Supervision gives your organization a wealth of extra control over iPhones, iPads, and AppleTVs, so it's pivotal to ensure mobile devices are supervised. Thankfully, Apple has made this easy with the use of Apple Configurator for macOS. Using Apple Business/School Manager, you can wirelessly enable supervision on a device as part of the setup process when purchased by Apple or an Apple Authorized Reseller using Automated Device Enrollment. However, if you have a device that is not in Apple Business/School Manager, you can manually enable supervision using Apple Configurator, or simply add that device to the business/school manager account.
Notes: This process requires the iPhone/iPad to be erased. Additionally, adding a device to Apple Business/School Manager is completely optional in obtaining supervision, but doing so is highly recommended.
For a list of requirements and additional info from Apple, please reference this article:
Add devices from Apple Configurator to Apple Business Manager
Supervising or Adding Devices to Apple Business/School Manager
1 - Configure a WiFi Profile
In order to add a device to AxM, Apple requires you to include a WiFI profile. You can easily create this using Apple Configurator.
Note: You do not need to create a WiFi profile if you plan on supervising the device without adding to AxM.
- Open Apple Configurator and click File > New Profile
- Select "WiFi" from the list on the left-hand side and configure the settings accordingly
- Click on the General tab, name your profile, and save it
2 - Connecting your Apple Business/School Manager Account to Apple Configurator
To grant supervision or add a device to AxM, a user account with proper device enrollment permissions must be linked to Apple Configurator.
- With Apple Configurator open, select the Apple Configurator text in the menu bar, click Settings, then Organizations
- Click the + button and follow the on-screen steps to log in to a valid AxM account. This user must have the Administrator or Device Enrolment Manager role in AxM
- Once you enter your password, you will be asked to generate or choose an existing supervision identity. As suggested by Apple, generate a new supervision identity
3 - Preparing Devices
Now that the heavy lifting has been done, all that's left is to prepare and enroll devices.
- Connect your iPhone or iPad device to your Mac
- If you see a padlock, that means the iPhone or iPad needs to trust the Mac. In some cases, the device also needs to be unlocked
- Select the device in Apple Configurator and click Prepare
- Select Manual Configuration. Here, you will choose whether the device will be added to AxM, or perform a supervised enrollment without being added to AxM. It is recommended to add the device to AxM if it is not already there
- If you choose to Add the device to the business/school account, select that checkbox and uncheck "Activate and complete enrollment". This setting is only for devices already in AxM
- If you choose to only supervise the device, uncheck the setting to add to AxM
- If you choose to Add the device to the business/school account, select that checkbox and uncheck "Activate and complete enrollment". This setting is only for devices already in AxM
- In this next screen, you will be asked to define an MDM server. Per Apple, simply enter a name for the server and leave the Host name or URL as the default
- The URL will fail to verify, which is expected. Click next
- In the next screen, don't select a certificate and click next
- Choose the organization that was previously configured
- Choose which setup screens will be presented during Setup Assistant
- If you are not adding the device to AxM, you will see Prepare as an option. Selecting this will begin supervising the device
- If adding a device to AxM, you will see a screen to attach a WiFi profile. Select the one previously configured and click Next
- Leave the user credentials blank and click Prepare
4 - Assign the Correct MDM Server in Apple Business/School Manager
If you chose to add the device to AxM, you must assign it to the MDM server that is linked with Addigy. If you do not assign the correct MDM server, the device will stay assigned to a placeholder Apple Configurator MDM server, and it will not enroll. To assign the MDM server, follow this guide:
How to Configure Automated Device Enrollment