Proudly Canadian flag Canadian

Solutions

Ready to optimize your mobile device strategy?

Speak with a mobility expert to find the right solution for your organization.

Contact us

Products

Ready to optimize your mobile device strategy?

Speak with a mobility expert to find the right solution for your organization.

Contact us

Industries

Ready to optimize your mobile device strategy?

Speak with a mobility expert to find the right solution for your organization.

Contact us

Company

What is Apple DEP? Automated device enrollment explained for IT teams

Apple DEP, now officially called Automated Device Enrollment, is Apple’s mechanism for automatically enrolling company-owned iPhones, iPads, and Macs into your MDM platform the moment they power on. No manual setup steps, no QR codes, no enrollment URLs. The device connects to Wi-Fi, checks in with Apple’s servers, and enrolls itself.

If you’ve been manually walking through setup screens on every new Apple device before handing it to a user, Automated Device Enrollment eliminates that work entirely. More importantly, it unlocks supervised mode—which means users cannot remove your MDM profile, even after a factory reset. That distinction matters more than most IT teams realise until something goes wrong.

What Apple DEP actually is—and what Apple calls it now

You unbox 50 new iPads for a retail rollout. Without Automated Device Enrollment, each one needs to be manually walked through the setup assistant, connected to Wi-Fi, pointed at an MDM enrollment URL, and configured individually. With Automated Device Enrollment, those iPads connect to your MDM automatically the moment they power on—no manual steps, no user intervention required.

Apple originally offered this capability through a standalone web portal called the Device Enrollment Program (DEP). In December 2019, Apple retired the standalone DEP portal and consolidated all functionality into Apple Business Manager (ABM). The enrollment feature is now called Automated Device Enrollment.

The functionality is identical—only the name and portal changed.

As of 2024, Apple Business Manager supports Automated Device Enrollment for iPhone, iPad, Mac, Apple TV, and Apple Vision Pro. If your organisation uses any of these devices, the enrollment mechanism is the same across all of them.

Here’s what actually happens in practice: many IT teams still call it “DEP” internally even though Apple retired the name years ago. When you search for “Apple DEP” in your MDM console and find nothing, it’s because the platform has already updated its terminology to “Automated Device Enrollment.” Don’t panic—the functionality you’re looking for is there, just under a different label.

How Automated Device Enrollment works step by step

The enrollment chain starts before the device ever arrives at your office. It begins at the point of purchase—either directly from Apple or through an authorised reseller—when the device serial number is linked to your Apple Business Manager account.

This is not a configuration you apply after the fact. Devices must be purchased from Apple directly or an Apple Authorised Reseller to be eligible for Automated Device Enrollment. In Canada, this includes carriers like Bell, Rogers, and TELUS, as well as authorised business resellers.

One of the most common mistakes we see is purchasing Apple devices from an unauthorised channel—a general electronics retailer or a grey-market supplier—and then discovering those serial numbers cannot be added to Apple Business Manager. The devices work fine, but they cannot be automatically enrolled. You lose supervision and zero-touch deployment capability for the life of that hardware.

This is a procurement decision with security implications that most organisations don’t recognise until it’s too late.

The role of Apple Business Manager

Apple Business Manager (ABM) is the web portal where IT administrators manage device assignments, MDM server connections, and app licences (via Apps and Books, formerly VPP). Think of ABM as the control plane—not the MDM itself.

Your MDM platform (whether that’s SOTI, 42Gears, VMware Workspace ONE, Microsoft Intune, or another) connects to ABM via a server token. When you assign device serial numbers to that MDM server in ABM, those devices know where to enroll when they first power on.

ABM handles the “who manages this device” question. Your MDM handles everything that happens after.

What happens at first power-on

The user experience is remarkably simple—by design.

The device powers on and prompts the user to connect to a Wi-Fi network. Once connected, it checks in with Apple’s activation servers. Those servers recognise that the device’s serial number is assigned to an Apple Business Manager account and respond with the MDM enrollment profile.

The device automatically enrolls in the designated MDM platform. Configuration profiles, security policies, apps, and restrictions push down without the user doing anything beyond connecting to Wi-Fi. Depending on your configuration, certain setup screens (Apple ID creation, diagnostics opt-in, passcode setup) can be skipped entirely.

From the user’s perspective, they power on the device, connect to Wi-Fi, and minutes later they’re looking at a fully configured work device. From IT’s perspective, zero hands-on time was required.

Why Automated Device Enrollment matters for enterprise IT

Manual enrollment works when you’re setting up five devices. It becomes a full-time job when you’re deploying 500—and a security liability when any user can remove the MDM profile by resetting their device.

The single most important capability that Automated Device Enrollment unlocks is supervision. Supervision enables over 100 additional MDM commands and restrictions not available on unsupervised devices. For an IT Manager, this is the practical difference between “we can manage this device” and “we can fully control this device.”

Without supervision—which requires Automated Device Enrollment—a user who factory-resets their corporate iPhone effectively removes your organisation’s security policies, app configurations, and remote wipe capability in one tap. That device is now outside your MDM environment, and you have no mechanism to bring it back under management without physically handling it again.

