Supported editions for this feature: Frontline Standard; Enterprise Standard and Enterprise Plus; Education Standard, Education Plus, and Endpoint Education Upgrade; Cloud Identity Premium. Compare your edition
As an administrator, you can manage company-owned iPhones and iPads in the Google Admin console alongside other devices you manage there. To do so, you connect Apple Business Manager or Apple School Manager with your Google Workspace or Cloud Identity subscription.
How the Apple Device Enrollment integration works
You integrate Apple Business Manager or Apple School Manager with your Admin console by providing an authorization key or token to each entity. These tokens allow Google endpoint management to push configuration settings from Admin console to the devices through a mobile device management configuration profile and the Google Device Policy app.
The server token you get from Apple expires annually. You must renew the token for devices to sync work data. However, unlike the Apple push notification certificate, you can renew the token after it expires.
Before you begin
- Review the device requirements.
- Get an account to sign in to your organization's Apple Business Manager or Apple School Manager.
- For easiest management, buy iOS devices for your organization through an authorized Apple retailer. To find an authorized Apple retailer, contact Apple Support. The devices are automatically linked to your Apple Business Manager or Apple School Manager.
- Turn on advanced mobile management for the organizational unit that will use the devices.
Note: The following steps require that you complete actions in both the Google Admin console and in Apple Business Manager or Apple School Manager with your business or school Apple ID. Make sure you have access to both before you continue.
Step 1: Set up Apple Enrollment
You must be signed in as a super administrator for this task. Admins who have the Mobile Device Management privilege but aren't super admins always see the setup flow, even if your organization is already set up. If they try to download the public key, they get an error message.
-
Sign in to your Google Admin console.
Sign in using an account with super administrator privileges (does not end in @gmail.com).
-
In the Admin console, go to Menu DevicesMobile & endpointsSettingsiOS.
- Click Apple certificatesSet Up Enrollment.
- Click Get public key. The public key downloads to your device.
- Open Apple Business Manager or Apple School Manager and sign in with your business Apple ID. In the Device Enrollment Program section:
- Click Manage Servers.
- If you already set up an MDM Server to use for these devices, click it. Otherwise, create a server.
- When prompted, upload the public key you downloaded from the Admin console.
- Download the server token from Apple.
- Return to the Admin console.
- Under Business Apple ID, enter the Apple ID you used to get the token. This entry helps you track which admin did the setup.
- Click Upload Server Token, select the token you downloaded from Apple, and click Open.
- Click Save & Continue.
- The token and its expiration date are now listed on the settings page. Set a calendar reminder to renew the token before it expires.
Step 2: Configure device setup settings
You can control how company-owned iOS devices are set up when a user first signs in. These settings apply to your entire organization.
-
Sign in to your Google Admin console.
Sign in using your administrator account (does not end in @gmail.com).
-
In the Admin console, go to Menu DevicesMobile & endpointsSettingsiOS.
- Click Company-owned iOS device setupDevice enrollment settings. To learn more about the settings, see the iOS settings reference.
- Click Save.
Step 3: Configure iOS device restrictions
In addition to the settings available to all iOS devices under advanced management, for supervised devices you can control user access to more apps and settings. You can configure these management settings by organizational unit. For example, you can allow users in some organizational units to install apps, but block app installation for other organizational units.
For details on the settings that apply only to supervised devices, see the iOS settings reference.
Step 4: Enroll and distribute company-owned iOS devices for management
- Open Apple Business Manager or Apple School Manager and sign in with your business Apple ID.
- Assign the devices to the MDM Server you connected to Google endpoint management. The serial numbers of the devices you want to manage through Google endpoint management must already be in the system (entered by your authorized Apple retailer).
- To assign all devices to the server by default, set the default assignment.
- To bulk enroll devices, download a CSV file of their serial numbers, then upload the CSV file.
- To assign devices individually, enter the serial number.
For details, see the Apple Device Enrollment documentation.
Note: It can take up to 24 hours for a device to be ready to use after you assign it to the MDM server.
-
(Optional) To use the device sooner, manually sync devices in the Admin console. Follow the steps in Manually sync devices.
- Distribute devices to your users. When users first sign in, they follow an easy setup flow. For details, see Set up a company-owned device.
Manage company-owned iOS devices
Add a company-owned device to Apple Device Enrollment- Go to Apple Business Manager or Apple School Manager and remove the device. On the next sync with Google, the device is removed from the devices list in the Admin console. The sync can take up to 24 hours to complete.
- To remove the device sooner, in the Admin console, you can Manually sync devices.
If you delete a device from the devices list
The management profile is removed from the device. When a user adds their work account to the device again without a factory-reset, the device is enrolled as unsupervised. You have the management capabilities of advanced mobile management, but settings that only apply to supervised devices aren't enforced.
- Delete the device from the devices list.
- Factory reset the device.
- Have the new user sign in to the device.
-
Sign in to your Google Admin console.
Sign in using your administrator account (does not end in @gmail.com).
-
In the Admin console, go to Menu DevicesMobile & endpointsSettingsiOS.
- Click Apple certificatesSync DEP Devices.
Related articles
Google, Google Workspace, and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated.