IBM Security MaaS360

 View Only

New Apple Automated Device Enrollment Workflows For iOS

By Matt Shaver posted Wed April 08, 2020 06:09 PM

  

MaaS360.jpg
This week MaaS360 teams have rolled out a few new features pertinent to the iOS automated device enrollment process (ADE - formerly known as DEP).

Apple has enhanced the enrollment process for devices by allowing MDM solutions to add customized screens during setup to address SAML enrollment and custom terms and conditions.  With iOS 13 and macOS 10.15 MaaS360 can implement these features with just a few setup items in the portal.

Custom EULA Display

Within the portal there are two areas that need to be configured to display a custom EULA during DEP enrollment.  First, navigate to Setup-->Settings and under Device Enrollment Settings select Advanced.  Enable the "Corporate Usage Policy" checkbox and upload a proper TXT or HTML file.  Admins will be able to preview the display to ensure it appears properly.

Screen_Shot_2020-04-08_at_4_55_08_PM.png
Screen_Shot_2020-04-08_at_5_06_13_PM.png

Once the usage policy has been enabled, make sure to Save the settings.

Navigate to the Device Enrollment Program setup page and edit or create a new DEP profile.  There is a check box to enable the usage policy (note it is only available for iOS 13+ and macOS 10.15+.  Devices below the OS versions listed will not see any new behavior).

Screen_Shot_2020-04-08_at_5_10_53_PM.png
Upon booting up a new device most of the enrollment workflows will remain the same.  It isn't until the user gets to the authentication screen that they will notice a difference.  Rather than seeing the embedded Apple screen, a MaaS360 window will pop up, and the user will see a more traditional manual enrollment UI (note: the user will not be able to adjust ownership). 

They will then be prompted to accept the MaaS360 native EULA, then the company EULA.  If the user chooses not to accept either, the device will not complete enrollment, but will also not complete activation.  They will not be able to move forward without accepting both.

Screen_Shot_2020-04-08_at_10_03_02_AM_2.png
Screen_Shot_2020-04-08_at_10_03_16_AM_2.png
Screen_Shot_2020-04-08_at_10_04_23_AM_2.png
Screen_Shot_2020-04-08_at_10_04_37_AM_2.png
SAML Enrollment

SAML Enrollment for DEP, much like the usage policy, is only available on iOS 13+ and macOS 13+.  When the default enrollment method is set to SAML, devices below these OS versions will get the standard login screen which will look to directory credentials for authentication.

When SAML enrollment is configured in the portal (test before deployment using the manual enrollment link of http://m.dm/corpID), nothing else needs to be done to enable the setup for DEP devices if users are already being prompted to authenticate as part of the DEP profile.

Screen_Shot_2020-04-08_at_5_25_20_PM.png
Much like the workflows above, the device will display a MaaS360 enrollment screen, rather than the embedded Apple setup screen.

Screen_Shot_2020-04-08_at_3_51_32_PM.png

Screen_Shot_2020-04-08_at_3_51_42_PM.png
*note: user will not be able to change ownership. 

The device will then redirect to the proper SAML authentication page

Screen_Shot_2020-04-08_at_3_51_53_PM.png
Screen_Shot_2020-04-08_at_3_52_37_PM.png
Once the credentials are validated the user will be brought to the MaaS360 EULA screen, and if configured, the company EULA policy as well.  The device will resume setup as defined by the DEP profile.

For more information around DEP profile configuration and settings available in MaaS360, please visit our Knowledge Center.  If there are any questions that arise from this post, our Security Community forums under the "Discussions" tab are a great place to get answers direct from MaaS360 technical experts.


1 comment
27 views

Permalink

Comments

Mon April 20, 2020 09:22 AM

Is SAML the only Auth type that is now incorporated to the Authentication interface?  

For instance, can we use this with the OTP option?

Thank You,

Bryan