Getting started
A few connections.
A simpler rollout.
A practical guide to setting up your Apple workspace.
Connecting Apple Business Manager & APNs
Connect the services that let AAMDM enroll company devices and notify them when management updates are available.
Have access to your organization’s Apple Business Manager account, an organization-controlled Apple Account for certificate management, and administrator access to AAMDM.
1Create your APNs certificate
In AAMDM, open Apple connections and download the certificate signing request. Use your organization-controlled Apple Account in the Apple Push Certificates Portal to create an MDM push certificate, then upload it to AAMDM.
Workspace → Settings → Apple connections APNs certificate → Download request → Upload certificate
2Link Apple Business Manager
Download the public key from AAMDM. In Apple Business Manager, create a device management service and upload that key. Download the resulting server token and upload it to your AAMDM workspace.
3Assign devices and sync
Assign the company devices to your AAMDM service in Apple Business Manager. Return to AAMDM, sync the connection and review the imported inventory before setting the enrollment profile.
Connection: Apple Business Manager Enrollment profile: Company standard Assignment: Selected company devices
4Verify with a test device
Use a suitable test device to check enrollment and policy delivery. Confirm that the device appears in the workspace and reports its management status.
Record the account used to create the APNs certificate. Renew the existing certificate with the same account, and monitor server-token expiry in Apple connections.
Enroll your first device
Start with a test device and confirm the experience before rolling out to the rest of your team.
1Choose the enrollment path
For company-owned devices, confirm the Apple Business Manager assignment. For supported employee enrollment, share the workspace enrollment page.
2Complete device setup
Connect the device to a network and follow its setup screens. Review the management notice and complete the required enrollment steps.
3Confirm the inventory record
Open Devices in AAMDM. Check the device name, ownership, enrollment status and assigned group.
Device: iPhone 16 — Sales-07 Group: Sales Management status: Enrolled
Existing devices may need additional preparation. Confirm ownership, backups and the intended enrollment method before erasing or resetting anything.
Apply your first policy
Create a small baseline, test it on a limited group and review the reported result.
1Create a baseline
Open Configuration policies. Create a policy for the target platform and configure your organization’s passcode and connectivity requirements.
2Assign a test group
Select a small device group. Review the policy settings and assignment before publishing.
Policy: Company baseline Target: Test devices State: Ready for review
3Review device status
Check that devices have received the policy. Investigate pending or unsupported settings before expanding the assignment.
Use descriptive policy names and review the audit log after each change.
Maintain Apple connections
Keep a clear record of service owners and upcoming certificate and token renewals.
1Review connection health
Open Apple connections and check the APNs certificate, enrollment token and apps token expiry dates.
2Renew the existing connection
Use the appropriate organization-controlled account to renew the existing certificate or token. Upload the renewed file to its matching connection in AAMDM.
3Verify after renewal
Confirm the new expiry date, run a sync and check management communication with a test device.
For APNs, renew the existing certificate with the account that created it. Record the renewal and the next review date in your internal operations process.
Renewing your APNs certificate
Your MDM push certificate expires every year. Renewing it, rather than creating a new one, keeps your enrolled devices connected.
A new certificate has a different identity, so devices enrolled with the old one stop receiving pushes and would need to be enrolled again. Always choose Renew on the existing certificate.
1Set a reminder 30 days before expiryPhase 1
Open Apple connections in AAMDM and note the expiry date of the APNs certificate. Put a reminder in a shared calendar 30 days earlier, owned by a team and not by one person.
Workspace → Settings → Apple connections APNs certificate → Expires on → add reminder (30 days before)
2Find the Apple Account that created itPhase 1
The renewal must be done with the same Apple Account that created the certificate. Check your internal records. Use an account controlled by your organization, not a personal one that could leave with an employee.
3Download a request and renew at identity.apple.comPhase 1
In AAMDM, download a new certificate signing request from the APNs certificate. Sign in at identity.apple.com with the same Apple Account, find the existing certificate and choose Renew. Upload the request, then download the renewed certificate.
4Upload the renewed certificate to AAMDMPhase 1
Back in Apple connections, upload the renewed certificate to the APNs connection. Confirm that the new expiry date is about a year away.
APNs certificate → Upload renewed certificate Status: Active · Expires: one year from renewal
5Check with a test devicePhase 1
Send a harmless command, such as a device information request, to a test device and confirm that it checks in. Record the renewal and the next reminder date.
Removing a device when an employee leaves
A short checklist for taking a company device out of an employee’s hands and, where needed, preparing it for someone else.
Send any lock or erase command while the device is still enrolled. Once a device is unenrolled, AAMDM can no longer send it commands. Remote lock is a Phase 1 command in development; erase is planned and not yet scheduled.
1Lock the device if neededPhase 1
If the device has not been returned, send a remote lock so it cannot be used. This applies to company-owned devices only.
2Remove the device from groupsPhase 2
Take the device out of the groups that assign apps and policies to the employee’s team, so that nothing is pushed to it afterward.
3Erase before it is reassignedPlanned
For a company-owned device that will go to someone else, erase it once it is back in your hands and before you unenroll it. Confirm that you have the right device first, because erase cannot be undone.
4Unenroll the devicePlanned
Unenrolling removes the management profile. Managed apps and the data inside them are removed with it. Personal content on a device the employee enrolled themselves is not touched.
5Release or reassign it in Apple Business ManagerPhase 2
For devices enrolled through Automated Device Enrollment, open Apple Business Manager and either release the device, if it is leaving your organization, or reassign it to the AAMDM service so that the next user enrolls it at setup.
6Review the audit logPhase 1
Each step above is recorded in the audit log with the administrator, the device and the time. Check the entries and keep them with your offboarding record.
Audit log → Filter: device serial Lock · Erase · Unenroll · each with actor and time
Deleting your organization’s data
How to take your data with you and have the rest deleted when you stop using AAMDM.
Deletion cannot be undone. Make sure the people who need the audit log and device history have received their export first.
1Export what you needPhase 1
Ask for an export of your device records and audit log while your contract is active. Until self-service export is released, write to contact@aamdm.com and we will provide it.
2Unenroll your devicesPhase 1
Remove the management profile from your devices, or follow the guide on removing a device, so that they stop contacting AAMDM and are not left half-managed.
3Disconnect your Apple connectionsPhase 2
You control your Apple side. Revoke the APNs certificate at identity.apple.com, and in Apple Business Manager remove the AAMDM server or reassign the devices to another service.
4Request deletionPhase 1
Send a written request from an administrator to contact@aamdm.com. We confirm the request, delete the workspace and confirm in writing once it is done.
5What is deleted, and whenPhase 1
Account data and device records are deleted within 30 days after your contract ends or the request is confirmed. Backups age out on a rolling cycle. Invoices and payment records are kept for as long as accounting and tax law require. The full list is on the Subprocessors & Data Retention page.
6What happens to the audit logPhase 1
Your workspace’s audit log is deleted together with the rest of the workspace, so export it first. We keep only a minimal record that the deletion was requested and completed, with the date, and no device data.