{"id":47664,"date":"2023-02-23T10:00:00","date_gmt":"2023-02-23T15:00:00","guid":{"rendered":"https:\/\/jumpcloud.com\/?p=47664"},"modified":"2023-02-23T10:40:04","modified_gmt":"2023-02-23T15:40:04","slug":"migrate-apple-mdm","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/migrate-apple-mdm","title":{"rendered":"How to Seamlessly Complete an Apple MDM Migration"},"content":{"rendered":"\n
What are you guys doing to cut costs?<\/em><\/p>\n\n\n\n Sit in any room full of CEOs, investors, or executives, and you are bound to hear the conversation steer toward how to best conserve capital. The current macroeconomic climate is motivating organizational leaders and regular folks alike to reexamine their budgets. <\/p>\n\n\n\n There are many ways for small to medium-sized enterprises (SMEs) to curb spending, but one of the easiest avenues is tool consolidation<\/a>. Instead of licensing 10 different point solutions, why not incorporate them into three or four multi-purpose platforms? <\/p>\n\n\n\n The 探花大神 Platform Directory<\/a> unifies IT stacks under one pane of glass, merging directory management and mobile device management (MDM), among other capabilities. The result? A frictionless admin experience that saves time, energy, and money.\u00a0<\/p>\n\n\n\n There has never been a better time to migrate from a single-point MDM to a multi-purpose IT management platform like 探花大神. <\/p>\n\n\n\n There are several reasons for MDM migration, but it primarily comes down to a) wanting to conserve resources and b) wanting a better user experience than the current MDM provides. <\/p>\n\n\n\n Regardless of the motivation, MDM migrations often instigate compatibility issues, end-user resistance, and other complexities for admins to sidestep. This article will outline an Apple MDM migration strategy to ensure a smooth outcome, whether the devices are enrolled through regular device enrollment or automated device enrollment (ADE). <\/p>\n\n\n\n Are you currently relying on Apple Business Manager for your MDM needs? The remainder of this article will walk through the process of an Apple MDM migration.<\/p>\n\n\n\n Your device migration strategy not only depends on the new MDM but also on your current one. Take note of what you dislike about your existing MDM and make a wish list of what you\u2019d like in your new MDM. <\/p>\n\n\n\n It\u2019s worth considering what needs you need to fulfill in addition to Mac management before switching vendors. Although you can select a single-purpose MDM solution, comprehensive platforms exist to meet more of your identity and access management needs along with device management.<\/p>\n\n\n\n Things to consider when choosing a new MDM solution include:<\/strong><\/p>\n\n\n\n A point MDM solution will likely be more expensive than an integrated solution. Case in point, many Apple-focused MDMs charge by the device, whereas a cloud identity management platform will charge by user and give you multiple devices per user.<\/p>\n\n\n\n 探花大神 gives you four devices included with its per-user charge. It\u2019s worth assessing whether you\u2019ll use enough of a single-purpose MDM\u2019s feature set to justify the price. <\/p>\n\n\n\n A point Apple-only MDM solution likely has the deepest feature set for macOS devices, while a solution with MDM as just one of its capabilities will meet a broader set of needs in your organization \u2014 such as identity management and Windows and Linux device management. <\/p>\n\n\n\n For heterogeneous work environments, it\u2019s important to adopt an integrated MDM solution that can onboard devices on other operating systems besides Apple.<\/p>\n\n\n\n You can also establish a zero-touch enrollment workflow with Apple Business Manager<\/a> or Apple School Manager to automatically enroll new machines in 探花大神 MDM, as well as install the 探花大神 agent on them. The agent is used to propagate a user\u2019s core identity to their machine and other device and identity management tasks.