iOS Devices - Intune

There is bookstack documentation for users 


Onboarding iOS Devices into Intune

All new iOS devices (iPhones & iPads) at PBR are bring onboarded to Intune

Step 1 - Onboarding Device to Apple Business Manager

In order to onboard an iOS device into Apple Business Manager you must first install the Apple Configurator App on your personal phone. This phone must be also connected to Wi-Fi (PBR Corporate Wi-Fi doesn't work with this process) so needs to be connected to Internet Wi-Fi. iOS version of your personal phone and the new PBR phone need to be similar, but not necessarily exactly the same (it worked for me with my personal iPhone on 18.01 and PBR iPhone on 17.7)

Apple Configurator App is available for the App Store, icon looks like image.png

# If the device has been reimaged or is new and not enrolled by phone supplier then you can start here

**If the device has been enrolled by phone supplier then you can start here

Step 2 - Onboarding Device to Intune

image.png

Step 3 - Configuring Device in Intune

Enrollment Profiles - These are assigned to devices as a part of the enrollment process above

AAD Groups and resultant configurations - These are assigned by adding device (or user) to the AAD group)

Make a group for wifi policy and add individual devices to it

Wifi policy is attached to a seperate AAD group, to avoid issues with devices in Kiosk mode losing network connectivity when changing policy's..  thiis way a device cabn be removed from its Kiosk Mode group, whislt enabling it to stay connected. I have expereinced issue where you can get locked out of a device if in kiosk mode that gets disconnected from wifi

Add Apps to Intune in Apple Business Manager

Log into Apple Business Manager at apple@pbr.org.au

Navigate to Apps & Books

image.png

In search bar at the top search for the app you want to add

image.png

select the app, assign to Puffing Billy Railway Board and enter quantity and click Get

 

Now go to Intune Tenant Admin | Connectors and Tokens 

image.png

 

On the line of apple@pbr.org.au go to far right and click on ... and select Sync

 

image.png

 

Once sync has completed navigate to  Apps | iOS/iPadOS apps, and the app will be displayed in the list and is now successfully added to Intune

image.png

Intune iOS Devices - FAQ

What to do if a device that is in Kiosk mode is unable to connect to the internet.

There is a PBR Wi-Fi Policy enabled in Intune that enables automatic connection to PBR Wi-Fi (Internet). If for some reason this Wi-Fi becomes unavailable whilst the device is in Kiosk mode then it is not possible to take the device out of Kiosk mode due to the fact the device needs to be connected to the internet to enable changes made in Intune to sync to the device.

A simple solution is to setup a hotspot from another phone, make the SSID internet and specify the same password as for the PBR internet Wi-Fi ..  then the device should be able to connect and changes in Intune can then be sync'd to the device

What to do if a device is successfully in Apple Business Manager and listed in Intune under Devices | Enrolment | Apple tab | Enrolment Program Tokens | Select Intune Token | Devices but event though it has a profile assigned when you erase and restart the device it doesn't enroll in Intune

Set up a new enrollment profile and set it as the default profile and assigned the iPad to it, synced the token, reset the iPad again and this time it booted up with the Intune OBE and enrolled into Intune. Then I reassigned it to the proper enrollment profile and wiped it via the Intune console. It rebooted and came back up with all of my custom configuration settings. Didn't even have to go through OBE this time. Beautiful!

 

You can tell if its on the Fix iPad profile by looking at the device name locxally on the device..  if its iPhone-Serialnumber   then its on the fix profile if its PBRB-iPhone-SerialNumber its on another profile

Kiosk Policy Notes

Always remove Kiosk policy before making changes to or adding or removing Wi-Fi policy

If you brick the iPad whilst in kiosk mode

Undertake a hard reset and restore - install iTunes on a windows device connect the iPad via cable to the computer, hold down the power and home button, keep holding once apple logo appears, wait for recovery screen. Then follow the prompts within iTunes.

Setup Better Impact iPad

Onboard the iPad into Intune by following this article https://bookstack.pbr.org.au/books/ios-devices-intune/page/onboarding-ios-devices-into-intune

Add the iPad to the following enrollment profile

Once you get to the home screen, the following settings need to be set manually -

Next step is to add the iPad to the Intune_iOS_Wifi Group. Its important to do this and ensure it is working before putting into Kiosk mode, as you can lock yourself out of the iPad. The best way to check the WiFi policy has been applied is go to Settings, Wi-Fi click on the connected wifi network 'internet' and see if the option to 'Forget This Network' is available . If this option is not available then the policy is applied.  I have finding doing a remote restart can speed up this process

If you set a passcode earlier in the setup process, now you need to remove it, Intune | Devices | select the device and click 'remove passcode'

