Skip Navigation

Configure
BlackBerry UEM
for DEP

You can configure
BlackBerry UEM
to synchronize with the
Apple
Device Enrollment Program (DEP) if you want to use the
UEM
management console to manage the activation of the
iOS
devices that your organization purchased for DEP.
  1. In the management console, navigate to
    Settings > External integration > Apple Device Enrollment Program
    .
    If you are using
    UEM
    on-premises, click The add icon and type a name for the account.
  2. In section
    1 of 4: Create an Apple DEP account
    , click
    Create an Apple DEP account
    .
  3. Complete the fields and follow the prompts to create your account.
  4. In section
    2 of 4: Download a public key
    , click
    Download public key
    .
  5. Save the public key on your local machine.
  6. In section
    3 of 4: Generate server token from Apple DEP account
    , click
    Open the Apple DEP portal
    .
  7. Sign in to
    Apple Business Manager
    . In the preferences for your account, download the server token for the MDM server. For more information, see the Apple Business Manager User Guide: Link to a third-party MDM server in Apple Business Manager.
  8. In section
    4 of 4: Register the server token with BlackBerry UEM
    , click
    Browse
    .
  9. Navigate to and select the .p7m server token file. Click
    Open
    then click
    Next
    .
  10. In the enrollment configuration window, type a name for the configuration.
  11. If you want
    UEM
    to automatically assign the enrollment configuration to devices when you register them with
    Apple
    DEP, select the
    Automatically assign all new devices to this configuration
    check box. Do not select this option if you want to use the
    UEM
    management console to manually assign the enrollment configuration to specific devices.
    UEM
    synchronizes with
    Apple
    DEP daily and whenever you view the
    Apple
    DEP devices page. You can automatically assign only one enrollment configuration to new DEP devices. If you previously created an enrollment configuration with this setting, the setting is removed from the previous configuration and added to the new one. If you previously created an enrollment configuration with this setting and the configuration was applied to devices,
    UEM
    does not assign the new enrollment configuration.
  12. Optionally, type a department name and support phone number to be displayed on devices during setup.
  13. In the
    Device configuration
    section, select any of the following options:
    • Allow pairing
      : Users can pair the device with a computer.
    • Mandatory
      : Users can activate devices using their company directory username and password.
    • Allow removal of MDM profile
      : Users can deactivate devices.
    • Wait until device is configured
      : Users cannot cancel the device setup until activation with
      UEM
      is complete.
  14. In the
    Skip during setup
    section, select the items that you do not want to include in the device setup. Hover over an option to view a tooltip with additional details.
  15. Click
    Save
    . If you selected
    Automatically assign new devices to this configuration
    click
    Yes
    .
  • Activate
    iOS
    devices. For more information about activating devices that are enrolled in DEP, see Activating iOS devices that are enrolled in DEP.
  • The server token is valid for one year. You must renew the token each year before it expires. To see the status of the token, see the Expiry date in the
    Apple
    Device Enrollment Program window. To renew the token, in
    Settings > External integration > Apple Device Enrollment Program
    , click the DEP account and click
    Update server token
    . Complete both steps to generate a new server token and register it with
    UEM
    .
  • You can remove any DEP connection that you create. If you remove all DEP connections, you cannot activate new
    Apple
    DEP devices. If you assigned enrollment configurations to devices and the configurations have not been applied,
    UEM
    removes the enrollment configurations assigned to the devices. Removing the connection does not affect devices that are active on
    UEM
    .