Skip to content

Commit d7eb2c4

Browse files
authored
Merge pull request #7961 from lenewsad/macosenrollupdate
Updated public key section per GitHub request
2 parents 0b4fefe + f776556 commit d7eb2c4

1 file changed

Lines changed: 30 additions & 18 deletions

File tree

memdocs/intune/enrollment/device-enrollment-program-enroll-macos.md

Lines changed: 30 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,12 @@
33

44
title: Enroll macOS devices - Apple Business Manager or Apple School Manager
55
titleSuffix:
6-
description: Learn how to enroll corporate-owned macOS devices.
6+
description: Learn how to enroll macOS devices purchased through Apple Business Manager and Apple School Manager.
77
keywords:
88
author: Lenewsad
99
ms.author: lanewsad
1010
manager: dougeby
11-
ms.date: 04/15/2022
11+
ms.date: 07/11/2022
1212
ms.topic: how-to
1313
ms.service: microsoft-intune
1414
ms.subservice: enrollment
@@ -21,7 +21,7 @@ ms.assetid:
2121
#ROBOTS:
2222
#audience:
2323

24-
ms.reviewer: tisilver
24+
ms.reviewer: benflamm
2525
ms.suite: ems
2626
search.appverid: MET150
2727
#ms.tgt_pltfrm:
@@ -72,30 +72,42 @@ You use the Apple portal to create a token. You also use the Apple portal to ass
7272

7373
![Screenshot of Enrollment Program Token pane in Apple Certificates workspace to download public key.](./media/device-enrollment-program-enroll-ios/add-enrollment-program-token-pane.png)
7474

75-
3. Choose **Download your public key** to download and save the encryption key (.pem) file locally. The .pem file is used to request a trust-relationship certificate from the Apple portal.
75+
3. Choose **Download your public key** to download and save the encryption key (.pem) file locally. The PEM file is used to request a trust-relationship certificate from the Apple portal.
7676

77-
### Step 2. Use your key to download a token from Apple
77+
### Step 2. Use your key to download a token from Apple
7878

79-
1. Choose **Create a token for via Apple Business Manager** or **Create a token via Apple School Manager** to open the appropriate Apple portal, and sign in with your company Apple ID. You can use this Apple ID to renew your token.
80-
2. For DEP, in the Apple portal, choose **Get Started** for **Device Enrollment Program** > **Manage Servers** > **Add MDM Server**.
81-
3. For Apple School Manage, in the Apple portal, choose **MDM Servers** > **Add MDM Server**.
82-
4. Enter the **MDM Server Name**, and then choose **Next**. The server name is for your reference to identify the mobile device management (MDM) server. It is not the name or URL of the Microsoft Intune server.
79+
1. Choose **Create a token via Apple Business Manager** or **Create a token via Apple School Manager** to open the Apple portal used by your organization.
80+
2. Sign in to the portal with your company Apple ID. You can use this Apple ID to renew your token.
81+
3. Select your account name to open the portal menu, and then choose **Preferences**.
82+
4. Go to your MDM server assignments.
83+
5. Select the option to add an MDM server.
84+
6. Enter the **MDM Service Name**. The purpose of the server name is to help identify your mobile device management (MDM) server in the portal. It doesn't have to be the actual name or URL of the Microsoft Intune server.
85+
7. Upload your public key file and then save your changes. Then you can download the server token.
8386

84-
5. The **Add <ServerName>** dialog box opens, stating **Upload Your Public Key**. Select **Choose File…** to upload the .pem file, and then choose **Next**.
87+
### Best practices
8588

86-
6. Go to **Deployment Programs** > **Device Enrollment Program** > **Manage Devices**.
87-
7. Under **Choose Devices By**, specify how devices are identified:
88-
- **Serial Number**
89-
- **Order Number**
90-
- **Upload CSV File**.
89+
While you're in the Apple portal, you can also apply device filters and assign devices to the MDM server.
9190

92-
![Screenshot of specifying choose devices by serial number, setting choose action as Assign to server and selecting the server name.](./media/device-enrollment-program-enroll-macos/enrollment-program-token-specify-serial.png)
91+
* Apply filters: To filter devices before assigning them to your MDM server, go to **Devices** > **Filter**. You can filter devices by:
9392

94-
8. For **Choose Action**, choose **Assign to Server**, choose the <ServerName> specified for Microsoft Intune, and then choose **OK**. The Apple portal assigns the specified devices to the Intune server for management and then displays **Assignment Complete**.
93+
* Device management
94+
* Source
95+
* Order number
96+
* Device type
97+
* Storage size
98+
99+
* Bulk assign devices: You can assign all eligible devices to your new MDM servers at the same time.
100+
1. Go to **Devices** > **All Devices** or select the devices you want to assign.
101+
2. Select **Edit MDM Server**.
102+
3. Select the MDM server you want to use.
103+
4. Select **Continue**.
104+
5. When prompted to, confirm your changes. A notification appears to confirm that the devices have been assigned to the new MDM server.
105+
106+
The Apple portal keeps track of your activity and changes. Select **Activity** to view assignment results and download logs.
95107

96108
### Step 3. Save the Apple ID used to create this token
97109

98-
In the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), provide the Apple ID for future reference.
110+
Return to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431) and enter your Apple ID so that you have record of it for future reference.
99111

100112
![Screenshot of specifying the Apple ID used to create the enrollment program token and browsing to the enrollment program token.](./media/device-enrollment-program-enroll-ios/image03.png)
101113

0 commit comments

Comments
 (0)