Skip to content

Mobile Device Management Implementation Plan

Use this plan to set up the CapaInstaller Mobile Device Management (MDM) service on a single server in a typical company DMZ. When you finish, you have a working system with an enrolled test device, ready for device management and distribution of profiles and apps.

The plan has three phases:

  1. Preparation — prepare network access and certificates.
  2. Deployment — install prerequisites and deploy the services.
  3. Enrollment — verify your installation and enroll your devices.

In the examples, mdm.company.com is the public DNS name of the MDM service and capaserver.company.com is the internal CapaInstaller server. Replace them with your own names.

For the MDM services to communicate with devices outside the company network, certain ports must be open between the DMZ and the LAN, and between the DMZ and the internet.

  1. Ask your network manager to open the required ports for traffic from the DMZ server to the CapaInstaller servers that host the Back-end service and the Front-end service. The default ports are listed in MDM Network Ports. You can change the port numbers.
  2. Assign a physical or virtual Windows server in the DMZ to host the MDM service. The rest of this plan calls it the DMZ server.
  3. Before you deploy the MDM service, create a DNS alias record for the DMZ server. If you move the MDM service to another server later, you can redirect the alias to the new host.
  4. Ask your network manager to create a firewall rule that allows traffic from the internet to the DMZ server. This is often done with a subdomain, for example mdm.company.com → DMZ server. At a minimum, open ports 443 (SSL) and 5024.

For an overview of all the ports, see MDM Network Ports and CapaInstaller Network Port Reference.

Each platform you plan to manage also needs its own preparation, described in the following sections.

  1. Get an Apple account that can generate a push certificate for your CapaInstaller MDM solution. Register for the Apple Developer Program (recommended), or sign up for the Apple Developer Enterprise Program.

    Register well before the implementation. The registration can take some time to complete.

  2. Use the account from step 1 to generate an Apple Push certificate in the Apple Push Certificate wizard. The certificate gives access to the Apple push servers, and each MDM solution needs its own certificate. For a step-by-step guide, see Request and generate or update an Apple Push Certificate.

  3. Request a TLS/SSL certificate for the company website. Most companies already have one. It can be a wildcard certificate, or it can be issued to the server that hosts the MDM service. The certificate must come from a certificate authority whose root certificate Apple trusts — see Apple’s list of trusted root certificates.

    The MDM service binds the SSL certificate to its port automatically. If the binding fails, another certificate is probably already bound to that port.

  4. Check with your network manager that nothing prevents devices on the local network from reaching the internet on ports 2195–2196 and 5223. Mobile devices use these ports to contact the Apple Push Notification service.

Check with your network manager that nothing prevents devices on the local network from reaching the internet on ports 5228–5230. Mobile devices use these ports to contact Google Cloud Messaging.

  1. Make sure mobile devices can reach the OMA port set in the MDM service configuration. The default is 8443. Mobile devices use this port to contact CapaInstaller.

  2. Create a DNS alias for the subdomain EnterpriseEnrollment that points to the MDM server.

    During enrollment, the user enters an email address. The device uses the domain part of the address to discover the MDM service at https://EnterpriseEnrollment.<domain>/Discovery.svc. For example, if the user enters firstname.lastname@company.com, the device looks for https://EnterpriseEnrollment.company.com/Discovery.svc.

  1. Make sure .NET Framework 4.0 is installed on the DMZ server. If it isn’t, install it now.

  2. On a new CapaInstaller system with no services, make sure the internal server has a Back-end service and a Front-end service. If it doesn’t, deploy them before you deploy the MDM and SCEP services. See Deploy the Back-end Service and Deploy Front-end Service.

  3. Check that the Front-end and Back-end ports are open through the DMZ. On the DMZ server, open a browser and go to these URLs:

    • Front-end service: http://capaserver.company.com:<frontend public port>/cifrontend
    • Back-end service: http://capaserver.company.com:<backend public port>/cibackend

    If the DMZ has no DNS lookup, use the server’s IP address instead, for example http://<frontend server IP>:<frontend public port>/cifrontend.

    Each service responds with some internal JSON. What matters is that the response isn’t HTTP 404 (Not Found) or HTTP 500 (Internal Server Error). If it is, check the following:

    • Are the ports open from the DMZ to the Front-end and Back-end services?
    • Are both services running?
    • Does a local firewall, such as Windows Firewall, run on the computer that hosts the services? If so, disable it.
  4. In the CapaInstaller Console, open System Administration and deploy the SCEP service and the MDM service as offline installations, with the DMZ server as the target computer. See Offline service deployment and Simple Certificate Enrollment Service. This plan assumes the MDM and SCEP services run on the same server.

    In a setup without a DMZ (not recommended), deploy the services directly from System Administration to the internal server.

  5. Log in to the DMZ server and open the Back-end service’s install page at http://capaserver.company.com:<backend public port>/cibackend/install. If the DMZ has no DNS lookup, use http://<backend server IP>:<backend public port>/cibackend/install. The page lists the MDM and SCEP services you can install.

