Faronics Deploy Docs
Deploy HomeDeploy Sign inSubmit a ticket
  • About Faronics Deploy
  • Highlights
    • Top 10 Trending Topics
    • What's New?
  • Getting Started
    • Quick Start Guide
      • System Requirements
      • Initial Setup and Configuration
        • Sign Up - Create a Faronics Deploy Account
        • Download and Install Deploy Agents
          • Windows Install Guide
            • Download MSI Installer to Deploy via Active Directory
          • Mac Install Guide
        • Login to Deploy for the First Time
        • Configure User Profile and Organization Settings
          • How to Configure your User Profile
          • How to Configure your Organization Settings
        • Add Administrators - Invite your Team and Assign Roles
        • Manage Tags
          • Apply a Tag
    • Navigating the User Interface
      • Deploy User Interface Views
        • Control Grid
          • Dashboard View
          • Applications View
          • Windows Updates View
          • OS Deployment View
          • Anti-Virus View
          • Inventory View
          • Policies View
        • Analytics
          • Applications View
          • Usage Reports View
          • Windows Updates Status View
          • Anti-Virus Reports View
          • Deploy Diagnostics View
        • Tickets View
        • Tasks View
      • Using the Control/Smart Grids
      • Using the Action Toolbar
      • Computer States and Actions
        • Handling Offline Computers
        • Wake-On-LAN
          • Designate Last Man Standing (LMS) computers
      • Light Mode/Dark Mode View
  • Feature Definitions and Glossary
  • Action Toolbar
  • App Preset
  • Custom App
  • Policies (Windows)
  • Policies (macOS)
  • Policy Update Mode
  • Application Management
    • Applications Overview
    • Navigating the Applications Control Grid
    • Cache Server: Save Bandwidth
    • Groups Configuration
      • Create a Group
      • Delete a Group
      • Add Computer(s) to a Group
        • Assign a Computer to a Group via the Deploy Agent Download and Install
        • Assign Computers to a Group After they Appear in the Dashboard
        • Group Computers Using a Naming Convention
        • Group Computers Based on Criteria in Inventory
      • Perform Actions on a Group of Computers
        • Perform Actions via the Action Toolbar on a Group of Computers
    • Install, Uninstall & Update Applications
      • Install Application(s)
        • Install Built-In Application(s)
        • Install an Application on All Computers in Deploy
        • Install an Application Using Winget
          • Enable and Install Winget
          • Install an Application Using the Winget Tool
        • Install an External Application (Custom App)
          • Create and Install a Custom App
            • Hosting a Custom App - URL or Network Path
          • Edit a Custom App
          • Copy a Custom App
          • Request Assistance From a Deployment Specialist
          • Example: Installing MS Office 365 as a Custom App
        • Install a Pre-Defined Group of Applications (App Presets)
          • Create an App Preset
          • Install an App Preset
          • Manage App Presets
        • Install an Application on a Group of Computers
        • Schedule an Install of Application(s)
          • Schedule an Install of an Application
          • Schedule an Install of Multiple Applications
      • Uninstall Application(s)
        • Uninstall an Application From a Group of Computers
        • Uninstall an Application From all Computers
        • Schedule an Uninstall
      • Update Application(s)
        • Performing Updates On-Demand
        • Update via Apps with Recent Updates Grid
        • Update Applications Using Policy Modes
    • Application Management for macOS
      • Install Application on macOS
        • Install Built-In Application(s) on macOS
        • Install a Custom App (External) on macOS
          • Create and Install a Custom App on macOS
      • Update an Application on macOS
      • Uninstall Application on macOS
      • Shell Scripts on macOS
  • WINDOWS UPDATES
    • Navigating the Windows Updates Control Grid
  • Manual Windows Updates Approval
    • Manually Approve All Windows Updates for All Computers (Install All Updates)
    • Manually Install Windows Updates on a Group of Computers
    • Manually Approve a Windows Update Category (in a Policy) for all Computers
    • Manually Approve an Individual Windows Update in a Policy for All Computers
    • Manually Approve or Deny Individual Windows Updates via Pending Windows Updates
    • Patch Scan (On-Demand)
  • Automated Windows Updates Approval
    • Automated Windows Updates Using Policies
    • Automated Windows Updates Use Case: Testing Patches
    • Patch Scan (Using a Policy)
  • OS DEPLOYMENT
    • Navigating the OS Deployment Control Grid
    • Imaging Utility Requirements
