In this article:
- What is Apple MDM Management?
- Accessing Apple MDM Management
- How to Set Up Apple MDM Management
- Renewing Apple Tokens
- Configuring Automated Device Enrollment
What is Apple MDM Management?
Apple MDM Management allows you to manage the certificates and tokens you need to provision iOS devices in the Esper console. After setup, you can sync devices between Apple Business (formerly Apple Business Manager or ABM) and Esper.
If you plan to provision iPhones, iPads, or Apple TVs , you must set up certificates and tokens in your Esper console. The following chart explains which certificates are needed per provisioning method:
| Provisioning Type | Description | Token or Certificate Requirements |
| Apple Business | Provision devices through Apple Business and seamlessly assign devices to your Esper tenant. |
APNS Certificate DEP Token (Requires an Apple Business account) VPP Token (Requires an Apple Business account) |
| Direct Profile | Provision devices manually via Apple Configurator and a QR code. | APNS Certificate |
After setting up the certificates and tokens in Apple MDM Management and enrolling them in Esper, you should navigate to the Esper Apple MDM page and press Sync Devices.
Devices are now synced with Apple Business and Esper.
Accessing Apple MDM Management
To access Esper MDM Management, click on your profile.
Then click on Apple MDM Management. You’ll see the certificate and tokens needed to begin provisioning iOS devices.
How to Set Up Apple MDM Management
Setting up the APNS Certificate
To set up an APNS Certificate, read Apple’s official APNS Certificate documentation.
After obtaining the APNS Certificate, go to the Esper Console, click on your profile, and select Apple MDM Management.
Then click on Setup Certificate.
First, click on Download Certificate.
The certificate will download to your computer.
Then click on Open Apple Identity Portal.
You’ll be redirected to the Apple Push Certificates Portal. You may need to sign in with a different account from your Apple Business to access Apple Push Certificates.
Then click on Create a Certificate.
Input the tenant name (your tenant name appears as the URL of your tenant: https://{tenant-name}.esper.cloud) and then click on Choose File.
Choose the certificate you downloaded from Esper and press Upload.
Then press Download.
Next, on Esper’s Manage Apple Token page, input your Apple ID. It must match the ID you used to create the APN certificate. This is usually an email address and must match the one you used to create the certificate. You must use the same ID when renewing the certificate, so we recommend using a service account for this process.
Then press Upload Apple Certificate to upload the certificate.
You’ve set up the APNS certificate.
Renewing the APNS Certificate
To renew an APNS certificate, go to Profile > Apple MDM Management. Then click on Renew Certificate.
Download the Esper certificate.
Then click on Open Apple Identity Portal.
You will be redirected to the Apple portal. Sign in using the same account listed under the Apple ID in Esper.
Then, while in the portal, click Renew.
After clicking renew, you can download the new certificate. Then go back to Esper and upload the renewed certificate.
Setting up the DEP Token
To set up the DEP token, read Apple’s official documentation.
Then navigate to Esper’s Apple MDM Management section, and click on Setup Token.
Then add the DEP Token. Click on Setup Token. Then click on Download Esper Key.
The key will be downloaded to your computer.
Then click on Open Apple Business Manager.
You'll be redirected to your Apple Business account. Log in, go to Devices > Management, and click on Add for Add device management service (this may be at the bottom).
Then upload the Esper Key. If you are renewing the DEP token, search for the token in the server list.
Then press Save.
Then, from the Device Management Services list, select the service, and click on the ellipsis menu (...). Then select Download Server Token.
In Esper, click on Upload Apple Token.
Upload the token to Esper.
Renewing the DEP Token
To renew the DEP Token, go to Apple Business and click on Management.
Then, from the Device Management Services list, select the service, and click on the ellipsis menu (...). Then select Download Server Token.
In the Esper console, go Profile > Apple MDM Management, locate the DEP section, and click on Renew Token and upload the token under Step 2.
You DEP token should be renewed. Look for the new renewal date in Apple MDM Management section.
Setting Up the VPP Token
To use applications from the Apple App Store®, you'll want to set up the Volume Purchase Program (VPP) Token.
If you are coming from a previous device management platform, you should migrate your existing VPP token as well. We recommend tying a VPP token to one specific location to avoid app installation issues.
