Configure BlackBerry UEM for ADE

You can configure BlackBerry UEM to synchronize with Apple Automated Device Enrollment (ADE) if you want to use the UEM management console to manage the activation of iOS and macOS devices that your organization purchased for ADE.
  1. In the management console, on the menu bar, click Settings > External integration > Apple Automated Device Enrollment.
    If you are using UEM on-premises, click Add icon and type a name for the account.
  2. In section 1 of 4: Create an Apple ADE account, click Create an Apple ADE account.
  3. Complete the fields and follow the prompts to create your account.
  4. In section 2 of 4: Download a public key, click Download public key.
  5. Save the public key on your local machine.
  6. In section 3 of 4: Generate server token from Apple ADE account, click Open the Apple Business portal.
  7. Sign in to Apple Business. In the preferences for your account, download the server token for the MDM server. For more information, see the Apple Business User Guide: Add devices using Apple Configurator to Apple Business.
  8. In section 4 of 4: Register the server token with BlackBerry UEM, click Browse.
  9. Navigate to and select the .p7m server token file. Click Open, then click Next.
  10. In the enrollment configuration window, type a name for the configuration.
  11. If you want UEM to automatically assign the enrollment configuration to devices when you register them with Apple ADE, select the Automatically assign all new devices to this configuration check box. Do not select this option if you want to use the UEM management console to manually assign the enrollment configuration to specific devices.
    Note: UEM synchronizes with Apple ADE daily and whenever you view the Apple ADE devices page. You can automatically assign only one enrollment configuration to new ADE devices. If you previously created an enrollment configuration with this setting, the setting is removed from the previous configuration and added to the new one. If you previously created an enrollment configuration with this setting and the configuration was applied to devices, UEM does not assign the new enrollment configuration.
  12. Optionally, type a department name, support email address, and support phone number to be displayed on devices during setup.
  13. In the Device configuration section, select any of the following options. Unless otherwise noted, the settings apply to both iOS and macOS devices:
    • Allow pairing: Users can pair the device with a computer.
    • Add supervising host certificates: Enable if you want to upload trusted host certificates that are delivered to supervised iOS devices during ADE activation. Supervised iOS devices with these certificates are allowed to pair with hosts that have a private key that matches one of these certificates, even if "Allow pairing" is not enabled. The certificates are delivered to devices during the ADE activation process only. Adding new certificates with this setting does not send the certificates to devices that have already completed ADE activation.
    • Mandatory: Users can activate devices using their company directory username and password.
    • Allow removal of MDM profile: Users can deactivate devices.
    • Wait until device is configured: Users cannot cancel the device setup until activation with UEM is complete.
    • Encrypt MDM profile during enrollment: Encrypt the user's MDM profile using the device certificate. Do not select this option if you are using automated enrollment with Apple Configurator.
    • Enable Shared iPad mode: Enable Shared iPad mode on the device.
    • Auto-advance setup: On macOS devices, the ADE setup occurs automatically without user intervention, unless other options are selected that require user actions. If enabled, in the Language and Region fields, specify the language and region that are configured automatically during the ADE setup process. Use the two character ISO 639-1 language code (for example, en for English, fr for French, and so on) and the two character ISO 3166-1 country code (for example, US for the United States, FR for France, and so on).
    • Do not use profile from backup: When a user restores an iOS device from a backup, the device will retrieve the ADE profile from the server instead of using the ADE profile from the backup. This option applies only to devices with iOS 26 and later.
    • Assign VPP app licenses when user assigned: Enable if you want to associate VPP app licenses (user licenses or device licenses) to the user or device when you Assign users to ADE devices. This setting is recommended when distributing VPP apps with a required disposition, as it allows for less delay in app distribution.
    • Require credentials for assigned user: Require that users provide their directory credentials during the ADE setup process. If enabled, iOS users are prompted for their credentials even if they are assigned to an ADE device before activation.
  14. In the Skip during setup section, select the items that you do not want to include in the device setup. Hover over an option to view a tooltip with additional details.
  15. Click Save. If you selected Automatically assign all new devices to this configuration, click Yes.
  • Activate iOS and macOS devices. For more information about activating devices that are enrolled in ADE, see Activating iOS and macOS devices that are enrolled in ADE.
  • The server token is valid for one year. You must renew the token each year before it expires. To see the status of the token, see the Expiry date in the Apple ADE window. To renew the token, in Settings > External integration > Apple Automated Device Enrollment, click the ADE account and click Update server token. Complete both steps to generate a new server token and register it with UEM.
  • You can remove any ADE connection that you create. If you remove all ADE connections, you cannot activate new Apple ADE devices. If you assigned enrollment configurations to devices and the configurations have not been applied, UEM removes the enrollment configurations assigned to the devices. Removing the connection does not affect devices that are active on UEM.