Activating iOS and macOS devices that are enrolled in ADE

You can enroll iOS, iPadOS, and macOS devices in Apple Automated Device Enrollment (ADE) and assign enrollment configurations and activation profiles to devices using the BlackBerry UEM management console. Enrollment configurations include extra rules that are assigned to devices during MDM enrollment.

You can use an Apple Business account to synchronize UEM with ADE. Apple Business is a web-based portal that allows you to enroll and manage devices in ADE and manage Apple VPP accounts.

Note that you can activate iOS ADE devices with UEM without using the BlackBerry UEM Client, but the UEM Client is required to support the following:

To activate devices that are enrolled in ADE, perform the following actions:

Step

Action


Step1 icon

Register devices in ADE and assign them to BlackBerry UEM.


Step 2 icon

Optionally, for iOS devices, to add the UEM Client to the app list and assign it to users or groups, see Add an iOS app to the app list.


Step 3 icon

Assign an enrollment configuration and activation profile to ADE devices.


Step 4 icon

For iOS and iPadOS device users, choose how you want users to activate their devices:

For macOS device users, Assign users to ADE devices.


Step 5 icon

Distribute devices to users and have them activate with UEM. For macOS devices, it is a best practice to reset the device to erase all content and settings before the user activates the device with UEM.

iOS devices: If you want to support features that require the UEM Client, instruct users to install and open the UEM Client to start the activation process.

macOS devices: When users start the activation process, they receive a device management prompt, followed by a prompt to set up the primary user account. If the assigned activation profile is configured to set up a local administrator account, the local administrator account is created in the background. If the user wants to log in with the local administrator account, you can view the generated password in the user's device details in the management console and provide it to the user, or instruct the user to view the generated password in BlackBerry UEM Self-Service, if they are granted that permission. The assigned activation profile determines how long the password is valid after it is viewed.