Skip to main content
This guide applies to Mac computers, iPhone, iPad, Apple TV devices, and Apple Vision Pro
Apple Business Manager is now Apple Business. Apple School Manager is unchanged. For more information, see Introducing Apple Business and Apple Business Manager is now Apple Business.
Set up Apple platform integrations to protect and manage Mac computers, iPhone, iPad, Apple TV devices, and Apple Vision Pro from one place. You’ll configure Apple Push Notification service (APNs), Automated Device Enrollment (ADE), and Apps and Books in that order.

Configure Apple Push Notification service (APNs)

APNs is required for communication with Apple devices. For best results, use a macOS computer.
1

Open Integrations

In the sidebar, select the Account Menu Button, then select Integrations.
Screenshot of the account menu with Integrations option highlighted
2

Select Apple

Under Platform integrations, select Apple.
Screenshot of the Integrations page with Apple platform selected
3

Set up APNs

Under Apple Push Notification service (APNs), select Set up APNs.
Screenshot of the Apple integrations section with Set up APNs button
4

Create an APNs certificate

Follow the on-screen instructions to create a new APNs certificate. Use an organization-controlled Apple Account that designated team members can access.
Do not attempt to use an existing APNs certificate. Create a new one specifically for Iru Endpoint.
APNs certificates must be renewed annually. Iru Endpoint will send email reminders to Team Members with Administrator or Account Owner permissions starting 30 days before certificate expiry. For renewal and troubleshooting, see Configure Apple Push Notification service.

Renewing Your Apple Push Notification Service Certificate

1

Open Integrations

In the sidebar, select the Account Menu Button, then select Integrations.
2

Select Apple

Under Platform integrations, select Apple.
3

Renew Certificate

Under Apple Push Notification service (APNs), select Renew certificate.
4

Complete Renewal

Follow the on-screen instructions to renew your APNs certificate.
For troubleshooting, see Configure Apple Push Notification Service.

Configure Automated Device Enrollment

Automated Device Enrollment enables zero-touch deployment for corporate-owned Apple devices. Apple Push Notification service must be configured in your tenant before you set up Automated Device Enrollment. These steps configure the ADE token shown on the Apple integrations page. If this Iru Endpoint tenant needs more than one ADE token, add the additional tokens with the Iru Endpoint API. See Configure multiple ADE tokens using the Iru Endpoint API.
1

Enroll in Apple Business or Apple School Manager

Organizations enroll in Apple Business or Apple School Manager (both are free; verification may take several days). Devices purchased from Apple or authorized resellers are automatically added to your account. To add existing devices, see Adding Devices to Apple Business or Apple School Manager.
2

Open Integrations

In the sidebar, select the Account Menu Button, then select Integrations.
Screenshot of the account menu with Integrations option highlighted
3

Select Apple

Under Platform integrations, select Apple.
Screenshot of the Integrations page with Apple platform selected
4

Set up ADE

Under Automated Device Enrollment, select Set up Automated Device Enrollment.
Screenshot of the Apple integrations section with Set up Automated Device Enrollment button
5

Start the wizard and obtain the PEM file

In the setup wizard, continue until Iru Endpoint provides a PEM public key file (download or save it when prompted). You will upload this file to Apple Business or Apple School Manager in the next steps.
6

Sign in to Apple Business or Apple School Manager

Sign in to Apple Business or Apple School Manager with a Managed Apple Account that can manage device management services.
7

Open the Devices tab

Select the Devices tab at the top of the page.
8

Open Management

In the left sidebar, select Management.
9

Add a device management service

Scroll to the bottom of the Management Services list and select Add next to Add device management service.
Apple Business or Apple School Manager Management Services list with Add device management service
10

Enter the service name

In the Service Name field, enter a name for this MDM integration (for example, Iru Endpoint).
11

Optional: Allow this service to release devices

If your organization needs it, select Allow this service to release devices.
12

Upload the PEM file

Upload the PEM file from Iru Endpoint.
13

Select Next

Select Next.
Add device management service form with Service Name, release devices option, and public key upload
14

