Apple Device Management For Beginners
Apple Device Management For Beginners
Apple Device
Management
FOR BEGINNERS
According to Forbes, Apple device growth in the
enterprise is 20% year over year.
As Apple device adoption rises in business and education environments around the globe, it’s
imperative that technology investments are maximized so that organizations can leverage Mac,
iPad, iPhone and Apple TV to their full potential. This can put a heavy burden on IT staff that are
now tasked with managing this influx of new devices – especially those of you in established
Windows environments. And as the shift to remote work, distance learning and adjusting to
working and learning anywhere becomes the new normal, managing devices from startup to
ongoing support is critical.
While some are very familiar with Apple already, many of you are diving into Apple
device management for the first time. This guide is for the latter, and will help you
build and master your Apple management skills by providing:
Introduction
and management commands.
These components communicate to the device via Apple’s Push Notification service
(APNs), which is kept private to your organization through obtaining a secure
to Apple device certificate from Apple. Apple’s server then maintains a constant connection to
devices so you don’t have to. Devices communicate back to your management server
management
and receive commands, settings, configurations or apps you define.
This agent enables a hidden admin account to be added, allowing for remote root access
to macOS and opens the door for more policies and scripts to be run on a computer.
Since agent-based Mac management goes beyond the built-in MDM, you need a third-
party solution, like Jamf, to take advantage of advanced Mac management.
programs
ID and automatically enroll a device into education institution, your instance is built
management under an Apple management directly within Apple School Manager (see
solution. Automated Device Enrollment next page).
enables you to provide a great zero-touch
As Apple devices became more popular in experience for end users. They simply
the enterprise and education, challenges open up the box, turn on the device
and get to work — regardless of if your
arose about how to best deploy devices
employees is on-site or remote.
at scale, how to address Apple IDs
and the purchasing of apps. Apple, of
Device Apple IDs
course, looked to solve these issues and
introduced various programs and services
Supervision
to take device management one step Supervision is a special mode of iPadOS, Apple IDs are the personal account
further, making it easier and more cost iOS and tvOS management where IT is credentials users use to access Apple
effective to manage devices in bulk. granted greater control over devices services such as the App Store, iTunes
they own when enrolled via Automated Store, iCloud, iMessage and more.
Not every Apple device management Device Enrollment, User Approved MDM Depending on the needs of your
or Apple Configurator. A large number of organization, your end users can leverage
solution supports Apple’s programs and
management features including Managed their Apple ID on the job, or you can avoid
services. Check with your vendor to Lost Mode, blocking apps and silently using Apple IDs altogether. If you’re an
ensure they support these programs, as installing apps all require supervision. education institution, your students will
It is recommended that corporate-owned receive a different type of Apple ID (see
well as the incremental changes Apple
and school-owned devices be put into next page).
makes throughout the year. supervision mode.
Apple School Manager Apple Business Manager
Launched in 2017, Apple School Manager is a web-based portal Apple Business Manager is the platform for IT teams and businesses
for IT administrators to oversee people, devices and content – all to pair with an MDM solution to automate device deployment, app
from one place. Exclusively for education, Apple School Manager deployment and purchasing, and content distribution. Similar to Apple
combines Automated Device Enrollment and volume purchasing of School Manager, it combines the power of Automated Device Enrollment
Apps and Books and other classroom management tools, such as and volume purchasing in one central location.
the Classroom app, in one portal. Apple School Manager enables
Managed Apple IDs and Shared iPad and can be integrated with
your school’s Student Information Systems (SISs).
Shared iPad
Lifecycle
3 App 4 Inventory
management management management
management framework —
available for macOS, iOS, iPadOS
and tvOS — and aids with these
From initial deployment to the end-user experience, it’s critical to understand,
functions:
manage and support the entire lifecycle of the devices in your environment.
This ensures both the security and maximized potential of your Apple devices.
1 Deployment and Provisioning
Before configuring devices for end users, devices must be enrolled into management within an MDM solution.
