Setup Apple Business Manager in Intune

In this blog we will look at how to enroll and configure Apple Business Manager in Intune to manage your corporate owned devices and allow for bulk enrollment.

Note. Apple Business Manager is only available in selected countries, please verify that your country is available for enrollment into this program.
Availability of Apple programs and payment methods for education and business – Apple Support

Prerequisites

Supported volume

  • Maximum enrollment profiles per token: 1,000.
  • Maximum Automated Device Enrollment devices per profile: Same as the maximum number of devices per token (200,000 devices per token).
  • Maximum Automated Device Enrollment tokens per Intune account: 2,000.
  • Maximum Automated Device Enrollment devices per token: We recommend that you don’t exceed 200,000 devices per token. Otherwise, you might have sync problems. If you have more than 200,000 devices, split the devices into multiple ADE tokens.
    • About 3,000 devices per minute sync from ABM/ASM over to Intune. We recommend that you wait to manually sync again from the admin console until enough time has passed for all of the devices to sync over (total number of devices/3,000 devices per minute).

Enroll Your Organization

To buy content, configure automatic device enrollment in Intune and create accounts for your managers you need to enroll your organization.

  1. In a browser navigate to Enroll in Apple Business Manager
  2. Enter the required information
    Graphical user interface, application

Description automatically generated
  3. Once you have submitted the enrollment, an AppleCare agent will research your organization.
    Timeline

Description automatically generated
  4. An Apple Deployment Programs Support Agent will contact the verification contact supplied to verify a few details and complete the enrollment process.
  5. You will receive an email to confirm the contact that should accept the Terms and Conditions
    Graphical user interface, text, application, email

Description automatically generated
  6. You will then receive another email to get started with the creation of an Apple ID and setting up Apple Business Manager
    Graphical user interface, text, application, email

Description automatically generated

Setup Apple VPP Token

  1. In Apple Business Manager, click Settings > Apps and Books
  2. Click Download and save the .vpptoken.
    Graphical user interface, application

Description automatically generated
  3. In the Microsoft Endpoint Manager admin center, Tenant Administration > Connectors and Tokens > Apple VPP Tokens
    Graphical user interface, application

Description automatically generated
  4. Click +Create
    Graphical user interface, text, application

Description automatically generated
  5. Enter the Token name, Apple ID and upload the Token downloaded in Step 2 and click Next
    Graphical user interface, text, application, email

Description automatically generated
  6. Select the Country/Region, Type of VPP account and select Yes to automatically update app associated with the VPP Token. Click Next and Create.
    Graphical user interface, text, application, email

Description automatically generated

Get an Apple Device Enrollment token

Now that we have enrolled our organization, we can continue to setup the enrollment program token.

  1. In the Microsoft Endpoint Manager admin center, click Devices > iOS/iPadOS > iOS/iPadOS enrollment > Enrollment Program Tokens
    Graphical user interface, text, application

Description automatically generated
  2. Click on Add
    Graphical user interface, text, application, email

Description automatically generated
  3. Grant permission to Microsoft to send both user and device information to Apple by ticking I agree.
  4. Click Download your public key to download and save the encryption key file locally. The file is used to request a trust-relationship certificate from the Apple portal.
  5. Click Create a token for Apple’s Device Enrollment Program to open Apple’s Deployment Program portal, and sign in with your company Apple ID. You can use this Apple ID to renew your token.
    Graphical user interface, text, application

Description automatically generated
  6. In Apple’s Deployment Programs portal, click Settings >Device Management Settings > Add MDM Server
    Graphical user interface, text, application, email

Description automatically generated
  7. For MDM Server Name, enter a preferred name such as Intune and then click Next.
  8. Click Choose File… to upload the .pem file downloaded in Step 4, and then click Save.
    Graphical user interface, text, application, email

Description automatically generated
  9. Under Settings click on the MDM Server created and click Download Token.
    Graphical user interface, application

Description automatically generated
  10. In the Microsoft Endpoint Manager admin center, enter the Apple ID used and upload the Token downloaded in Step 9 and click Next. Graphical user interface, text, application, email

Description automatically generated
  11. Click Create.
    Graphical user interface, application

Description automatically generated

Create an Apple enrollment profile

Now that we’ve installed our token, we can create an enrollment profile for Apple Device Enrollment devices. A device enrollment profile defines the settings applied to a group of devices during enrollment.