<\/p>\n\n\n\n You may also prioritize features like: <\/strong><\/p>\n\n\n\n Ensure you choose an MDM solution that addresses the seven most common challenges of mobile device management<\/a>. With solutions for Apple MDM, Windows MDM, and Linux MDM, 探花大神 allows admins to implement cross-platform MDM that keeps all their devices secure. For the remainder of this article, we\u2019ll assume you chose 探花大神 for MDM. <\/p>\n\n\n\n Configure 探花大神 as a mobile device management (MDM) server by establishing a secure connection between Apple and 探花大神 using certificate-based authentication. Use a push certificate to establish that secure connection between 探花大神 and Apple Push Notification Service (APNs). You\u2019ll need an Apple ID and password to do this.<\/p>\n\n\n\n To configure MDM complete the following steps:<\/strong><\/p>\n\n\n\n Log in to the 探花大神 Admin Portal<\/a> and go to Device Management > MDM<\/em>. <\/em>On the MDM homepage, click Configure MDM<\/em>:<\/p>\n\n\n\n Under Download Your CSR, click Download<\/em> and save the file:<\/p>\n\n\n\n Click Go to Apple<\/em> and log in to the Apple Push Certificate Portal<\/a>:<\/p>\n\n\n\n Click Create A Certificate<\/em>:<\/p>\n\n\n\n Upload your 探花大神 CSR, then click Continue<\/em>:<\/p>\n\n\n\n Click Download<\/em> to download the new certificate (for example, MDM_探花大神_certificate.pem). Then, in the 探花大神 Admin Portal, under Upload MDM Push Certificate on the Set-Up Apple MDM Certificate page, click Browse<\/em> to find the Apple Push Certificate or drag and drop the file:<\/p>\n\n\n\n Finally, click Complete Setup<\/em>. <\/p>\n\n\n\n A message on the MDM Home tab indicates that MDM is configured. As you can see, forging a connection between Apple and 探花大神 is easy peasy. <\/p>\n\n\n\n Click here to learn more<\/a> about establishing a secure connection between Apple and 探花大神.<\/p>\n\n\n\n After you have configured 探花大神\u2019s mobile device management (MDM) server, you can enroll your macOS, iOS, and iPadOS devices in MDM. 探花大神 MDM lets you securely and remotely configure your organization\u2019s devices and update software and device settings. <\/p>\n\n\n\n Below are your options for enrolling company-owned and bring-your-own (BYOD) Apple devices: <\/p>\n\n\n\n Read more<\/strong><\/a> about Apple and 探花大神 MDM integration.<\/strong><\/p>\n\n\n\n It\u2019s worth emphasizing that 探花大神 has a pre-built policy<\/a> you can apply to 探花大神-managed macOS devices. This feature allows you to enroll your devices in bulk. <\/p>\n\n\n\n When you apply the policy, you have the option of checking a box that removes the existing non-探花大神 MDM enrollment profile and automatically un-enrolls them from their last MDM. You can also use this policy to enroll new machines quickly.<\/p>\n\n\n\n Unfortunately, organizations using automatic device enrollment can\u2019t yet take advantage of 探花大神\u2019s one-click migration feature.<\/em> Devices with removable enrollment profiles can<\/em> take advantage of the feature. But if the profile is non-removable, unenrollment must originate from their current MDM. <\/p>\n\n\n\n For ADE-enrolled machines, you instead need to go through Apple Business\/School Manager and switch the association of their serial numbers to the new MDM server. See Configuring Automated Device Enrollment<\/a> for more information on configuring 探花大神 MDM in ABM\/ASM.<\/p>\n\n\n\n After you have configured, enrolled, and deployed your Apple devices, you\u2019re MDM migration is complete. You can now remotely and securely implement policies and execute commands.<\/p>\n\n\n\n Use 探花大神\u2019s ready-to-use policies to securely and remotely manage devices in your organization or create custom policy profiles<\/a> to distribute specialized payloads and restrictions. Some of the commands you can execute include lock, restart, shut down, erase, and unenroll. <\/p>\n\n\n\n With 探花大神, Apple MDM is just one of the features to help you securely manage identities, access, and devices.<\/p>\n\n\n\nMDM Migration: Apple Business Manager to 探花大神 <\/h2>\n\n\n\n
<\/figure>\n\n\n\n
1. Choose Your New MDM<\/h3>\n\n\n\n
Cost Considerations <\/h4>\n\n\n\n
Capability Considerations<\/h4>\n\n\n\n
Zero-Touch Enrollment <\/h4>\n\n\n\n
Other Considerations<\/h4>\n\n\n\n
\n
2. Establish a Connection Between Apple and 探花大神<\/h3>\n\n\n\n
<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
<\/figure>\n\n\n\n
3. Choose an Enrollment Method<\/h3>\n\n\n\n
\n
探花大神 Makes MDM Migration Easy<\/h2>\n\n\n\n