The Device Enrollment Program (DEP) provides a fast, streamlined way to deploy your corporate-owned Mac or iOS devices, whether purchased directly from Apple or through participating Apple Authorized Resellers.

First signup to Apple DEP at deploy.apple.com – this requires a new account with out an existent AppleID.


In the Intune console go to DEP enrollment

Intune console DEP.png

Download Encryption Key

DEP1

Save the key file

DEP2

Go to Deploy.apple.com

Select Get Started

DEP3

Select Add MDM Server

DEP4

Give the new MDM system a Name – If this is the only MDM system in DEP then select “Automatically Assign New Devices”

DEP5

Then you need to upload the Key file previous downloaded from the Intune Portal

DEP6

Select the downloaded file

DEP7

Select Next

DEP8

Download the “Server Token” you need to put into Intune to combine DEP and Intune

DEP9

Save for latter use

DEP10

Select Done – and now back to the Intune Portal

DEP11

Select “upload the DEP Token”

DEP12

Select Browse

DEP13

Browse for the previous downloaded file from Apple DEP portal

DEP14

Enter your AppleID that you used when downloaded the DEP token

Select Upload

DEP15

And now you have combined Intune with Apple DEP and are ready to create a default profile for DEP enrolled devices

DEP16


Go to Admin – Policy – Corporate Device Enrollment

Select Add

DEP20

Create a Default DEP enrollment Profile

  1. Give the profile a name
  2. Select a assignment group
  3. Set a Department name
  4. Set a Support number
  5. Select Supervised mode

Always use User affinity in my appinion – just remember that :

Many user affinity features require the Company Portal.

DEP21

Select the settings you need as part of the Assistant panes.

Just remember if you want to deploy IOS Apps with Apple VPP it is only possible to users and there for requires a AppleID on the device!!! 

DEP22

Then set the “Default DEP enrollment Profile” as default

DEP23

Just Confirm by selection Ok

DEP24


 

To test what you just have configured go back to deploy.apple.com find your Apple Device

  1. Find the Apple Device by Serial Number
  2. Assign a MDM Server
  3. Set the Name
  4. Select Ok

DEP25

Comfirm by select Ok

DEP26

Now you can see your first device on the DEP program

DEP30

When the DEP and Intune is syncing the next time you have the device in Intune.

The DEP sync is happing every 12 hours.

Now you have to reset your Apple Device – and use the Assistant panes on the device. Every thing you have disabled is not shown to the user.