ESET PROTECT – Table of Contents

Apple Business (AB) synchronization (iOS)

The Apple Business (AB) is Apple's new method for enrolling corporate iOS devices. With AB you can enroll the iOS devices without any direct contact with the device and also with minimal interaction from the user. The AB enrollment provides administrators the option to customize the complete device setup process. It also provides the option to prevent users from removing the MDM profile from the device. You can enroll your existing iOS devices (if they meet the iOS devices AB requirements) and all iOS devices that you will buy in the future. For further information about AB see the AB Documentation.


Important

Before performing the iOS AB enrollment, you must enable AB synchronization in your ESET PROTECT Web Console. To do so, navigate to More > Settings > Apple Business (AB) synchronization.

Synchronize your ESET PROTECT MDM with AB server

1.Verify that all AB Requirements are met for both account requirements and device requirements.

AB Account:

oThe program is only available in certain countries. Visit the AB web page to see if AB is available in your country.

oAB Account requirements can be found on these websites: Apple deployment program requirements and Apple Device Enrollment Program requirements.

oSee the detailed AB device requirements.

2.Log in to your AB Account (if you do not have an AB account you can create it).

3.From the Device Management Settings section select Add MDM Server.

Add MDM Server.

4.In the Untitled MDM Server screen type your MDM Server Name, for example: "MDM_Server".

Type the MDM Server name.

5.Upload your public key into the AB portal. Click Choose File and select the public key file (this is the public key file you download from the AB settings screen in ESET PROTECT) and click Save.

Upload your public key into the AB portal.

6.Click Download Token to download your AB Token. This file will be uploaded into the ESET PROTECT Settings under AB Server token > Upload.

Click Download Token to download your AB Token.

Add iOS Device into AB

The next step is to assign iOS devices to your virtual MDM Server inside AB portal. You can assign your iOS devices by serial number, order number or by uploading a list of Serial numbers for target devices in CSV format. Either way, you must Assign the iOS device to the virtual MDM Server (you created in the previous steps).

1.Navigate to the Devices section of the AB portal and select the device you want to assign and click Edit Device Management.

Click Edit Device Management.

2.After selecting your MDM server from the list, confirm your selection and the mobile device will be assigned to your MDM server.


Warning

After a device is removed from the AB portal, it is removed permanently, you cannot add it back.

After that you can leave the AB portal and continue in ESET PROTECT Web Console.


Warning

If you are enrolling iOS devices that are currently in use (and that meet the device requirements) new policy settings will be applied to them after a factory reset of target device.

The Cloud MDM synchronization interval is set to 30 minutes, so you will need to wait for this time period for the Apple device to appear in ESET PROTECT.

Troubleshooting—Re-add a removed AB device

If you have removed an AB device from the list of devices in ESET PROTECT Web Console, follow the steps below to re-add the device to ESET PROTECT Web Console:

1.Unassign the device from the MDM Server in AB. Do not release the device in the AB portal.

2.Wait for 30 minutes.

3.Re-assign the device to the MDM Server.