Automated Device Enrollment

What is Automated Device Enrollment


Automated Device Enrollment provides an automated approach to enrolling devices owned by the school or district the moment they are unboxed. In order to enroll using Automated Device Enrollment, devices must exist in an Apple School Manager account and be assigned to the Mosyle MDM server. Devices purchased from Apple or an Apple Authorized Reseller or carrier can be automatically added to the Apple School Manager account. Other devices can be manually added to Apple School Manager using Apple Configurator 2 (certain restrictions apply). Click here for more information on manually adding devices to Apple School Manager.

Devices assigned to the Mosyle MDM server from Apple School Manager can be assigned to an Automated Device Enrollment profile created in Mosyle to be synced with Apple's Cloud Configuration servers. Doing this will ensure devices automatically download the enrollment profile when the devices are powered on for the first time, or erased and the OS reinstalled, and connected to the network. Different settings can be configured in the Automated Device Enrollment profile to dictate the Setup Assistant steps that will be presented when enrolling devices.

In addition to the benefit of over-the-air hands off deployment and enrollment of devices, enrolling devices using Automated Device Enrollment provides:

During Automated Device Enrollment, devices will attempt to retrieve/download the cloud configuration profile that is synced with Apple servers. In order to successfully retrieve the profile and complete enrollment it's critical the network allows for proper communication, including access to all Mosyle and Apple domains. Click here for information on which hosts and ports are required for Apple products.

enroll.png

Enrolling devices using Automated Device Enrollment


The first steps to enrolling devices into Mosyle using Automated Device Enrollment include:

  1. Integrating the Apple School Manager account with Mosyle
  2. Assigning devices in Apple School Manager to the Mosyle MDM Server
  3. Creating and syncing an Automated Enrollment profile

Steps 1 and 2 have been reviewed in previous lessons. In the next sections we'll review the many configuration options available in the Mosyle Automated Device Enrollment profile.

All Mosyle accounts include a Default enrollment profile which has basic enrollment settings configured. All devices assigned to the Mosyle MDM server will be assigned to the Default profile unless they are manually assigned to a different enrollment profile. Modify the Default profile at any time to meet the needs of the school or district.

View devices assigned to the Mosyle MDM server and their current status by going to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment > View devices. The following statuses are retrieved from Apple servers and will be listed for each device:

Each status is color-coded to assist with quick identification. If needed, the devices and their current status can be exported from this screen using the “Download devices” option at the bottom of the list.

Update the list of devices and their status by clicking the “Update” button in this screen.

Tip: It's recommended to work within your Mosyle Education account while going through this section to configure the Automated Device Enrollment profiles to meet your school or district's needs.



Automated Device Enrollment configurations for iOS/iPadOS


Use the Automated Device Enrollment profile(s) to specify how the devices will behave after they're unboxed, or after Erasing all Content and Settings. Multiple enrollment profiles can be created if needed.

To start, go to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment. Choose the iOS/iPadOS platform from the dropdown menu at the top. Click the Default profile to make any changes or adjustments, or create a new profile by clicking “New profile”. The Automated Device Enrollment profiles are separated into different sections. Each is addressed below.

Profile Name

Enter a name for the enrollment profile. Only Mosyle Administrators will see this information, so feel free to use a name that will help organize and identify the enrollment settings configured.

The default enrollment profile will be named the same as the Mosyle account. You can update the name at any time by clicking the profile and editing this field.

Check the options you want to activate on the device

Each new enrollment profile created in Mosyle will automatically have the default settings configured. Feel free to check any new options or uncheck options as needed.

Supervision Identity

The Supervision Identity is required in order to pair a device with a computer when the restriction “Do not allow host pairing” is applied. When the restriction is applied, devices will not be able to connect or pair with computers. By installing the Supervision Identity on the Mac, you grant permission for the device to pair with the computer. Devices will only be able to pair with computers that have the Supervision Identity certificate installed.

The options that can be configured in Mosyle include:

In most cases when pairing is required, a command from Mosyle MDM can be sent to the device to remove the restriction profile and allow host pairing. If the device loses network connectivity and is unable to receive commands from the MDM to remove the restriction profile, the Supervision Identity is useful to allow pairing access.

Devices will be used in which model?

