Before you can manage classes in Workspace ONE UEM, you must integrate with Apple School Manager (ASM). You must complete tasks in both the UEM console and in the Apple School Manager portal.
To complete integration, your organization must already be registered with Apple School Manager.
Workspace ONE UEM requires the following:
- If you are uploading CSV files to Apple School Manager, have all your files prepared.
- When you begin configuring the DEP profile using the wizard in the UEM console, keep the same browser session open. You cannot save your activity until you complete the final configuration step, so it is important to finish the entire configuration in one browser session.
- Do not use Internet Explorer as your browser when performing any of the integration steps.
Enable Education Functionality
|Select Enable to turn education functionality on.|
|Class Source||Select your Apple or Workspace ONE UEM as your Education functionality provider.
Note that changing sources and saving the configuration will delete all existing classes.
|Set Maximum Resident Users||Specify the maximum number of users each device's memory can support. This value divides the local storage on the iPad evenly for that number of users. If the number of users exceeds this setting, additional users' information is stored on iCloud instead of on the device.|
Configure Apple School Manager
- Navigate to Apple School Manager.
- Sign in with your organization's Apple credentials.
- Confirm your identity by entering the verification code. The Apple School Manager portal screen appears.
- Choose to Trust Your Browser if you are on a secure network.
- Select Get Started to automate MDM enrollment the first time you sign into ASM.
- Use the Set Up Assistant to add Managers, and Find Students Staff and Classes by connecting to your Student Information System or by uploading CSV files, and Create Accounts and Classes. For more information, see Apple School Manager Help.
- Select Close Setup Assistant when you are finished.
- Navigate to Device Assignments and select MDM Server in the left-navigation pane to begin configuring a server.
- Select Add MDM Server and enter the MDM Server Name to create a container that groups devices in the ASM portal for management in the UEM console. Leave this window and the browser session open. The MDM server name may refer to a server, department, or location.
- Navigate to the UEM console and obtain a Public Key as described in Link to Apple School Manager section.
- Select Upload File to upload the key.
- Download the Server Token and save it in a convenient location to upload to the UEM console later.
- Select Save MDM server.
- Choose to Assign Devices to Server and select the server name.
- Choose how to Manage Devices and add devices by manually adding serial numbers, order numbers, or uploading a CSV file.
- Select Done.
Link to Apple School Manager
Now that you created an MDM server in Apple School Manager (ASM), exchange keys to allow for mutual authentication between Workspace ONE UEM and Apple so that you can sync devices and class information later.
- n the UEM console, navigate to Configure. A Device Enrollment Program window appears. and select
- Download the public key by selecting the MDM_DEP_PublicKey.pem file and save the public key. Leave this window and the browser session open.
- Navigate back to the Apple School Manager window you left open.
- Select Upload File and Upload your Public Key in Apple School Manager.
- Navigate to the MDM_DEP_PublicKey.pem that you downloaded from the UEM console and upload it. Select Next.
- Select Your Server Token to receive an encrypted Apple Server Token file (.p7m) and save it in a convenient location.
- Navigate back to the Device Enrollment Program window of the UEM console.
- Select Upload and select Apple Server Token File (.p7m). Select Next.
Workspace ONE UEM and Apple can authenticate each other.
Profiles for Workspace ONE UEM School Manager Shared Device Management
Profiles are the primary means by which you can manage devices. Profiles are the settings, configurations, and restrictions that, when combined with compliance policies, help you enforce corporate rules and procedures.
The individual settings you configure, such as Wi-Fi, VPN, and passcodes, are called payloads. In most cases, only one payload is associated per profile for security profiles, which means you have multiple security profiles for different settings you want to establish.
When you configure a profile for a deployment integrated with Apple School Manager, you must select whether a profile applies to a Device or a User. User profiles are important for Shared Device deployments where users may log in to multiple devices, and need the proper Profile configuration present on each device.
DEP Profiles for ASM
Enrollment through DEP is required for Shared iPads and suggested for one-to-one devices to enable supervision on devices. After you create class rosters and configure your MDM server container, create an MDM configuration profile for devices using the Device Enrollment Program (DEP) wizard in the UEM console. For more information on configuring DEP profiles and syncing them in the UEM console, see the VMware Workspace ONE UEM Guide for the Apple Device Enrollment Program.
DEP Profile Requirements for Shared iPads in Apple Schoool Manager Deployments
Shared iPads require specific configuration. Use the following table as a reference when completing the DEP wizard to ensure that your profile meets the following requirements.
Prepare devices for enrollment using the following method.
Enable ALL of the following features that are required for management.
This feature is optional for Shared iPad management:
|Setup Assistant||Choose to Skip all the Setup Assistant features except for Locations Services if you want to search for devices in Lost Mode or track devices.|
DEP Profile Requirements for One-to-One Devices in Apple School Manager
Configure these devices as needed for your organization. Use the following table as a reference when completing the DEP wizard.
|Authentication||Choose any of the features that best meet your organizational needs.|
|MDM Features||Choose any of the features that best meet your organizational needs.|
|Setup Assistant||Choose any of the features that best meet your organizational needs. You can choose to Skip or Don't Skip features. Choose Don't Skip for the Locations Services option if you want to search for devices in Lost Mode or track devices.|
Manually Assign or Remove a DEP Profile
For Apple School Manager deployments, you must assign profiles to the appropriate devices after creating them for both Shared iPad and one-to-one configurations.
- Navigate to .
- Select the devices needed for the action.
- Select the
and select one of the following options:
- Assign Profile – Assign new or additional DEP profiles to selected devices. The DEP profile is not updated on a device until the device is factory wiped or re-connected to Wi-Fi.
- Remove Profile – Removes existing DEP profiles from selected devices.
Sync Class Rosters
- Navigate to .
- Select .
- View the statuses that appear at the top of screen to notify you when the sync is in progress and when it's complete. Refresh the page as needed.
Note: Whenever you update information in Apple School Manager, you must Sync Classes again to update the UEM console and enrolled devices.When the sync is complete, the time and date of the most recent sync is recorded in the tool tip for reference.
Use Sync Reports
- Navigate to .
- Scroll to the Roster Sync Failed report and select the hyperlink to review the report.