Zero-touch deployment at scale

Automated Device Enrollment enables true zero-touch provisioning. Devices can be shipped directly from Apple or an authorised reseller to end users—across multiple provinces, in remote locations, wherever your workforce operates—without IT ever physically handling them.

For Canadian organisations with distributed workforces, this is transformative. A new hire in Vancouver receives their iPad the same day as a new hire in Halifax. Both devices enroll in MDM automatically. Both receive identical configurations. IT didn’t touch either one.

This also applies to device replacements. When a field worker’s iPhone breaks, the replacement ships directly to them. They power it on, connect to Wi-Fi, and they’re back to work—with all their apps, policies, and configurations already in place.

Supervised mode and the security controls it unlocks

Supervision is not a marketing term. It’s a specific technical state that Apple devices can be placed into only through Automated Device Enrollment (or Apple Configurator 2 for existing devices).

Supervised devices give IT access to controls that are simply unavailable otherwise:

  • Preventing users from removing the MDM profile
  • Restricting AirDrop to managed devices only
  • Enforcing always-on VPN
  • Silently installing or removing apps without user interaction
  • Enabling Lost Mode to locate and lock a missing device
  • Restricting which Wi-Fi networks the device can connect to

For organisations handling sensitive data—customer records, patient information, financial transactions—these controls are not optional. They’re the baseline expectation for a managed device.

The next question most IT teams ask is straightforward: what exactly do they lose if they skip Automated Device Enrollment and stick with manual enrollment methods?

Apple DEP vs. manual enrollment—what you lose without it

Manual enrollment is not broken. For a five-person office with a handful of iPads, it works. The gap becomes visible when devices number in the hundreds, when users are spread across multiple provinces, or when a lost device needs to be locked remotely and you discover the user already removed the MDM profile.

The comparison is not about convenience—it’s about what you can and cannot do with devices after they’re deployed.

Criteria Automated Device Enrollment Manual Enrollment
Setup effort per device Zero touch—device self-enrolls at first power-on IT must manually walk through setup or provide enrollment URL/QR code
Supervision capability Full supervision enabled automatically Not available—device remains unsupervised
MDM persistence after reset Device re-enrolls automatically after factory reset User can remove MDM profile permanently by resetting
Direct-to-user shipping Yes—devices ship from Apple/reseller directly to end users No—IT must handle each device before distribution
Silent app deployment Yes—apps install without user interaction Limited—user must approve many installations
Ongoing IT overhead Minimal after initial ABM configuration Ongoing manual enrollment work as fleet grows

The most important row in that table is MDM persistence. With Automated Device Enrollment, even if an employee factory-resets their corporate iPhone, the device checks back in with Apple’s servers during setup and re-enrolls in your MDM automatically. The employee cannot bypass this.

With manual enrollment, a factory reset removes the MDM profile entirely. That device is now outside your management environment. You cannot push policies, deploy apps, or remotely wipe it. IT only discovers the gap when something goes wrong—a compliance audit, a lost device, or a data breach investigation that reveals a “shadow fleet” of unmanaged hardware.

In practice, organisations that skip Automated Device Enrollment often accumulate these shadow devices over time. A user resets their phone to fix a glitch. Another user leaves the company and the device is reassigned without re-enrollment. A batch of devices was purchased from an unauthorised reseller and could never be enrolled properly in the first place. These gaps only surface during an audit—or a breach.

How Canadian organisations use Automated Device Enrollment with MDM

Automated Device Enrollment gets the device into your MDM. It does not manage the device after that.

The ongoing work—pushing security policies, deploying apps, monitoring compliance, responding to incidents—is the MDM platform’s job, and someone on your team needs to administer it. This is where the operational picture expands beyond Apple’s enrollment mechanism.

SOTI MobiControl and 42Gears SureMDM both support Apple Automated Device Enrollment natively, alongside Android zero-touch enrollment and Samsung Knox Mobile Enrollment. VMware Workspace ONE, Microsoft Intune, and Jamf all integrate with Apple Business Manager the same way—via a server token that links your ABM account to the MDM platform.

For most Canadian enterprises, the fleet is not Apple-only. You might have 300 iPhones for sales reps, 200 Zebra scanners in the warehouse, and 50 Honeywell handhelds in the field. Your MDM environment needs to handle all of them—different enrollment methods, different policy models, different app ecosystems—under a single administrative console.

The most common gap is not the enrollment itself—it’s what happens on Day 2. Automated Device Enrollment gets the device configured on day one, but policy drift, app version inconsistencies, and unenrolled devices accumulate over weeks and months. That ongoing administration is where most internal IT teams get stretched thin, especially when they’re also responsible for network infrastructure, security incidents, helpdesk tickets, and everything else on the job description.

