Lesson 7: Mobile Device Management (MDM)

Jamf 100 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Explore how Apple's MDM framework functions and how it can enable management for devices with Jamf Pro.

Video

Key points

  • Mobile Device Management (MDM) allows organizations to remotely configure, secure, and deploy content to Apple devices.

  • Jamf Pro communicates with enrolled devices via Apple Push Notification service (APNs) through the following process:

    1. Jamf Pro contacts APNs.

    2. APNs notifies devices available online.

    3. Alerted devices contact Jamf Pro for management updates.

    4. Devices notify APNs of success.

    5. APNs notifies Jamf Pro of success.

  • Declarative device management is an evolution of Apple's MDM protocol allowing for improved stability and speed of management.

  • A push certificate is required for MDM communication.

    • This certificate must be renewed yearly with the same Apple ID, so creating an organizational Apple ID is recommended.

  • Both the Jamf Pro server and enrolled devices must be able to communicate with APNs over a network for MDM commands to be sent and received.

  • Much of Jamf Pro functionality leverages MDM communication, including:

    • Remote commands

    • Configuration profiles

    • App deployment

Review

To view answers, click arrow next to each question.

  1. APNs stands for Apple Push Notification service and is responsible for facilitating communication between an MDM provider like Jamf Pro and the devices which that MDM provider manages. Without a connection to APNs, Jamf Pro cannot send MDM commands to enrolled devices for management.
  2. A push certificate for APNs must be renewed yearly.
  3. A push certificate must be renewed with the same Apple ID that was used to create the certificate.
  4. Jamf Pro uses MDM to communicate with enrolled devices for management, including sending one-time remote commands, applying restrictions and other settings, and deploying volume-licensed apps.

Practice

  1. Locate an existing push certificate in your Jamf Pro server.

    1. Navigate to Settings > Global > Push certificates.

    2. Identify the Apple ID that was used to create the push certificate.

    3. Note the expiration date of the push certificate.

Resources

Jamf 100 Course

Jamf Pro Documentation

Jamf Technical Articles

Apple Platform Deployment

Apple