To get started, click Setup Token in the VPP section.
Click on Open Apple Business. You’ll be redirected to the Apple Business page. You may have to log in.
Create a location in your Apple Business account for Esper MDM. We recommend creating a specific location for Esper. You'll need Administrator or People Manager privileges to create a location. See how to Configure Locations in Apple Business.
Then, navigate to Settings from the dropdown menu next to your profile.
In the Payments & Billing > Apps & Books section, choose the MDM (it'll have the same name as the location) and click Download next to your linked Esper MDM.
Next, go to Esper’s VPP page, and click on Upload Apple Token. Upload the Apple Token.
You’re now set up with Apple MDM in Esper. If you worked with a reseller, you should have devices in your Apple Business portal. Use the automatic Apple Business onboarding guide to add those devices to Esper. If you have devices that you'd like to add to Apple Business, see the manual Apple Business onboarding guide.
VPP Country Selection
If you use VPP apps across multiple regions, you can now select up to five countries that align with where your organization operates. Configure these countries in Apple MDM Management.
Then choose the appropriate region when adding or editing apps under Apps > VPP Apps.
Selecting the correct country for each VPP app helps ensure devices receive updates as expected. Apps assigned to a country that doesn’t match a device’s operating region may fail to update.
Renew Apple Tokens
Apple tokens are valid for one year. You will receive an alert in the console once it's time to renew your tokens.
Go to your Profile > Apple MDM Management and follow the prompts to renew your tokens. The steps for renewal are the same steps you took when setting up the token the first time. Use this article as a guide to renew the tokens and certificates.
Configuring Automated Device Enrollment
Choose the steps for Automated Device Enrollment (ADE, formerly known as DEP profile configuration) at the tenant level.
Requirements:
- Apple Business
- Supervised Devices
- Keys may have additional device and version requirements
Console Method
Setup Assistant steps control which screens device users see when activating a new iOS or iPadOS device. By default, all 41 steps are skipped, meaning devices provision with no setup screens shown. You can choose which steps to present based on your deployment requirements.
Changes apply to devices that enroll after you save. Devices already provisioned to the tenant are not affected.
- In the Esper Console, navigate to MDM Setup > Apple MDM.
- Under Setup Assistant steps, click Configure Setup Steps.
- Select each step you want device users to see during setup. Use the iOS / iPadOS filter to show only steps relevant to your deployment.
- To advance devices through setup without requiring device user input, enable Auto-advance Setup Assistant. This is enabled by default.
- Click Save.
The Setup Assistant steps card updates to reflect the number of steps currently skipped.
Note: Some steps are marked May Still Show. These steps may appear before the device fetches its cloud configuration, regardless of your selection.
Available setup steps
Steps are grouped by category. Each step lists the platforms and minimum OS versions it applies to.
| Category | Step | Description | Platforms |
|---|---|---|---|
| Apple Account & Services | Apple Account | Sign in to an Apple Account and iCloud | iOS, iPadOS, tvOS (iOS 7+, tvOS 10.2+) |
| App Store | App Store introduction pane | iOS, iPadOS (iOS 14.3+) | |
| Apple Pay | Set up Apple Pay | iOS, iPadOS (iOS 8.1+) | |
| iMessage & FaceTime | Enable iMessage and FaceTime | iOS, iPadOS (iOS 12+) | |
| iMessage Activation | Activate iMessage with a phone number | iOS, iPadOS (iOS 10+) | |
| Cellular / eSIM | Add a cellular plan (skips automatic eSIM setup) | iOS, iPadOS (iOS 12+) | |