For organisations subject to Canadian privacy regulations—PIPEDA federally, PHIPA in Ontario healthcare, Quebec Law 25 for private-sector data—the stakes of that drift are higher. If Apple devices in the fleet handle personal information, the organisation has obligations around how that data is protected and what happens if a device is lost. Supervised enrollment ensures MDM policies enforcing encryption and remote wipe cannot be removed by the user, directly supporting compliance posture. But only if someone is monitoring and maintaining those policies over time.

When managing Apple enrollment and MDM becomes too much to handle internally

For an IT Manager already juggling network infrastructure, security incidents, and helpdesk tickets, adding “MDM administrator for 300 iPhones and 200 Zebra scanners” to the job description is where things start to slip.

The work is not conceptually difficult. It’s just relentless. Policy updates need testing before deployment. App versions need consistency across the fleet. Devices fall out of compliance and need investigation. New hires need enrollment; departing employees need devices wiped. Apple releases a new iOS version and suddenly half your fleet is flagged for update enforcement. Meanwhile, the Zebra scanners run Android Enterprise, which has its own enrollment model and its own quirks.

Most organisations do not need a full-time MDM administrator. They need MDM to be administered full-time. The distinction matters.

This is exactly why some Canadian organisations hand MDM operations to a managed service provider rather than staffing it internally. PiiComm’s MDM as a Service (MDMaaS) model exists for this reason. PiiComm’s certified, Canada-based MDM administrators handle policy configuration, app deployment, compliance monitoring, and incident response across SOTI, 42Gears, and other platforms—including Apple Business Manager administration as part of the service.

For organisations running mixed fleets—Apple alongside Zebra, Honeywell, or Samsung rugged devices—the value is not just offloading Apple enrollment. It’s having a single team that understands how all these enrollment mechanisms fit together and can manage them under a unified operational model.

The 24/7 bilingual (English/French) service desk staffed in Canada also matters for federal government departments and Quebec-based organisations where support interactions may need to be delivered in both official languages—a capability US-based MDM services providers cannot deliver as standard.

Learn how managed MDM administration works →

Have a specific question about Apple enrollment, supervision, or MDM integration? Ask EMMA—PiiComm’s AI assistant trained on managed mobility operations.

Frequently asked questions

Is Apple DEP the same as Apple Business Manager?

Apple DEP is now part of Apple Business Manager (ABM). Apple retired the standalone DEP portal in 2019 and consolidated device enrollment, app distribution, and account management into ABM. The enrollment feature is called Automated Device Enrollment. The functionality is identical—only the name and portal changed.

Do I need Apple DEP to manage iPhones and iPads with MDM?

You can enrol Apple devices in MDM manually without Automated Device Enrollment, but you lose supervision. Supervised devices give IT over 100 additional controls—including preventing users from removing the MDM profile. For enterprise fleets, manual enrollment creates security gaps and does not scale.

Can I add existing Apple devices to Automated Device Enrollment?

Yes, using Apple Configurator 2 on a Mac. Each device must be physically connected via USB and added to your Apple Business Manager account. This works for existing inventory but requires hands-on access to every device—practical for a one-time catch-up, not an ongoing strategy.

What MDM platforms work with Apple Automated Device Enrollment?

Most enterprise MDM platforms support Automated Device Enrollment natively, including SOTI MobiControl, 42Gears SureMDM, VMware Workspace ONE, Microsoft Intune, and Jamf. The MDM platform connects to your Apple Business Manager account via a server token, and assigned devices enroll automatically at first power-on.

Does Automated Device Enrollment work for both corporate-owned and BYOD devices?

Automated Device Enrollment is for corporate-owned devices only. It places devices into supervised mode, giving IT full management control. For BYOD, Apple offers User Enrollment, which creates a managed partition on the device without giving IT access to personal data—a deliberate privacy boundary.

Do I have to manage Apple Business Manager and MDM enrollment myself?

You do not have to. Many Canadian organisations outsource MDM administration—including Apple Business Manager setup and ongoing enrollment—to a managed mobility services provider. This is especially common when IT teams manage mixed fleets of Apple and Android or rugged devices and lack dedicated MDM platform expertise.

What happens if a user factory-resets a device enrolled through Apple DEP?

The device re-enrols in your MDM automatically. Because Automated Device Enrollment links the device’s serial number to your Apple Business Manager account, a factory reset triggers re-enrollment during setup. The user cannot bypass this—one of the most important security advantages over manual enrollment.

The enrollment decision you’re actually making

Apple DEP—Automated Device Enrollment—is often treated as a technical checkbox. Configure ABM, link it to your MDM, move on.

But the choice to use or skip Automated Device Enrollment is really a decision about how much control you want over your Apple devices for their entire operational life. It determines whether a user can remove your security policies with a single reset. It determines whether IT needs to physically handle every device or can ship directly to distributed workers. It determines whether a lost iPhone can be locked and wiped—or whether it’s already outside your management environment by the time you discover it’s missing.

The enrollment mechanism itself is not the hard part. The hard part is everything that comes after: maintaining policies, managing app deployments, keeping devices in compliance, and responding when something goes wrong. That’s the operational question worth answering before the next batch of iPads arrives.