 Note. Devices will be blocked if there aren’t enough Company Portal licenses for a VPP token or if the token is expired. Intune will display an alert when a token is about to expire, or licenses are running low.

  1. In Microsoft Endpoint Manager admin center, select Devices > iOS/iPadOS > iOS/iPadOS enrollment > Enrollment Program Tokens.
  2. Select a Enrollment program token that was created previously and then select Profiles > Create profile > iOS/iPadOS:
Graphical user interface, application

Description automatically generated
  1. On the Basics tab, enter a Name and Description for the profile and click Next
Graphical user interface, application

Description automatically generated
  1. In the User Affinity list, select Enroll with User Affinity.
  2. In the Authentication Method list, select Company Portal.
Screenshot of authentication method options.
  1. In the Install Company Portal with VPP, select the VPP token for your organization. Graphical user interface

Description automatically generated with low confidence
  2. Select Yes for Run Company Portal in Single App Mode until authentication.

Note. Multifactor authentication isn’t supported on a single device locked in Single App Mode. This limitation exists because the device can’t switch to a different app to complete the second factor of authentication. If you want multifactor authentication on a Single App Mode device, the second factor must be on a different device.

This feature is supported only for iOS/iPadOS 11.3.1 and later.

Graphical user interface, text, application

Description automatically generated
  1. In the Locked enrollment list, select Yes.
  2. In the Sync with computers list, select Allow all.
    Graphical user interface, application, Word

Description automatically generated
  3. You can specify a naming format for devices that’s automatically applied when they’re enrolled and upon each successive check-in. To create a naming template, select Yes under Apply device name template. Then, in the Device Name Template box, enter the template to use for the names that use this profile. You can specify a template format that includes the device type and serial number.
    Graphical user interface, text, application, email

Description automatically generated
  4. Click Next
  5. On the Setup Assistant, enter the Department and phone number.
  6. Select the Setup Assistant screens that you would like to show or hide during the process.
  7. Click Next.
  8. Click Create.

Assign an enrollment profile to devices.

Before devices can be enrolled, you need to assign an enrollment program profile to them.

  1. In Microsoft Endpoint Manager admin center, select Devices > iOS/iPadOS > iOS/iPadOS enrollment > Enrollment Program Tokens. Select the token in the list.
  2. Select Devices. Select devices in the list, and then select Assign profile.
  3. Under Assign profile, choose a profile for the devices, and then select Assign.

Assign a default profile.

You can choose a default profile to be applied to all devices that enroll with a specific token.

  1. In Microsoft Endpoint Manager admin center, select Devices > iOS/iPadOS > iOS/iPadOS enrollment > Enrollment Program Tokens. Select the token in the list.
  2. Select Set Default Profile, select a profile in the list, and then select Save. The profile will be applied to all devices that enroll with the token.
Graphical user interface, text, application, email

Description automatically generated

Sync managed devices.

Now that we have setup our enrollment token we can sync the devices that we have purchased through a supported channel.

  1. In Microsoft Endpoint Manager admin center, select Devices > iOS/iPadOS > iOS/iPadOS enrollment > Enrollment Program Tokens.
  2. Click the token we created earlier, and then select Devices > Sync:
Graphical user interface, text, application, email

Description automatically generated

Distribute devices to users

You’ve set up management and syncing between Apple and Intune, and assigned a profile to let your ADE devices enroll. You can now distribute devices to users. Devices with user affinity require each user be assigned an Intune license.

Author

One thought on “Setup Apple Business Manager in Intune