| Siri | Set up Siri | iOS, iPadOS, tvOS (iOS 7+, tvOS 10.2+) | |
| Privacy & Diagnostics | Privacy | Data & Privacy information pane | iOS, iPadOS, tvOS (iOS 11.3+, tvOS 11.3+) |
| App Analytics | Share analytics with developers | iOS, iPadOS, tvOS (iOS 7+, tvOS 10.2+) | |
| Location Services | Enable Location Services | iOS, iPadOS, tvOS (iOS 7+, tvOS 10.2+) | |
| Apple Intelligence | Set up Apple Intelligence | iOS, iPadOS | |
| Security | Passcode | Prompt to set a device passcode | iOS, iPadOS (iOS 7+) |
| Touch ID / Face ID | Set up biometric authentication | iOS, iPadOS (iOS 8.1+) | |
| Lockdown Mode | Offer to enable Lockdown Mode | iOS, iPadOS (iOS 17.1+) | |
| Appearance & Display | Get Started | The welcome / Get Started pane | iOS, iPadOS (iOS 13+) |
| Choose Your Look | Light / Dark appearance choice | iOS, iPadOS (iOS 13+) | |
| What's New | Showcase of new OS features | iOS, iPadOS (iOS 26+) | |
| Liquid Glass | New Liquid Glass intro pane | iOS, iPadOS (iOS 27+) | |
| Screen Saver | Aerial screensaver intro | tvOS (tvOS 10.2+) | |
| Accessibility Appearance | Accessibility appearance options | iOS, iPadOS (iOS 17+) | |
| Device Features | Keyboard (May Still Show) | Keyboard selection pane | iOS, iPadOS (iOS 13+) |
| Dictation (May Still Show) | Set up Dictation | iOS, iPadOS (iOS 13+) | |
| Action Button | Configure the Action Button | iOS, iPadOS (iOS 17+) | |
| Camera Control | Configure Camera Control | iOS, iPadOS (iOS 18+) | |
| Multitasking | iPad multitasking intro | iOS, iPadOS (iOS 26+) | |
| Screen Time | Screen Time setup | iOS, iPadOS (iOS 12+) | |
| Screen Time & Safety | Safety | Safety features intro | iOS, iPadOS (iOS 16+) |
| Safety & Handling (May Still Show) | Safety & handling information | iOS, iPadOS (iOS 18.4+) | |
| Terms & Conditions | Accept Terms and Conditions | iOS, iPadOS, tvOS (iOS 7+, tvOS 10.2+) | |
| Legal & Onboarding | Terms of Address (May Still Show) | Preferred terms of address | iOS, iPadOS |
| Terms & Conditions | Accept Terms and Conditions | iOS, iPadOS, tvOS (iOS 7+, tvOS 10.2+) | |
| Restore & Migration | Restore from Backup | Restore apps & data from a backup | iOS, iPadOS (iOS 7+) |
| Restore Completed | Confirmation after a restore | iOS, iPadOS (iOS 14+) | |
| Move from Android | Remove the Move from Android option in the Restore pane | iOS, iPadOS (iOS 9+) | |
| Device-to-Device Migration | Transfer from another Apple device | iOS, iPadOS | |
| Apple Watch Migration | Migrate a paired Apple Watch | iOS, iPadOS (iOS 11+) | |
| Software Updates | Software Update | Mandatory software update screen | iOS, iPadOS (iOS 12+) |
| Update Complete | Software update complete pane | iOS, iPadOS (iOS 14+) | |
| Apple TV | TV Home Screen Sync | Sync Home Screen layout | tvOS (tvOS 11+) |
| TV Provider Sign-In | Sign in to a TV provider | tvOS (tvOS 11+) | |
| Apple TV Room | "Where is this Apple TV?" pane | tvOS (tvOS 11.4+) |
API method
Use the API to create a uniform setup experience for every Apple device that will be provisioned to the tenant. See Apple's documentation for a list of available skip keys.
Create or Update:
curl --request POST \
--url https://{tenant}-api.esper.cloud/api/tenant/v0/depprofiles \
--header 'authorization: Bearer API_KEY' \
--header 'content-type: application/json' \
--header 'x-tenant-id: ENTERPRISE_ID' \
--data '{
"show_setup_items": [
"Appearance",
"Diagnostics",
"AppleID",
"Biometric",
"Passcode",
"Privacy",
"TOS",
"ScreenTime",
"Welcome",
"Intelligence"
],
"auto_advance_setup": true
}'Get Current DEP Profile for Tenant:
curl --request GET \
--url https://{tenant}-api.esper.cloud/api/tenant/v0/depprofiles \
--header 'authorization: Bearer API_KEY' \
--header 'content-type: application/json' \
--header 'x-tenant-id: ENTERPRISE_ID'Note: The tenant-level DEP profile configuration expects a JSON payload. When configuring at the blueprint level, use a property list (PLIST).