Now you need to assign the device to the Intune_iPads_BI AAD group. This will enable Kiosk Mode and create the bookmarks for Safari

Once iPad is in Kiosk Mode, you just need to open the Better Impact bookmark within Safari and ensure its the only tab open

Make sure to update snipeit with the new hostname that has been assigned by Intune, it will be in the format of PBRB-iPad-<serial number>

and update the details of what the iPad is being used for and where it is located in Intune

Devices | Overview> iOS/iPadOS | iOS/iPadOS devices>

select the device and go to properties and enter details in the Notes section

image.png


Summary Of Applied Profiles & Policies for Better Impact iPads

Enrollment Profile
Compliancy Policy applied
Configuration Policies applied

Manual Configuration

Setup Employment Hero iPad

Onboard the iPad into Intune by following this article https://bookstack.pbr.org.au/books/ios-devices-intune/page/onboarding-ios-devices-into-intune

Add the iPad to the following enrollment profile

Once you get to the home screen, the following settings need to be set manually -

Next step is to add the iPad to the Intune_iOS_Wifi Group. Its important to do this and ensure it is working before putting into Kiosk mode, as you can lock yourself out of the iPad. The best way to check the WiFi policy has been applied is go to Settings, Wi-Fi click on the connected wifi network 'internet' and see if the option to 'Forget This Network' is available . If this option is not available then the policy is applied.

Now you need to remove the passcode set earlier, Intune | Devices | select the device and click 'remove passcode'

Now you need to assign the device to the Intune_iPads_EH AAD group. This will enable Kiosk Mode 

Once iPad is in Kiosk Mode, you just need to logon to Employment Hero 


Summary Of Applied Profiles & Policies for Employment Hero iPads

Enrollment Profile
Compliancy Policy applied

Apps Assigned

Configuration Policies applied

Manual Configuration 

Setup Survey Legend iPad

Onboard the iPad into Intune by following this article https://bookstack.pbr.org.au/books/ios-devices-intune/page/onboarding-ios-devices-into-intune

Add the iPad to the following enrollment profile

Now you need to remove the passcode set earlier, Intune | Devices | select the device and click 'remove passcode'

Now you need to assign the device to the Intune_iPads_SL AAD group. This will enable Kiosk Mode and create the bookmarks for Safari

Once iPad is in Kiosk Mode, you just need to configure Kiosk Pro Lite to -  (this can all be done from app when in full kiosk mode)



Summary Of Applied Profiles & Policies for Survey Legend iPads

Enrollment Profile
Compliancy Policy applied

Apps Assigned

Configuration Policies applied

Manual Configuration

Migrating a User to a new iPhone from an existing iPhone (WIP)

Migrating a user with an existing PBR issued iPhone to a new PBR issued iPhone that is MDM enrolled

Step 1 - Backup Device

Use Apple Devices App from Microsoft Store to backup existing iPhone

Step 2 - Restore Backup on new Device

 

Device must be enrolled in Apple business manage and intune

When restore is complete the iPhone will restart. remove the cable from the computer when apple logo is displayed

Step 3 - Enrollment Process

Everything should come across, photo's contacts, settings, apps etc. 

Notes:

Renewing Apple Tokens in Intune

There are 3 Apple Tokens that need to be renewed in Intune

Refer https://c7solutions.com/2024/01/renewing-apple-tokens-in-intune for instructions

Apple MDM Push Certificate

This certificate expires ever 365 days and must be renewed prior, otherwise all iOS devices will need to be reenrolled. 
there's lots of documentation out there about how to do this, such as the below, the main things to remember is to log into Apple Push Certificates Portal with apple@pbr.org.au and to renew the existing certificate, rather than creating a new one
https://www.recastsoftware.com/resources/renewing-your-apple-mdm-certificate-for-intune/
https://learn.microsoft.com/en-us/mem/intune/enrollment/apple-mdm-push-certificate-get


Apple Business Manager Enrolment Program Token (DEP)

This token expires ever 365 days and must be renewed prior

In Apple Business Manager, on the LHS click on IT - Puffing Billy Railway and select Preferences

Scroll to the bottom and Select Intune under Your MDM Servers

Then select Download MDM Server Token

image.png

In Intune navigate to Devices | Overview > iOS/iPadOS | Enrollment > Enrollment Program Tokens

image.png

Click on Renew Token

Apple ID apple@pbr.org.au

Select the token you downloaded from Apple Business Manager

The expiry date should now updated and the token renewed

Apple VPP Token
There is a recurring ticket in helpdesk for this to be done
In Apple Business Manager, download content token

image.png

in Intune

 Tenant Administration > Connectors and Tokens > Apple VPP Tokens

select the token, and click edit next to basics

image.png

Browse to the token file you downloaded

image.png