Skip Navigation

Configure
BlackBerry UEM
for DEP

You can configure
BlackBerry UEM
to synchronize with the
Apple
Device Enrollment Program (DEP) if you want to use the
UEM
management console to manage the activation of the
iOS
devices that your organization purchased for DEP.
  1. In the management console, navigate to
    Settings > External integration > Apple Device Enrollment Program
    .
    If you are using
    UEM
    on-premises, click The add icon and type a name for the account.
  2. In section
    1 of 4: Create an Apple DEP account
    , click
    Create an Apple DEP account
    .
  3. Complete the fields and follow the prompts to create your account.
  4. In section
    2 of 4: Download a public key
    , click
    Download public key
    .
  5. Save the public key on your local machine.
  6. In section
    3 of 4: Generate server token from Apple DEP account
    , click
    Open the Apple DEP portal
    .
  7. Sign in to your DEP account. In the preferences for your account, download the server token for the MDM server.
  8. In section
    4 of 4: Register the server token with BlackBerry UEM
    , click
    Browse
    .
  9. Navigate to and select the .p7m server token file. Click
    Open
    then click
    Next
    .
  10. In the enrollment configuration window, type a name for the configuration.
  11. If you want
    UEM
    to automatically assign the enrollment configuration to devices when you register them with
    Apple
    DEP, select the
    Automatically assign all new devices to this configuration
    check box. Do not select this option if you want to use the
    UEM
    management console to manually assign the enrollment configuration to specific devices.
  12. Optionally, type a department name and support phone number to be displayed on devices during setup.
  13. In the
    Device configuration
    section, select any of the following options:
    • Allow pairing
      : Users can pair the device with a computer.
    • Mandatory
      : Users can activate devices using their company directory username and password.
    • Allow removal of MDM profile
      : Users can deactivate devices.
    • Wait until device is configured
      : Users cannot cancel the device setup until activation with
      UEM
      is complete.
  14. In the
    Skip during setup
    section, select the items that you do not want to include in the device setup:
    Option
    Impact if selected
    Passcode
    Users are not prompted to create a device passcode.
    Location services
    Location services are disabled on the device.
    Restore
    Users cannot restore data from a backup file.
    Move from
    Android
    Data cannot be restored from an
    Android
    device.
    Apple
    ID
    Users are prevented from signing in to
    Apple
    ID and
    iCloud
    .
    Terms and conditions
    Users do not see the
    iOS
    terms and conditions.
    Siri
    Siri
    is disabled on devices.
    Diagnostics
    Diagnostic information is not automatically sent from the device during setup.
    Biometric
    Users cannot set up Touch ID.
    Payment
    Users cannot set up
    Apple
    Pay.
    Zoom
    Users cannot set up
    Zoom
    .
    Home button setup
    Users cannot adjust the Home button's click.
    Screen Time
    The option to set up Screen Time is skipped during DEP enrollment.
    Software update
    Users do not see the mandatory software update screen on the device.
    iMessage
    and
    FaceTime
    Users do not see the
    iMessage
    and
    FaceTime
    screen on the device.
    Display tone
    Users do not see the Display tone screen on the device.
    Privacy
    Users do not see the Privacy screen on the device.
    Onboarding
    Users do not see the informational onboarding screen on the device.
    Watch migration
    Users do not see the watch migration screen on the device.
    SIM setup
    Users do not see the screen to set up a cellular plan on the device.
    Device-to-device migration
    Users do not see the device-to-device migration screen on the device.
  15. Click
    Save
    . If you selected
    Automatically assign new devices to this configuration
    click
    Yes
    .
  • Activate
    iOS
    devices. For more information about activating devices that are enrolled in DEP, see Activating iOS devices that are enrolled in DEP.
  • The server token is valid for one year. You must renew the token each year before it expires. To see the status of the token, see the Expiry date in the
    Apple
    Device Enrollment Program window. To renew the token, in
    Settings > External integration > Apple Device Enrollment Program
    , click the DEP account and click
    Update server token
    . Complete both steps to generate a new server token and register it with
    UEM
    .
  • You can remove any DEP connection that you create. If you remove all DEP connections, you cannot activate new
    Apple
    DEP devices. If you assigned enrollment configurations to devices and the configurations have not been applied,
    UEM
    removes the enrollment configurations assigned to the devices. Removing the connection does not affect devices that are active on
    UEM
    .