If you choose to enroll devices to limbo and they are assigned after the enrollment, if the device is ever wiped it will automatically re-enroll in Mosyle and will automatically be reassigned to the user. If you do not want this to happen, please check the option to Return devices to assignment model selected above after wipe.

Select the location responsible for the devices

Here you can choose which of the locations in Mosyle the device should be assigned after it is enrolled. If the device will be assigned 1:1 to a user or to a Shared Device Group, the device will assume the location of the user or shared group.

Customize Setup Assistant (Available only for iOS 13+)

The options available allow you to customize the end user experience during the enrollment process. Include items such as a welcome message, an End User License Agreement Screen, and/or authentication. Each option is described in more detail below. As items are added, they can be rearranged by dragging and dropping the tile in any order desired.

*When using the options in the Custom Setup Assistant to complete device assignment (Mosyle User Authentication and Single Sign-On Authentication), be sure the Device Assignment options configured in your account are correct. To confirm, go to My School > Users > Device Assignment > User Authentication Assignment. Be sure the option under the heading 'Assignment through SSO Authentication during Automated Device Enrollment' is configured with the selection Auto-assign the device to the Authenticated user during the SSO Sign In.

Select the iOS/iPadOS devices that will receive this profile

Choose the device serial numbers to receive the enrollment profile. Assign all devices or specific devices to the enrollment profiles as needed to meet the needs of your school or district.

By default, devices that are erased and re-enrolled in Mosyle will automatically keep the user assignment. Therefore, if you wish to always enroll devices as freshly unassigned devices check the box for “Enroll devices as unassigned devices”.

Select the options that will not be presented to the user in Setup Assistant

Check any of the Setup Assistant steps you wish to skip during the enrollment. Uncheck any steps you wish to present to the user during the enrollment. Anything skipped during the enrollment can always be configured at a later time through the device Settings unless it is configured to be restricted.

Phone & Email Support (optional)

These fields are optional. If information is entered here it will be displayed on the Remote Management screen during the enrollment as the School/District Support Email and Phone Number.

Rename devices after enrollment

Automatically rename devices during the enrollment flow using device or user variables. If users are authenticating during the enrollment and completing the device assignment, any available 1:1 variables can be used for the renaming. If prompting users to enter Tag or Asset Tag information with the Custom Setup Assistant, use the corresponding variables to rename the devices.

After configuring the Automated Device Enrollment profile for iOS/iPadOS devices, click Save. View the device list to ensure the devices show a “Profile Associated” (Enrollment > Automated Device Enrollment > View Devices). Once the devices show a “Profile Associated” they are ready to be enrolled.

iOS and iPadOS devices will prompt the enrollment process in one of two ways:



Automated Device Enrollment configurations for macOS


Use the Automated Device Enrollment profile(s) to specify how the devices will behave after they're unboxed, or after erasing and reinstalling the macOS. Multiple enrollment profiles can be created if needed.

To start, go to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment. Choose the macOS platform from the dropdown menu at the top. Click the Default profile to make any changes or adjustments, or create a new profile by clicking “New profile”. The Automated Device Enrollment profiles are separated into different sections. Each is addressed below.

Profile Name

Enter a name for the enrollment profile. Only Mosyle Administrators will see this information, so feel free to use a name that will help organize and identify the enrollment settings configured.

The default enrollment profile will be named the same as the Mosyle account. You can update the name at any time by clicking the profile and editing this field.

Check the options you want to activate on the device

The following options are the same as the iOS/iPadOS configuration. Please see “Automated Device Enrollment configurations for iOS/iPadOS” for additional information.

Each new enrollment profile created in Mosyle will automatically have the default settings configured. Feel free to check any new options or uncheck options as needed.

Customize Setup Assistant (Available only for macOS 10.15+)

The options available in the Custom Setup Assistant for macOS are the same as the options for iOS/iPadOS, allowing the possibility to provide a consistent enrollment experience across all devices in the fleet. Please see “Automated Device Enrollment configurations for iOS/iPadOS” for additional information.

If using the Auto-Advance enrollment options, it's recommended to skip as many Setup Assistant steps as possible to fully leverage the Auto-Advance enrollment process.

Select the Macs that will receive this profile

Choose the device serial numbers to receive the enrollment profile. Assign all devices or specific devices to the enrollment profiles as needed to meet your organization needs.

