Addigy can manage macOS, iOS, and tvOS devices using Addigy Mobile Device Management (MDM) functionality. What is Mobile Device Management (MDM)?
Prerequisites
- Must be an Owner and have no policy restrictions
- Create an Apple Push Notification service (APNs) Certificate and assign it in Addigy (Instructions: Addigy Apple Push Certificates)
- Configure an MDM Profile on at least one policy to deploy to devices of that Policy (more details below).
Configure MDM for Enrollment
You must configure the MDM Enrollment Profile to enable the MDM functionality on a policy. Once configured, the MDM Enrollment Profile will be automatically installed on all devices in the policy. This requires a push certificate.
To configure MDM for a policy, navigate to Policies > (Policy) > Integrations & Settings > MDM Enrollment Profile.
Setup the following configuration options in the MDM Profile:
- Display Name
- Company Name
- Description for your Mobile Device Management Profiles
Note: This information will be visible to the end-user in the device's settings when the Profile is installed, so make sure it's specific to the customer/department.
Enrolling Your Devices With MDM
Now that you've set up your Push certificates and configured MDM in your policies, it's time to start enrolling new machines with MDM. It's important to note that this allows Addigy to bypass some of the PPPC restrictions introduced in Mojave and Catalina.
(Have an Apple Business Manager or School Manager account? You can bypass the steps below by using Automated Device Enrollment)
1. Head over to the Add Devices page
2. Use the dropdown menu to select the policy for the new device
If a policy with an MDM Profile is selected, a number of MDM installation options will appear.
1: Automated Device Enrollment
For more information on what Automated Device Enrollment (ADE) is and how to configure it, reference the below articles:
- Configuring Apple Business Manager and the Addigy Automated Device Enrollment Integration
- Configuring Apple's Automated Device Enrollment Integration with Addigy
2: Device Enrollment
This is also known as manual MDM enrollment as it requires local interaction in order to approve the enrollment. More information on how to enroll macOS devices via this option can be found in this article: How To: Manually Enroll macOS into Addigy's MDM
This enrollment method has 3 options to download/send the enrollment profile:
Option 1: Download the .mobileconfig file that would allow you to directly install MDM directly onto the device when the .mobileconfig file is double-clicked.
Option 2: Copy the URL shown so that it may be used by the device's browser to download and install the MDM Profile. This link will download the .mobileconfig associated with your environment which can then be double-clicked to install the MDM Profile to the System Settings of the desired device.
Option 3: Display a QR code that can be scanned to install MDM on an iPhone or iPad.
Please Note: If you do not see an installation URL like the one below, then you still have to set up an Apple Push Certificate. Please reference the instructions found in this article Addigy Apple Push Certificates.
Additional Notes
- iOS and tvOS devices will only be eligible for the MDM Profile URL Deployment (or Automated Device Enrollment / Business and School Manager deployments).
- iOS and tvOS devices are not eligible for the Addigy Agent which recognizes device state (MDM-specific devices will show as a gray icon).
- iOS and tvOS support Remote Lock, Remote Wipe, and MDM Configurations.
- macOS supports both MDM Profiles and the Addigy Agent.
- macOS can reinstall both the Addigy Agent and the MDM Profile using the builtin Actions