Configure BlackBerry UEM for DEP

You can configure BlackBerry UEM to synchronize with the Apple Device Enrollment Program (DEP) if you want to use the UEM management console to manage the activation of the iOS devices that your organization purchased for DEP.
  1. In the management console, navigate to Settings > External integration > Apple Device Enrollment Program.
    If you are using UEM on-premises, click The add icon and type a name for the account.
  2. In section 1 of 4: Create an Apple DEP account, click Create an Apple DEP account.
  3. Complete the fields and follow the prompts to create your account.
  4. In section 2 of 4: Download a public key, click Download public key.
  5. Save the public key on your local machine.
  6. In section 3 of 4: Generate server token from Apple DEP account, click Open the Apple DEP portal.
  7. Sign in to Apple Business. In the preferences for your account, download the server token for the MDM server. For more information, see the Apple Business Manager User Guide: Link to a third-party MDM server in Apple Business Manager.
  8. In section 4 of 4: Register the server token with BlackBerry UEM, click Browse.
  9. Navigate to and select the .p7m server token file. Click Open then click Next.
  10. In the enrollment configuration window, type a name for the configuration.
  11. If you want UEM to automatically assign the enrollment configuration to devices when you register them with Apple DEP, select the Automatically assign all new devices to this configuration check box. Do not select this option if you want to use the UEM management console to manually assign the enrollment configuration to specific devices.
    Note: UEM synchronizes with Apple DEP daily and whenever you view the Apple DEP devices page. You can automatically assign only one enrollment configuration to new DEP devices. If you previously created an enrollment configuration with this setting, the setting is removed from the previous configuration and added to the new one. If you previously created an enrollment configuration with this setting and the configuration was applied to devices, UEM does not assign the new enrollment configuration.
  12. Optionally, type a department name and support phone number to be displayed on devices during setup.
  13. In the Device configuration section, select any of the following options:
    • Allow pairing: Users can pair the device with a computer.
    • Mandatory: Users can activate devices using their company directory username and password.
    • Allow removal of MDM profile: Users can deactivate devices.
    • Wait until device is configured: Users cannot cancel the device setup until activation with UEM is complete.
  14. In the Skip during setup section, select the items that you do not want to include in the device setup. Hover over an option to view a tooltip with additional details.
  15. Click Save. If you selected Automatically assign new devices to this configuration click Yes.
  • Activate iOS devices. For more information about activating devices that are enrolled in DEP, see Activating iOS devices that are enrolled in DEP.
  • The server token is valid for one year. You must renew the token each year before it expires. To see the status of the token, see the Expiry date in the Apple Device Enrollment Program window. To renew the token, in Settings > External integration > Apple Device Enrollment Program, click the DEP account and click Update server token. Complete both steps to generate a new server token and register it with UEM.
  • You can remove any DEP connection that you create. If you remove all DEP connections, you cannot activate new Apple DEP devices. If you assigned enrollment configurations to devices and the configurations have not been applied, UEM removes the enrollment configurations assigned to the devices. Removing the connection does not affect devices that are active on UEM.