iOS

You can perform the following actions:

Enroll Device

Select one or more devices and click Enroll Device.

iOS devices can be enrolled as a DEP Device and BYOD Device based on your requirements:

DEP devices are registered in the Apple's Device Enrollment Program (DEP). DEP allows you to make MDM enrollment mandatory and unremovable, and also automatically installs Deep Freeze Cloud MDM during the initial device setup.

The advantage of a DEP device is the Deep Freeze MDM settings can be directly pushed to the device during initial device setup. Even when the mobile device is reset, the settings are pushed to the device again during setup.

Configuring a DEP device has three stages:

Creating an Apple Push Certificate

The first step to connect the Deep Freeze MDM with Apple Enterprise Mobile Management by creating an Apple Push Certificate and uploading to Deep Freeze MDM.

Complete the following steps:

  1. Go to MDM > Settings > Push Certificate.

  2. Click Certificate Request to download the Certificate Request. Save it on your computer.

  3. Go to Apple Push Certificate Portal (https://identity.apple.com/pushcert/) and sign in with your Apple ID and password.

  4. Click Create a Certificate. Select I have read and agree to these terms and conditions and click Accept.

  5. Click Choose File. Browse to select the Certificate Request file (.csr) from Deep Freeze MDM and click Open.

  6. Click Upload. The message You have successfully created a new push certificate with the following information: is shown.

  7. Click Download to download the Apple Push Certificate (.pem) and save it on your computer.

  8. Go to Deep Freeze Cloud > MDM > Settings > Push Certificate.

  9. Click Choose File. Browse to select the Apple Push Certificate file and click Open.

  10. Specify the Apple ID.

  11. Click Upload.

Deep Freeze MDM is now connected to Apple Enterprise Mobile Management.

Configuring a DEP MDM Server

Device Enrollment Program (DEP) is for devices purchased directly from Apple and owned by your organization.

Complete the following steps to configure a DEP Server:

  1. Go to Deep Freeze Cloud > MDM > Settings > DEP.

  2. Click DEP Public Key to download the public key.

  3. Go to http://deploy.apple.com/ and sign in to your account.

  4. Click Get Started.

  5. Click Add MDM Server.

  6. Enter a name for your MDM server (for example Deep Freeze MDM – your company name).

  7. Click Choose File. Browse to select the DEP Public Key downloaded in step 2. Click Next.

  8. Download the DEP Server Token.

  9. Go to Deep Freeze Cloud > MDM > Settings > DEP.

  10. Click Choose File. Browse to select the DEP Server Token.

  11. Click Upload.

  12. Go to http://deploy.apple.com/.

  13. Click Manage Devices.

  14. Click Choose by Serial Number. Specify the serial number of your device.

  15. Select Assign to Server and select the MDM Server.

  16. Click OK.

  17. Go to Deep Freeze Cloud > MDM > Settings > DEP.

  18. Click Sync with Apple to refresh.

  19. Configure the following settings: General Configuration

    • Initial device group: select the group that the device will belong to. If no group is selected the device will be part of the Default iOS group.

    • Force Deep Freeze MDM enrollment – select this option if this device will be automatically enrolled in Deep Freeze MDM profile and the Deep Freeze MDM app will be automatically downloaded. Clearing this checkbox gives you an option to either Apply configuration or Skip configuration during initial setup.

    • Allow Deep Freeze MDM removal by user.

    • Place device in Supervised mode – select this option to place this device in Supervised mode. Supervised mode gives more control to the administrator over the device and additional restrictions can be set. Optionally, select Allow Deep Freeze MDM removal by user if you want to give the permission to the user to remove the MDM user profile from Settings > Device Management > Deep Freeze MDM.

    • Allow pairing with OS X computers – select this option to make the mobile device visible in OS X computers and pair with them. If this option is not selected, the mobile device will not be visible in the Bluetooth settings on your OS X computers.