Select the options that will not be presented to the user in Setup Assistant

Check any of the Setup Assistant steps you wish to skip during the enrollment. Uncheck any steps you wish to present to the user during the enrollment. Anything skipped during the enrollment can always be configured at a later time through the device System Settings unless it is configured to be restricted.

Account Configuration

Define whether or not the user will be prompted to create a local user account during the Setup Assistant, and/or configure a local administrator account on the Mac using the options below.

To prompt the creation of a local user account on the Mac during the Setup Assistant, check the box for “Prompt user to create an account”. After checking the box, you'll have additional option available:

If you plan to use Mosyle Auth 2 to create user accounts, or users will be logging in using a network/mobile account or another account created outside of Setup Assistant, uncheck the box for “Prompt user to create an account”. In doing so, after downloading and installing the enrollment profile it will boot to the Login Window without requiring the user to manually create a local user account.

Since the Mac requires at least one Admin account during setup, when skipping the manual creation of a local user account you'll be required to create a managed administrator account using the option “Create additional local admin during Setup Assistant”. When creating the managed administrator account:

Phone & Email Support (optional)

These fields are optional. If information is entered here it will be displayed on the Remote Management screen during the enrollment as the School/District Support Email and Phone Number.

Rename devices after enrollment

Automatically rename devices during the enrollment flow using device or user variables. If users are authenticating during the enrollment and completing the device assignment, any available 1:1 variables can be used for the renaming. If prompting users to enter Tag or Asset Tag information with the Custom Setup Assistant, use the corresponding variables to rename the devices.

After configuring the Automated Device Enrollment profile for macOS devices, click Save. View the device list to ensure the devices show a “Profile Associated” (Enrollment > Automated Device Enrollment > View Devices). Once the devices show a “Profile Associated” they are ready to be enrolled.

macOS devices can be enrolled in the following ways:



Automated Device Enrollment configurations for tvOS


Use the Automated Device Enrollment profile(s) to specify how the devices will behave after they're unboxed, or after Erasing all Content and Settings on the Apple TV. Multiple enrollment profiles can be created if needed.

To start, go to My School > Apple Basic Setup > Enrollment > Automated Device Enrollment. Choose the tvOS platform from the dropdown menu at the top. Click the Default profile to make any changes or adjustments, or create a new profile by clicking “New profile”. The Automated Device Enrollment profiles are separated into different sections. Each is addressed below.

Profile Name

Enter a name for the enrollment profile. Only Mosyle Administrators will see this information, so feel free to use a name that will help organize and identify the enrollment settings configured.

The default enrollment profile will be named the same as the Mosyle account. You can update the name at any time by clicking the profile and editing this field.

Check the options you want to activate on the device

Devices will be used in which model?

Apple TVs can only be enrolled as Limbo devices.

Select the location responsible for the devices

Here you can choose which of the locations in Mosyle the device should be assigned after it is enrolled.

Select the Apple TVs that will receive this profile

Choose the device serial numbers to receive the enrollment profile. Assign all devices or specific devices to the enrollment profiles as needed to meet the needs of your school/district.

Select the options that will not be presented to the user in Setup Assistant

Check any of the Setup Assistant steps you wish to skip during the enrollment. Uncheck any steps you wish to present to the user during the enrollment. Anything skipped during the enrollment can always be configured at a later time through the device Settings unless it is configured to be restricted.

If using the Auto-Advance enrollment options, it's recommended to skip as many Setup Assistant steps as possible to fully leverage the Auto-Advance enrollment process.

Phone & Email Support (optional)

These fields are optional. If information is entered here it will be displayed on the Remote Management screen during the enrollment as the School/District Support Email and Phone Number.

Rename devices after enrollment

Automatically rename devices during the enrollment flow using device variables.

After configuring the Automated Device Enrollment profile for tvOS devices, click Save. View the device list to ensure the devices show a “Profile Associated” (Enrollment > Automated Device Enrollment > View Devices). Once the devices show a “Profile Associated” they are ready to be enrolled.

Apple TVs can be enrolled in the following ways:



After enrollment


Once devices are enrolled in the Mosyle account, they can be fully managed by all available and compatible configuration profiles and commands. Enrolled devices can be found under the Management tab > Devices Overview. Click the device name to bring up the Device Info window.


Revision #4
Created 2025-10-07 23:11:08 UTC by joliveira
Updated 2025-10-07 23:15:30 UTC by joliveira