Set up Apple platform integrations to protect and manage Mac computers, iPhones, iPads, Apple TV, and Apple Vision Pro from one place. You’ll configure Apple Push Notification service (APNs), Automated Device Enrollment (ADE), and Apps and Books in that order.
APNs is required for communication with Apple devices. For best results, use a macOS computer.
1
Navigate to the Account Menu Button
In Iru Endpoint, in the sidebar, click the Account Menu Button.
2
Open Integrations
Click the Integrations option in the menu.
3
Select Apple
Under Platform integrations, select Apple.
4
Set up APNs
Under Apple Push Notifications service, click Set up APNs.
5
Create an APNs certificate
Follow the on-screen instructions to create a new APNs certificate. Use a managed Apple account that multiple team members can access.
Do not attempt to use an existing APNs certificate. Create a new one specifically for Iru Endpoint.
APNs certificates must be renewed annually. Iru Endpoint will send email reminders to Team Members with Administrator or Account Owner permissions starting 30 days before certificate expiry. For renewal and troubleshooting, see Configure Apple Push Notification Service.
Automated Device Enrollment enables zero-touch deployment for corporate-owned Apple devices. Apple Push Notification service must be configured in your tenant before you set up Automated Device Enrollment.
In Iru Endpoint, in the sidebar, click the Account Menu Button.
3
Open Integrations
Click the Integrations option in the menu.
4
Select Apple
Under Platform integrations, select Apple.
5
Set up ADE
Under Automated Device Enrollment, click Set up Automated Device Enrollment.
6
Start the wizard and obtain the PEM file
In the setup wizard, continue until Iru Endpoint provides a PEM public key file (download or save it when prompted). You will upload this file to Apple Business or Apple School Manager in the next steps.
Scroll to the bottom of the Management Services list and click Add next to Add device management service.
11
Enter the service name
In the Service Name field, enter a name for this MDM integration (for example, Iru Endpoint).
12
Optional: Allow this service to release devices
If your organization needs it, select Allow this service to release devices.
13
Upload the PEM file
Upload the PEM file from Iru Endpoint.
14
Click Next
Click Next.
15
Download the service token
Click Download Service Token.
16
Click Done in Apple Business or Apple School Manager
Click Done.
17
Upload the token in Iru Endpoint
Return to Iru Endpoint and upload the .p7m service token file when prompted.
18
Complete the wizard in Iru Endpoint
Complete any remaining steps in the wizard and click Done.
19
Assign devices in Apple Business or Apple School Manager
In Apple Business or Apple School Manager, add Iru Endpoint as your Mobile Device Management (MDM) server and assign devices. Assigned devices will appear in Iru Endpoint as Awaiting Enrollment.
Apps and Books (formerly Volume Purchasing Program) lets you distribute App Store apps to devices. Apple Push Notification service must be configured in your tenant before you set up Apps and Books.
You cannot share the same Apps and Books token across multiple MDM servers. Create a new organizational unit in Apple Business or Apple School Manager specifically for your Iru Endpoint tenant and use a dedicated token.
1
Create a dedicated organizational unit in Apple Business or Apple School Manager
In Apple Business or Apple School Manager, click your organization name at the top right of the page.
8
Open Settings
Click Settings.
9
Apps & Books in Settings
After you open Settings, you should already be on Payments & Billing → Apps & Books. This view is where your organization’s Apps and Books content tokens appear.
10
Download the content token
Under Content Tokens, click Download next to the token you want to use with Iru Endpoint.
11
Upload token to Iru Endpoint
Return to the Iru Endpoint Web App and upload your token.