Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Simple steps to set up new ipads DEP and Meraki MDM


Recommended Posts

Posted

I have done this before but it was 10 years ago.

School Manager is set up.

I have a new mac mini.

The ipads are listed under school manager.

I am waiting for the meraki licensing to come through.

 

I don't mind researching the steps, I would love someone to give me an idea what those steps are.

 

As far as i am aware, I set up a new meraki network, add the licences for the mdm to it.

Add the apple certificate that i create in school manager.

Then do the MDM profiles student , teacher ect.

I want to set them up without apple ids as they will be shared devices.

 

So is this still correct?

 

Now the real questions.

 

I am unsure about supervision, where to enable, would you use apple configurator, or enable via school manager.

 

Is there a way of automating the initial setup. So I don't have to manually go through 75 setups adding wifi answering the questions ect to get to the point where meraki mdm app is installed.

 

Any help, I just don't want to royaly mess things up. So any resources, guides or even a list of things to read up on. even a list of steps that you recommend.

Posted

I'd assume Meraki has the same functionality but in Jamf I have a device enrollment policy which allows me to skip the majority of a new iPad setup.

 

- New device is purchased and added to ASM

- Change MDM provider for the device in ASM to Jamf.

- Device should now appear in Automated device enrollment in Jamf - Add default ADE policy to device.

- Turn on device and add wifi. It then adds Jamf remote management & ade policy which skips majority of setup.

- Device appears fully in Jamf - Assign profile/change name.

Done.

 

I only really use my mac mini for any older devices that aren't added to ASM on purchase (I.e refurbished Iphones)

 

Looks possible in Meraki aswell https://documentation.meraki.com/SM/Device_Enrollment/Apple_Automated_Device_Enrollment_(ADE)

  • Thanks 1
Posted

That is exactly what I wanted to know.

I had worked out that they are supervised just by being dep enrolled to asm.

Apple just makes me stressed about messing up and doing something stupid.

 

BTW I posted this in the wrong forum, just saw the sticky. Sorry. :-(

Posted
That is exactly what I wanted to know.

I had worked out that they are supervised just by being dep enrolled to asm.

Apple just makes me stressed about messing up and doing something stupid.

 

BTW I posted this in the wrong forum, just saw the sticky. Sorry. :-(

 

Yeah the initial setup can be a little daunting!

Some of the things I did which I'd assume all apply to Meraki

 

 

You'd need an Apple push certificate which links Apple push to your MDM, I think I made a managed apple id in ASM and used that direct with Apple. https://documentation.meraki.com/SM/Device_Enrollment/Apple_MDM_Push_Certificate

Supervision identity - MDM download - add it to ASM.

Volume Purchasing - ASM to MDM (Under payments & billing on asm)

ADE deployment - Add a certificate both ways.

  • Thanks 1
Posted
That is exactly what I wanted to know.

I had worked out that they are supervised just by being dep enrolled to asm.

Apple just makes me stressed about messing up and doing something stupid.

 

BTW I posted this in the wrong forum, just saw the sticky. Sorry. :-(

I noticed you said these devices are going to be shared devices. You can take advantage of the new shared mode in which you assign a class of users to iPads and they sign in using their Apple ID passcode. This way you also stop users signing into personal accounts in the browser.

Posted
I noticed you said these devices are going to be shared devices. You can take advantage of the new shared mode in which you assign a class of users to iPads and they sign in using their Apple ID passcode. This way you also stop users signing into personal accounts in the browser.

Very interested in this - does it work reliably enough? $64k question is can it in any way be linked to 365 accounts for the logins?

 

Also was it a pain to set up?

 

Sorry to hijack!

Posted
Very interested in this - does it work reliably enough? $64k question is can it in any way be linked to 365 accounts for the logins?

 

Also was it a pain to set up?

 

Sorry to hijack!

 

You can federate your domain with Office 365 so the managed apple ids become your users office 365 logins. We've not done this yet but I believe it requests the user to set a pin when they first sign in using their office 365 account.

 

It's not much more of a pain to setup than a 1:1 device. As part of the prestage enrolment you tell it to be a shared device. I would trial it before hand with some users to see how they get on with it.

  • Thanks 2
Posted
I noticed you said these devices are going to be shared devices. You can take advantage of the new shared mode in which you assign a class of users to iPads and they sign in using their Apple ID passcode. This way you also stop users signing into personal accounts in the browser.

 

It is a case of keep it simple.

We already have in excess of 400 windows laptops with their own user accounts.

Plus a computer suite, and 50 staf computers. 24 IWB

The ipads are literally going to be used as cameras and with a few managed apps.

On the hours I have I have to keep admin to a minimum. 27hrs does not go far on a network of this size.

The ipads will be locked down with meraki, and it is for primary school kids. also the wifi network they are on is heavily restricted.

It is the way it has been done before, so here's hoping it will be good enough for the next 6 years.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...