There are several enrollment methods available, but the two highlighted below are recommended for enterprise and
education institutions looking for a streamlined and positive end-user experience:
Supervision
Description User Experience (iOS only) Best For
Automated Device
User receives shrink-wrapped
Enrollment with Automatic enrollment box, and the device is
Shipping devices to remote employees, students
Apple School Yes–wirelessly or to speed up the onboarding process.
over the air automatically configured when
Providing users with an out-of-box experience
Manager or Apple turned on
Business Manager
Purchase devices, add them to Device enrolls with the MDM server.
your MDM inventory and ship them Prepare any configuration profiles and apps
directly to users. you’d like to apply to devices.
Jamf can
automatically
configure
your iPad.
1 2 3 4 5
Sign up for Apple Business As a user turns their device on Device receives configurations
Manager and link your account for the first time, the device will and apps scoped to it, and the
to your MDM server. automatically be enrolled – no user is brought to the Home
additional interaction is needed. screen. The device is now
managed and configured – all
without IT having to touch it!
Purchase devices, add them Device enrolls with the MDM server.
to your MDM inventory and ship Prepare any configuration profiles and apps
them directly to users. you’d like to apply to devices.
Jamf can
automatically
configure
your iPad.
1 2 3 4 5
Sign up for Apple School As a user turns their device on Device receives configurations
Manager and link your account for the first time, the device will and apps scoped to it, and the
to your MDM server. automatically be enrolled – no user is brought to the Home
additional interaction is needed. screen. The device is now
managed and configured – all
without IT having to touch it!
Configuration management Don’t know where to start? Check out a list
2 of MDM configuration profiles here, or join
When it comes to configuring Apple devices, the world is your oyster. the conversation on Jamf Nation.
You can personalize and tailor individual devices or groups of devices based
on the needs of your end users.
Find and purchase app licenses from the web Invite users to participate in your
store. You will also need to “purchase” free apps. deployment via email or push notification.
Choose to assign
apps to either
devices directly
or to a user’s
Apple ID.
1 2 3 4 5
Sign up via Apple’s website and link Add your app licenses to your Apps are linked to a user’s Apple ID and are
your account to your MDM server. MDM server, including free apps. found in the Purchased tab of the App Store.
Find and purchase app licenses from the Apple School Manager Apps are deployed directly to the device.
web store. You will also need to “purchase” free apps. No interaction or Apple ID required.
1 2 3 4
Sign up for Apple School Manager and link Add your app licenses to your
your account to your MDM server. MDM server, including free apps.
Best Practice
Configuration profiles
Using an MDM solution, IT can define settings with tvOS configuration profiles
Check out our
and distribute them to Apple TV devices. As a result, Wi-Fi, restrictions and
AirPlay settings are more easily applied over the air. Further, Apple TV devices Apple TV Management
can be put in Single App Mode to customize the Apple TV experience by class for Beginners e-book.
or Conference Display Mode for an intuitive presentation workflow.
Smart targeting
With the ability to automatically collect inventory details, including Apple
TV device names from all managed devices, IT can quickly and accurately
identify which devices require action. Based on this inventory information,
IT can build targeted groups to trigger automatic device management tasks.
For example, IT can now find all Apple TV devices without AirPlay settings
configured and then deploy that configuration.
running?
1 2 3
4 5 6
Some management solutions even allow you to collect extra
Apply a Profile or Policy
(custom) inventory about specific hardware and software add-ons.
For example, you can figure out when a third-party backup utilitiy
last ran or what printer drivers are installed.
Static Groups are a set of devices that are defined, like a classroom or a lab.
You can apply a management policy to that entire group.
Smart Groups, on the other hand, are dynamic and always changing based
on inventory data. This enables you to dynamically group devices and deploy
configuration profiles and restrictions to those devices.
