Monday, September 14, 2020

iOS Device Enrolment in Meraki

Apple's Device Enrolment Program is a slick and foolproof way to enrol and configure devices. It covers iPad and iPhone devices, Mac computers, and Apple TV. Each of these devices requires activation by phoning home to Apple on every reset. Bypassing this activation removes the devices from security and OS updates and access to other official Apple ecosystem products, such as the App Store.

DEP devices enrolled in an MDM, like Meraki at our school, makes a simple hands-off reset procedure. The reset procedure is initiated online without the need for the device in hand. Once the device is online it resets and upon a successful activation will automatically download the Meraki profile associated with the device. This allows customization of apps, wallpaper, restrictions, wifi and email settings, etc.

For legacy devices that were not purchased with DEP enabled or older devices that are not compatible with DEP your best option to register the device via Apple School Manager or via Apple directly into DEP. Failing that, you can still use Configurator to manually supervise and push a Meraki profile on the devices -- but this requires the device on hand. We have a few dozen of these iPads and it requires a lot of plugging and unplugging but it's fairly straightforward.

The only profile you're really pushing via Configurator is the Meraki MDM enrolment URL so the iPad can download it in the setup screens, and a wifi profile so you are not manually typing in SSID passwords. There are a few other quirks: sometimes there are conflicts with wallpapers and lock screen messages, but most are cosmetically minor.