    • Getting Images Ready for Deployment
      • Loading Images from ISO Files
        • Download and Install the Faronics Deploy Imaging Server Tool
        • Loading ISO Image Files via the Faronics Deploy Imaging Tool
      • Building Images for Deployment - Template Machine
    • Capturing Images
    • Deployment Packages
      • Deployment Package Install Settings
    • Post Imaging Actions
    • USB Media Creator
      • Generate a Portable USB Creator (Used to Create a Recovery USB Drive)
      • Create a Recovery USB Flash Drive from a Portable USB Creator
    • Inject Drivers into the boot.wim File
    • Abort the Sysprep Task
  • OS MANAGEMENT
  • OS Management Overview
  • Create a Configuration
    • System and Security
    • Network and Internet
    • Hardware
    • User Accounts
    • Appearance and Personalization
    • Clock and Region
    • Ease of Access
    • Others
  • Apply a Configuration to a Group of Computers
  • Custom Scripts - PowerShell, VB, Batch, Executable [.exe]
    • Custom Scripts Library
      • Quick Guide to Self-Hosting Custom Scripts
      • Send Message
      • Rename Multiple Computers
      • Show All Notification Icons
      • Hide Task View
      • Hide Recent Apps
      • Hide People Taskbar
      • Disable Cortana
      • Google Chrome Ad Blocker Extension
        • Create a Custom Script to Install any Google Chrome Extension
      • Uninstall Windows Updates
      • Auto Logon
      • Disable the UltraVNC System Tray Icon
      • Install Printer Driver Silently
  • Policies - Scheduling and Automation
    • Update modes - Automatic, Scheduled, Adhoc
    • Create a Policy
      • Create a Windows Policy
      • Create a macOS Policy
      • Create a New Policy (MDM)
        • Global Settings (MDM)
    • Maintenance Mode
    • End-User Experience: Defer Updates and Reboots
    • Protecting the Deploy Agent
  • ANTI-VIRUS & FIREWALL
    • Faronics Anti Virus & Firewall Protection Configuration
      • Anti-Virus Settings
      • Firewall Settings
      • Computer Settings
  • Upgrade Anti-Virus Software
  • Restore or Delete Quarantined Files
  • INVENTORY
    • Inventory
      • View Details
    • Organize Computers Using Inventory Data
    • Retrieve MSInfo Reports Using the Deploy Console
    • Inventory Data Update - Heartbeat + On-Demand
    • Quickly View Installed Applications
    • Organize Inventory by Active Directory Group Membership / Organization User Membership
  • ANALYTICS
    • Usage Statistics Reports
      • Application Usage Report
      • Application Update Status Report
      • Installed Applications Report
      • Computer Usage Report
      • Login Summary Report
      • Windows Update Status Report
  • REMOTE ACCESS - RDP / VNC
    • Remote Access Requirements - Ports and Networking
    • Remote Pro
    • VNC - Initial Setup
    • Using VNC - Virtual Network Computing
    • Using RDP - Remote Desktop Protocol
    • Remote View the Screen of a Computer (Configure Refresh Rate & Monitor Selection)
  • TASKS
    • Task History
    • Scheduled Tasks
      • Assign a Scheduled Task
      • Delete a Recurring Scheduled Task
      • Cancel a One Time or Recurring Scheduled Task
    • Schedule a One Time Task
    • Schedule a Recurring Task
    • Schedule a Custom Script to Run on Every Reboot
  • Help Desk Tickets
    • Enabling Ticketing
      • Enable Ticketing for Your Organization
        • Enable Email Alerts for Incoming Tickets
      • Enable Ticketing for a User
      • Ticketing Emails
    • Ticket Actions
      • Create a Ticket
      • Edit a Ticket
      • Add a Note to a Ticket
      • Assign Ticket (To a User)
      • Assign Owner (To a Ticket)
      • Change Status of a Ticket (Open, In Progress, Closed)
      • Download a File Attached to a Ticket
      • View a Ticket
      • View History
      • Export a Report of All Tickets to a CSV File
      • Remote Access a Computer via a Ticket
    • Ticketing - Mapping Email IDs
    • Fair Use Policy - Ticketing
  • User Management
    • User Roles
    • Add Users
      • Add a User via Email
      • Add a User/Group via Active Directory
    • Configure SAML (Verify Users for External Applications)
  • Organization Settings
    • 2FA - Two Factor Authentication
    • Accessibility
  • Mobile Device Management
    • Overview
    • Device Configuration
      • MDM Set up
      • Enroll Standard Device
        • Mobile Browser
        • iOS App
        • Apple Configurator
        • Email
      • Enroll Lite Device
    • Apple Devices
    • Apple Lite Devices
    • Apps & Docs
      • Applications
      • Shared Documents
    • Settings
      • Networks
      • Personalization
      • Accounts
    • Device Actions
    • Action Toolbar
Powered by GitBook
On this page
  • Apple Push Certificate
  • DEP MDM Server
  • Sync with Apple
  • VPP Account
  • Sync with Apple
  1. Mobile Device Management
  2. Device Configuration