    Organization Details – This information is presented to the user of the device during the setup process:

    • Support phone number – specify the phone number of the support team.

    • Support email address – specify the email address for your support team.

    • Department name – specify the name of the department to which the mobile device user belongs.

    Device Naming Scheme – This option controls how supervised devices are renamed. Select one of the following:

    • Default Name – keep devices' default names when they enroll.

    • Add prefix to name – rename each device when it enrolls by adding a prefix to its default name. Define the prefix in the Prefix field that appears when this option is selected.

    • Name devices based on serial numbers – select this option to define custom names for specific serial numbers. Existing and newly enrolled devices are then assigned the name associated with their serial number. Devices with serial numbers that do not have defined names are not affected (they keep their default/existing name). To use this option, you must create and upload a table that associates names to serial numbers:

      1. Select the Name devices based on serial numbers option.

      2. Click Download CSV Template.

      3. Edit the downloaded template by defining a name for each serial number you add to the table. Remember that you can enter serial numbers for devices that already enrolled as well as those that will enroll in the future.

      4. Save and close the .csv file.

      5. Click Choose File and use the file browser to select the .csv file.

    Optional Setup Panes – You can choose to skip any of the setup steps below during initial configuration of the mobile device:

    • Skip passcode setup

    • Skip location service

    • Skip restoring from backup

    • Remove "Move from Android" from restore options

    • Skip signing in to Apple ID and iCloud

    • Skip Terms and Conditions

    • Skip Touch ID setup

    • Skip Apple Play setup

    • Skip zoom setup

    • Skip Privacy pane (iOS 12+)

    • Skip iMessage and Face Time (iOS 12+)

    • Skip ScreenTime (iOS 12+)

    • Skip Software Update (iOS 12+)

    • Disable Siri

    • Disable sending diagnostics info

  20. Click Save.

  21. Setup the mobile device (for a new device) or reset the device.

Once the device setup is completed, go to Deep Freeze Cloud > MDM > Devices to view the device.

Note: An Apple device can only be assigned to one Apple MDM Server. The Apple device must be assigned to the Apple MDM Server that is connected to Deep Freeze MDM. If the Apple device is assigned to another Apple MDM Server, you must unassign the iOS device and re-assign to the Apple MDM Server that is connected to Deep Freeze MDM.

Add Groups

Select one or more devices and click Add Groups. See Creating Groups for iOS Devices.

CSV

Select one or more devices and click CSV to export device. information to a CSV format.

Move to Group

Select one or more devices. Click Move to Group and select the group from the drop-down list.

Message

You can use the Deep Freeze Cloud Console to send messages to devices. Such messages are displayed as push messages. Messages are not cached, however; if a recipient computer is powered down or no user is logged in when the message is received, the message will not appear on that computer.

Select one or more devices and click Message. Define the message text then click Send.

Lock

Select one or more devices and click Lock.

If a passcode has been specified on the device, a user must enter the passcode to unlock the device.

Push Assigned Apps

Select one or more devices and click Push Assigned Apps to re-install apps that are removed using Select Wipe. The apps that are selected in the group to which the mobile device belongs are re-installed.

Clear Passcode

Select one or more devices and click Clear Passcode.

If the iOS device is part of a Group where passcode is required, the user will be prompted to enter a new passcode on the device as per the passcode policy.

Select Wipe

A select wipe action is used to remove all the apps that are installed on the device. The device configuration and all the settings are left unchanged.

Select one or more devices and click Select Wipe.

Full Wipe

A full wipe action is used to restore the device to its original settings.

Select one or more devices and click Full Wipe.

Update iOS

Select one or more devices and click Update iOS.

Devices with an out-of-date version of iOS are indicated with an orange icon.

Only those selected devices that are supervised and are running an out-of-date version of iOS will update.

Connections

Select one or more devices. Click Connections and select whether to enable or disable Bluetooth.

Remove

Select one or more devices and click Remove.

Last updated