Kaseya MDM: Enrollment

NAVIGATION  Modules > Integrations > Connectors

NAVIGATION  Modules > Devices > MDM Enrollment

PERMISSIONS  Connectors > Full access to all Connectors pages

PERMISSIONS  Device Management > Add Devices

PERMISSIONS  Administrative privileges to manage software on the device to be enrolled and any endpoints assisting in the enrollment

Kaseya offers mobile device management (MDM) for supported devices. This article provides compatibility, prerequisite, and process information pertaining to Kaseya's standalone MDM solution.

To learn how to migrate to Kaseya from another MDM solution, refer to Kaseya MDM: Migrating from another MDM solution.

Prerequisites

Compatibility

Our MDM solution currently supports enrollment for the following Apple operating systems:

  • iOS 4.0 and above
  • iPadOS 4.0 and above

Permissions

To complete this process, you'll need the following permissions:

  • Full access to all Connectors pages.
  • Ability to log in to appleid.apple.com with the Apple ID of the device or devices you'd like to enroll.
  • If configuring Automated Device Enrollment (ADE), ability to log in to Apple Business Manager with Administrator or Device Enrollment Manager credentials.

Device Enrollment vs. Automated Device Enrollment (ADE)

The two types of Apple MDM connectors available in Kaseya MDM drive your enrollment strategy. For a basic overview, refer to Types of Apple MDM connectors in the Kaseya MDM: Connectors article.

Device Enrollment

To enroll devices in Kaseya MDM using QR code or USB enrollment methods, you'll perform the following steps:

  1. Configure an Apple MDM Push Certificate connector in Kaseya MDM. Refer to Create an Apple MDM Push Certificate connector in Kaseya MDM.
  2. Create a push certificate in the Apple portal and upload it to Kaseya MDM. Refer to Create a push certificate.
  3. Enroll devices one at a time into Kaseya MDM. Refer to Manually enroll a device in MDM.

ADE

To configure automatic Kaseya MDM-enrollment of devices assigned to a dedicated server in Apple Business Manager, you'll perform the following steps:

  1. Configure an Apple MDM Push Certificate connector in Kaseya MDM. Refer to Create an Apple MDM Push Certificate connector in Kaseya MDM.
  2. Create a push certificate in the Apple portal and upload it to Kaseya MDM. Refer to Create a push certificate.
  3. Create an Apple Automated Device Enrollment connector in Kaseya MDM, and generate an MDM server token in Apple Business Manager to upload to Kaseya MDM. Refer to Configure Automated Device Enrollment (ADE).

ADE behavior

After configuring ADE, every device assigned to the newly added MDM server in Apple Business Manager automatically appears in Kaseya MDM and is added to the agent group specified in the connector. The following applies to devices processed through ADE:

  • These devices are enrolled in supervised mode, granting full control over device configurations and ensuring compliance with organizational policies. Refer to Kaseya MDM: Supervised vs. non-supervised devices.
  • These devices will receive all the assigned configuration profiles, ensuring consistent and secure device management across the organization.
  • Non-activated devices appear on Kaseya MDM device pages as offline with an Enrollment status of Unenrolled. They do not consume licenses until activated.
  • These devices are activated in Kaseya MDM once they are turned on and undergo standard Apple device setup/activation. During this process, the Remote Management screen will show that the device is enrolling into remote management by your Kaseya MDM instance. Once activated, the Enrollment status on Kaseya MDM device pages changes to Enrolled, and MDM Commands become available. Refer to Kaseya MDM commands.

How to...

Kaseya MDM commands

Once you've enrolled a device in MDM, the following commands will become available. Note that availability of any command is dependent on both the device type and enrollment method used.

Command iOS/iPadOS
QR code enrollment USB enrollment
Non-supervised Supervised
Restart FALSE TRUE
Shutdown FALSE TRUE
Enable/Disable lost mode FALSE TRUE
Play Lost Mode Sound FALSE TRUE
Erase FALSE TRUE

Refer to Kaseya MDM: Supervised vs. non-supervised devices.

Next step: Configuring Apple MDM profiles

After a device completes the enrollment process, any configuration or management policies you've defined for its type will automatically apply. For more information, refer to Kaseya MDM: Apple MDM profiles.