Download the service token

Select Download Service Token.
Apple Business or Apple School Manager Download Service Token action
15

Select Done in Apple Business or Apple School Manager

Select Done.
16

Upload the token in Iru Endpoint

Return to Iru Endpoint and upload the .p7m service token file when prompted.
17

Complete the wizard in Iru Endpoint

Complete any remaining steps in the wizard and select Done.
18

Assign devices in Apple Business or Apple School Manager

In Apple Business or Apple School Manager, add Iru Endpoint as your Mobile Device Management (MDM) server and assign devices. Assigned devices will appear in Iru Endpoint as Awaiting Enrollment.

Renewing Your Automated Device Enrollment Token

Renew Token renews the ADE token shown on the Apple integrations page. If this tenant already has more than one ADE token, renew the additional tokens with the Iru Endpoint API. See Renew, update, or delete ADE tokens using the Iru Endpoint API.
1

Open Integrations

In the sidebar, select the Account Menu Button, then select Integrations.
2

Select Apple

Under Platform integrations, select Apple.
3

Renew Token

Under Automated Device Enrollment, select Renew Token.
4

Complete Renewal

Follow the on-screen instructions to renew your Automated Device Enrollment token.
For more detail, see Configure Automated Device Enrollment. To add more ADE tokens to this tenant, see Configure multiple ADE tokens using the Iru Endpoint API.

Configure Apps and Books

Apps and Books, formerly the Volume Purchase Program (VPP), lets you distribute App Store apps to devices. Apple Push Notification service must be configured in your tenant before you set up Apps and Books.
You cannot share the same Apps and Books token across multiple MDM servers. Create a new organizational unit in Apple Business or Apple School Manager specifically for your Iru Endpoint tenant and use a dedicated token.
1

Create a dedicated organizational unit in Apple Business or Apple School Manager

Create a new organizational unit in Apple Business or Apple School Manager for your Iru Endpoint tenant.
2

Open Integrations

In the sidebar, select the Account Menu Button, then select Integrations.
Screenshot of the account menu with Integrations option highlighted
3

Select Apple

Under Platform integrations, select Apple.
Screenshot of the Integrations page with Apple platform selected
4

Set up Apps and Books

Under Apps and Books, select Set up Apps and Books.
5

Sign in to Apple Business or Apple School Manager

In the new window, sign in to Apple Business or Apple School Manager to complete the integration.
6

Open your organization menu

In Apple Business or Apple School Manager, select your organization name at the top right of the page.
7

Open Settings

Select Settings.
Apple Business or Apple School Manager with organization menu open and Settings option
8

Apps & Books in Settings

After you open Settings, you should already be on Payments & BillingApps & Books. This view is where your organization’s Apps and Books content tokens appear.
9

Download the content token

Under Content Tokens, select Download next to the token you want to use with Iru Endpoint.
Apple Business or Apple School Manager Payments and Billing Apps and Books Content Tokens with Download
10

Upload token to Iru Endpoint

Return to the Iru Endpoint Web App and upload your token.
11

Complete Apps and Books setup

Select Complete Apps and Books setup.

Renewing Your Apps and Books Token

1

Open Integrations

In the sidebar, select the Account Menu Button, then select Integrations.
2

Select Apple

Under Platform integrations, select Apple.
3

Renew Token

Under Apps and Books, select Renew Token.
4

Complete Renewal

Follow the on-screen instructions to renew your Apps and Books token.
For more detail, see Configure Apps and Books. For detailed information about each integration, see Configure Apple Push Notification service, Configure Automated Device Enrollment, Configure Apps and Books, and Apple Integrations Overview.

Next Steps

After completing Apple setup:
1

Configure Blueprints and Library

Create and configure Blueprints so policies and apps are ready before enrollment. See Configuring Blueprints and Managing Library.
2

Enable other platforms (optional)

To manage Android devices or Windows computers as well, see Android Setup or Windows Setup.
3

Set up enrollment for each platform

Once Blueprints are configured, set up enrollment: Apple Enrollment, Windows Enrollment, or Android Enrollment.