    If the page doesn’t open, check the following:

    • Are the ports open from the DMZ to the services?
    • Is the Back-end service running?
    • Does a local firewall, such as Windows Firewall, run on the computer that hosts the services? If so, disable it.

    If the page lists no MDM or SCEP service, check in System Administration that the services were deployed to the right computer.

  6. On the install page, select the MDM service. An executable file downloads. If the browser asks whether to keep the .exe file, allow it.

  7. Run the executable as an administrator. The MDM service installs and starts automatically.

    If the MDM service doesn’t install, check the following:

    • Did you run the .exe file as an administrator?
    • Is the MDM service installed in C:\Program Files\CapaInstaller\Services\MdmService?
    • Does the MDM service log file, C:\Program Files\CapaInstaller\Logs\Services\cimdm.log, show any errors?
    • Is the MDM service installed and running? Check Task Manager or the Services console.
  1. Install the TLS/SSL certificate and the Apple Push certificate on the DMZ server. See Certificate handling in CapaInstaller.

  2. On the install page, select the SCEP service. An executable file downloads. If the browser asks whether to keep the .exe file, allow it.

  3. Run the executable as an administrator. The SCEP service installs and starts automatically.

    If the SCEP service doesn’t install, check the following:

    • Did you run the .exe file as an administrator?
    • Is the SCEP service installed in C:\Program Files (x86)\CapaInstaller\Services\Scep?
    • Does the SCEP service log file, C:\Program Files (x86)\CapaInstaller\Logs\Services\ciScep.log, show any errors?
    • Is the SCEP service installed and running? Check Task Manager or the Services console.
  1. In the CapaInstaller Console, open System Administration and check that both services have a green check mark. If a service doesn’t, restart it.

  2. Log in to the DMZ server and open the URLs for the platforms you implement:

    Platform Service URL Expected result
    All MDM service https://mdm.company.com/cimdm An error page saying that the device can’t be enrolled in this service. The error is expected — it shows that the MDM service is running.
    Apple SCEP service http://localhost:<scep port> A placeholder page saying that the SCEP server is running.
    Windows MDM service, OMA https://mdm.company.com:<oma port>/omadm A placeholder page saying that the CapaInstaller OMA-DM server is running.
  3. Check that the services are reachable from the internet. Use a PC on the internet, or a phone or tablet on a mobile network. The device must reach the services from the internet, not from the local network. Open the URLs for the platforms you implement:

    Platform Service URL
    All MDM service https://mdm.company.com/cimdm
    Apple SCEP service http://mdm.company.com:<scep port>
    Windows MDM service, enterprise enrollment https://enterpriseenrollment.company.com/cimdm
    Windows MDM service, OMA https://mdm.company.com:<oma port>/omadm

    You get the same pages as in step 2. If you can’t reach the services, check the following:

    • Are the ports open from the internet to the DMZ?
    • Are the MDM and SCEP services running?
    • Does a local firewall, such as Windows Firewall, run on the computer that hosts the services? If so, disable it.

The server side is now ready for enrollment.

Before you enroll the first device, check that it’s compatible and ready:

  • The device is at least 80% charged, or plugged in.
  • You have backed up the device.
Platform Minimum version Notes
Apple iOS 5 Some features only work if the device is configured with an Apple account.
Android Android 2.3 Some features only work if the device is configured with a Google account. Use the Chrome browser for enrollment.
Windows Phone Windows Phone 8.1 Some features only work if the device is configured with a Microsoft account.

Enroll a test device for every platform you plan to support. See Device enrollment.

If a device doesn’t appear in the console after enrollment, check the Quarantined Units view — the device may be waiting for approval. If enrollment fails, check the services’ log files.

Your system is now ready, and your first device is enrolled and ready for management and deployment.

  • Register the Apple account for the Apple Push certificate well before the implementation. The registration can take some time to complete.
  • Create a DNS alias, so that all devices enroll at a short URL such as https://mdm.example.com/. If the MDM service moves to another server, you only redirect the alias.
  • Renew the Apple Push certificate before it expires. If it expires, you must re-enroll all Apple devices.
  • Use port 443 for the enrollment page in the MDM service configuration, because browsers assume port 443 for URLs that begin with https. If the service uses another port, add the port to the enrollment URL, for example https://mdm.example.com:8443/cimdm. Alternatively, use a DNS alias or a reverse HTTP proxy that routes port 443 to the configured port.
  • Protect the login URL, for example https://mdm.example.com/, with a valid SSL certificate.
  • Test new MDM profiles and devices in a development Configuration Management Point before you promote them to the production Configuration Management Point, as you do when you deploy software to PCs. Enrolled devices normally belong in the production point. To enroll a device in the development point, create a user that uses the development point, or move an existing user to it before enrollment.
  • If the DMZ server also runs IIS, see Make the MDM Service Work Together with IIS.