5 Security and privacy
The security and privacy of devices and access to corporate
resources are a top priority for any organization. To address
these worries, Apple has a number of security features built right
into macOS, iPadOS, iOS and tvOS.
iOS/iPadOS macOS
Security Features Security Features
1 1
tvOS leverages many of the security
features found in iOS, such as direct
Software Secure System App Store Software System Integrity Gatekeeper software updates from Apple, vetted
Updates Updates Protection (SIP) and secure App Store apps, app data
protection with App Sandboxing and
deeper levels of management through
supervision.
Touch ID Hardware App App Store FileVault XProtect
Encryption Sandboxing Encryption With management, Apple TV settings can
be deployed to automate AirPlay security.
This allows you to pair Apple devices
with Apple TVs, so only the appropriate
Privacy Supervision App Privacy devices share their screens wirelessly.
Sandboxing
5 Security
Unix is the foundation for Apple’s operating
systems, providing a strong kernel at the
core. Apple’s OSs are built with security
in mind and have unique security settings Apple’s deployment
added. Those settings can be managed via programs
an MDM solution.
environment.
Apple security
features
Apple OSs
Conditional access
iOS/iPadOS • Enable Lost Mode
For organizations leveraging Windows Azure AD and
• Lock and wipe a device
Office 365, it’s critical to implement a conditional access
• Remote wipe path for Mac devices. Best-of-breed MDM solutions offer
• Update iOS built-in conditional access integrations.
• Clear restrictions and passcodes
• Remove MDM Software upgrades
By developing major versions of macOS, iOS, iPadOS and
tvOS annually, Apple has set the pace of innovation. Each
year, Apple unveils new and great consumer features, but
tvOS • Enable Lost Mode also adds layers of security and fixes vulnerabilities. These
• Lock and wipe a device updates can be critical for devices used by employees or
• Remote wipe students in order to protect their data. Your management
• Update iOS solution not only needs to be able to deploy updates
• Clear restrictions and passcodes from Apple, but also needs to quickly support all the new
• Remove MDM management features that come with them too.
6 User empowerment and adoption
With the rise in self-sufficiency tools like Lyft, Headspace and Duolingo, today’s
workforce expects to get the tools they want, when they need them. Enterprise
app catalogs meet the needs of users by empowering them with instant access
to resources, content, tier one help and trusted apps through a single click from
their device — all without submitting a help desk ticket to IT.
•
App Store, B2B, in-house apps and third-party
software
• E mail, VPN and other configurations
• E -books, guides and videos
• B ookmarks and shortcuts
• P rinter mapping and drivers
• H elp desk ticketing and hardware requests
• P assword resets and compliance information
APP CATALOG FOR MOBILE APP CATALOG FOR MAC • B asic maintenance and system diagnostics
• S oftware and OS upgrades
Example: Jamf Self Service for macOS, iOS and iPadOS offers a branded app • S ingle Sign-on (SSO) integration
catalog that can integrate seamlessly into any organization’s internal resources • Localized language support for English, French,
or corporate intranet. German, Japanese and Simplified Chinese
6 User empowerment and adoption
Best-of-breed MDM solutions should offer the ability to brand your app catalog
to match your existing corporate resources. This seamlessly integrates your app catalog
among existing internal properties, increasing familiarity and ease of use.
Infrastructure More and more organizations are moving
to the cloud.
planning Below are just a few reasons why enterprise organizations are going cloud:
Database administration,
Server monitoring and
ongoing security and
response team
updates
The Standard for Apple
Enterprise Management
Apple continues to build an interconnected ecosystem, with apps and services
being cross compatible across devices. Growing enterprise partnerships (IBM, Cisco,
SAP, etc.) and a boom in technology choice programs will only bring more Mac, iPad,
iPhone and Apple TV devices to your doorstep.
To get the absolute most out of Apple and your technology As the gold standard in Apple management and with dedication to
investment, you need a management solution that matches Apple’s the Apple ecosystem since 2002, Jamf is the product most trusted
intuition and has proven from day one that helping people succeed by businesses and schools that want to offer Apple and provide
with Apple is top priority. a consistent management experience across the entire ecosystem.
Put our word to the test by taking Request Trial Or contact your preferred reseller of Apple devices.
a free test drive.