Skip to content

How to use Apple Business Manager (Apple DEP)

Apple Business Manager is a web-based portal where IT administrators deploy iOS, macOS, and tvOS devices from one place. When you link it to CapaInstaller, the devices you assign to CapaInstaller in Apple Business Manager are available for enrollment and management in CapaInstaller.

If you’re still enrolled in the Device Enrollment Program (DEP), upgrade to Apple Business Manager. When you sign in to Apple Business Manager, you’re prompted to upgrade.

For background, see Apple Device Enrollment Program and Apple Business Manager.

Section titled “Link CapaInstaller to Apple Business Manager”
  1. In System Administration, expand Software Accounts.
  2. Right-click Apple Device Enrollment Programs and select Add. The Add DEP Server wizard starts.
  3. Wait for the prerequisite check. If Verify OpenSSL doesn’t pass, see OpenSSL.
  4. Click Export Public Key and save the public key file.
  5. Sign in to Apple Business Manager. Add CapaInstaller as an MDM server, or edit your existing MDM server, and upload the public key.
  6. Download the server token (a .p7m file) from Apple Business Manager.
  7. In the wizard, click Upload Server token and select the .p7m file.
  8. Check the server and organization details that the wizard retrieves from Apple, and click Create.

The DEP server appears under Apple Device Enrollment Programs, with the folders Devices and Profiles.

Right-click the DEP server, and select Synchronize with Apple to fetch devices and profiles now. To synchronize automatically, schedule the global Replicator task Synchronize Apple Device Enrollment Program. It’s disabled by default. See Manage Global Replicator tasks schedule.

Right-click a profile or a device to manage it:

Object Actions
Profiles Create, Modify, View, Delete, Set profile as default, Clear default profile, Synchronize with Apple
Devices Assign Profile…, Remove Profile…, Pre-Configure Device…, Synchronize with Apple

For the details, see Create a DEP Profile and Assign DEP Profiles to Devices.

The server token expires after a period set by Apple. The DEP server’s Properties show the expiration date.

  1. Right-click the DEP server and select Properties.
  2. Click Export Public Key and save the file.
  3. In Apple Business Manager, upload the public key to your MDM server and download a new server token.
  4. Click Upload Server Token, select the new .p7m file, and click Ok.