MDM Set up

PreviousDevice ConfigurationNextEnroll Standard Device

Last updated 10 months ago

To set up MDM, you need to configure the following:

Apple Push Certificate

To connect the Faronics Deploy MDM with Apple Enterprise Mobile Management, you need to create an Apple Push Certificate and upload to Faronics Deploy MDM. To complete this process, you must have an , and generate an Apple MDM Push Certificate, which is required to manage Apple devices.

Complete the following steps to generate an Apple MDM Push Certificate:

  1. Download your certificate signing request (CSR), signed by Deploy.

  2. Go to the Apple Push Certificates Portal.

    1. Sign in with your Apple ID.

    2. Click Create a Certificate.

    3. Read and agree to the terms and conditions, then click Accept.

    4. Click Choose File and select the CSR file to be uploaded, then click Upload.

    5. Click Download to download your push certificate. Once you have generated the Apple MDM Push Certificate, you can now upload the certificate to Deploy.

  3. In the MDM page, click Configure > MDM Setup.

  4. Under the Push Certificate tab:

  5. Enter the Apple ID used to generate the certificate.

  6. Click Choose File and upload your push certificate.

  7. Click Done.

DEP MDM Server

Device Enrollment Program (DEP) allows businesses to quickly deploy and configure Apple devices by providing a fast, streamlined way to deploy organization-owned Apple devices.

To add a DEP Server, you need to generate a DEP Server Token.

  1. Click Configure > MDM Setup.

  2. Under the DEP Server tab, click Add New.

  3. Click Download to download your public key certificate. After obtaining the public key certificate, go to the Apple Business/School Manager portal and upload your public key certificate to be able to download your Server Token.

  4. Click Choose File and select the Server Token to be uploaded, then click Save.

To edit DEP server settings, click Edit Settings and make your changes.

  1. Click Configure > MDM Setup.

  2. Under the DEP Server tab, configure the following:

    • General Configuration

      • Initial device policy – Select the policy that will be enforced on the device. If no policy is selected, the Default iOS Policy will be pushed to the device.

