide Apps using Bundle IDs using info from https://learn.microsoft.com/en-us/mem/intune/configuration/bundle-ids-built-in-ios-apps and they do remove the Apps I’ve tested etc.

 

Even if I wanted to keep some of the stock Apps, would I still need to Hide them, and redeploy the (same) App via ASM (then Intune)?

 

Settings / Device Configuration

Are there recommended settings / options to apply that anyone is happy to share?

 

Initially for assigned 1:1 user only; but I know you can setup as Shared Device but aware certain things don’t work or work as expected.

 

I would really appreciate some suggestions / help, as newbie to using Apple, iPad, ASM etc.

 

Many Thanks,

Edited by MYK-IT

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...