Muistiinpano
Tämän sivun käyttö edellyttää valtuutusta. Voit yrittää kirjautua sisään tai vaihtaa hakemistoa.
Tämän sivun käyttö edellyttää valtuutusta. Voit yrittää vaihtaa hakemistoa.
Applies to macOS
An enrollment program token (sometimes called an automated device enrollment token) is a required component of Apple automated device enrollment (ADE) for macOS. It creates the trust relationship between Microsoft Intune and Apple Business Manager or Apple School Manager, and allows Intune to:
- Sync device information from your Apple enrollment program account.
- Upload enrollment profiles to Apple.
- Assign devices to enrollment profiles.
This article describes how to create, renew, and delete enrollment program tokens for macOS.
Note
The steps in this article are the same whether you're using Apple Business Manager or Apple School Manager. For brevity, this article refers to Apple Business Manager only, except where clarification is necessary.
Create an enrollment program token
Step 1: Download the Intune public key certificate
The public key certificate is needed to request a trust-relationship certificate from Apple Business Manager.
In the Microsoft Intune admin center, go to Devices > Enrollment.
Select the Apple tab.
Under Bulk Enrollment Methods, select Enrollment program tokens.
Select Add.
Select I agree to grant permission to Microsoft to send user and device information to Apple.
Select Download your public key and save the key as a PEM file locally. The key is used to get the MDM server token in the next step.
Important
Keep this browser tab open. If you close the tab, the certificate you downloaded is invalidated and you'll need to start over.
Step 2: Add an MDM server in Apple Business Manager and download the server token
Add Intune as a mobile device management (MDM) server in Apple Business Manager, and then download the server token.
In the admin center, select the link that corresponds with the Apple portal you use:
- Create a token via Apple Business Manager
- Create a token via Apple School Manager
The selected portal opens in a new browser tab. Switch to the new tab, but keep the Intune tab open.
Sign in to the Apple portal with your company Apple ID.
Important
Use your organization's Apple ID, not a personal one. You and your organization will need this Apple ID to renew and manage the token going forward.
Go to your account profile > Preferences.
Go to your MDM server assignments.
Select the option to add an MDM server.
Name the MDM server. The name is for identification purposes in Apple Business Manager and doesn't have to match the actual Microsoft Intune server name or URL.
Upload your public key (.pem) file, and then save your changes.
Download the server token (.p7m file).
Step 3: Assign devices to the MDM server
After you create the MDM server in Apple Business Manager, assign devices to it. You can do this now or come back later.
We recommend assigning devices now since you're already in Apple Business Manager. You can use available features like filters and bulk assignment to simplify selection. For more information and steps, see Assign, reassign, or unassign devices in Apple Business Manager.
Step 4: Save the Apple ID
Return to the Intune admin center tab.
In the Apple ID field, enter the Apple ID used to download the server token.
This ID is the Apple ID you'll need to renew the token each year. Make sure future Intune admins know which Apple ID was used, in case you leave your organization and need to transition token management.
Step 5: Upload the server token and finish
- In the Apple token field, browse to the server token (.p7m file) you downloaded from Apple Business Manager.
- Select Open, and then select Create.
Intune automatically connects with Apple Business Manager to sync device information from your enrollment program account.
Renew an enrollment program token
Renew your enrollment program token yearly. The Intune admin center shows the token expiration date. Also renew the token in these situations:
- The Apple ID password changes for the user who set up the token in Apple Business Manager.
- The user who set up the token in Apple Business Manager leaves the organization.
Sign in to Apple Business Manager with an account that has an Administrator or Device Enrollment Manager role.
Select Settings. Under MDM Servers, select the MDM server associated with the token file you want to renew.
Select Download Token.
Note
Don't select Download Server Token unless you intend to renew the token. Doing so invalidates the token currently in use by Intune. If you already downloaded the token, complete the remaining steps to finish the renewal.
After downloading the token, go to the Microsoft Intune admin center.
Go to Devices > Enrollment.
Select the Apple tab.
Under Bulk Enrollment Methods, select Enrollment program tokens.
Select the token you want to renew.
Select Renew token. Enter the Apple ID used to create the original token.
Upload the newly downloaded token.
Select Next. Assign scope tags if needed.
Select Create to save your changes.
Delete an enrollment program token
Warning
Deleting devices from a token (required before you can delete the token) removes those devices from Intune management. If the devices are still in use, users will lose access to corporate resources and apps managed by Intune. Wipe and re-enroll devices with a new token if you want to continue managing them.
You can delete an enrollment program token from Intune as long as:
- No devices are assigned to the token.
- No devices are assigned to the default profile.
- There are no enrollment profiles under that token.
To delete an enrollment program token:
- In the Microsoft Intune admin center, go to Devices > Enrollment.
- Select the Apple tab.
- Under Bulk Enrollment Methods, select Enrollment program tokens.
- Select the token, and then select Devices.
- Delete all devices assigned to the token.
- Return to Enrollment program tokens. Select the token, and then select Profiles.
- Delete all enrollment profiles listed, including any default profile.
- Return to Enrollment program tokens. Select the token, and then select Delete.