      • Force Faronics Deploy MDM enrollment – Selecting this option automatically enrolls the device in Faronics Deploy MDM profile and downloads the Faronics Deploy MDM App.

      • Place device in Supervised mode – Selecting this option gives more control to the administrator over the device and be able to set additional restrictions.

      • Allow Faronics Deploy MDM removal by user – Selecting this option gives the user permission to remove the MDM user profile.

      • Allow pairing with OS X computers – Selecting this option makes the mobile device visible in OS X computers and allows pairing.

    • Optional Setup Panes – You can choose to skip any of the setup steps below during initial configuration of the mobile device:

      • Skip passcode setup

      • Skip restoring from backup

      • Skip signing in to Apple ID and iCloud

      • Skip Touch ID setup

      • Skip Zoom setup

      • Skip iMessage and Face Time (iOS 12+)

      • Skip Software Update (iOS 12+)

      • Disable sending diagnostics info

      • Skip location service

      • Remove 'Move from Android' from restore options

      • Skip Terms and Conditions

      • Skip Apple Play setup

      • Skip Privacy pane (iOS 12+)

      • Skip ScreenTime (iOS 12+)

      • If false, disables Siri. Available in iOS 5 and later. Also available for user enrollment.

    • Organization Details – This information is presented to the user of the device during the setup process:

      • Support phone number – Specify the phone number of the support team.

      • Support email address – Specify the email address for your support team.

      • Department name – Specify the name of the department to which the mobile device user belongs.

    • Device Naming Scheme – This option controls how supervised devices are renamed. Select one of the following:

      • Default Name – Select this option to keep the device default names during enrollment.

      • Add prefix to name – Rename each device during enrollment by adding a prefix to the default name. Define the prefix in the Prefix field that appears when this option is selected.

      • Name devices based on serial numbers – Select this option to define custom names for specific serial numbers. Existing and newly enrolled devices are then assigned the name associated with their serial number. Devices with serial numbers that do not have defined names are not affected (they keep their default/existing name).

      • To use this option, you must create and upload a CSV file that associates names to serial numbers:

        1. Select the Name Devices Based on Serial Numbers option.

        2. Click Download CSV Template.

        3. Add or update the information in the CSV file, then save the file.

        4. Click Choose File and use the file browser to select the .csv file.

To update a DEP server token, you must sign in to your Apple DEP or Apple School Manager account and follow the steps to generate a new server token. Once you have generated the new server token, you can now upload the new server token to Deploy.

To unpair DEP account, click Unpair DEP Account.

An Apple device can only be assigned to one Apple DEP MDM Server. The Apple device must be assigned to the Apple MDM Server that is connected to Deploy MDM. If the Apple device is assigned to another Apple MDM Server, you must unassign the iOS device and re-assign to the Apple MDM Server that is connected to Deploy MDM.

Once the device setup is completed, the device will be displayed under Apple Devices under the MDM page in Deploy.

Sync with Apple

Click Sync with Apple to sync VPP token/license-related information.

VPP Account

The Volume Purchase Program (VPP) allows an organization to bulk purchase, distribute and manage apps and books to the iOS devices (iPads, iPhones, and Macs) used within the organization.

To add a VPP Service token, you must sign in to your Apple Volume Purchase Program for business or education and download the VPP service token file found on the VPP purchases page. After downloading the VPP service token, you can now upload the new service token to Deploy.

If you are enrolled in Apple's Volume Purchase Program, you can retrieve your managed distribution token from the Volume Purchase Program portal.

To delete a VPP service token, select a token from the list and click Delete.

Make sure that this token is not being used by more than one MDM server, otherwise, the VPP information will not sync properly.

Sync with Apple

Click Sync with Apple to sync VPP token/license-related information.

If you purchase licenses from Apple after adding your token, you will need to Sync with Apple button to make Faronics Deploy MDM aware of the change.

Apple ID
Apple Push Certificate
DEP MDM Server
VPP Account