Enroll Apple devices
Prepare the Apple management identities, distribute the right enrollment artifact, and verify device reporting.
On this page
Apple enrollment connects a Mac, iPhone, or iPad to its management authority. Beam's native management path uses your workspace's Fleet engine. The separate Beam response channel uses NanoMDM and needs its own enrollment.
Before you enroll
Your operator must configure Apple MDM in Fleet, including an Apple Push Notification service (APNs) certificate and the engine's SCEP identity. For automated company-device enrollment, Apple Business Manager is configured in the engine. Track certificate ownership and renewal dates outside Beam; automatic renewal alerts are not provided.
Use the platform readiness shown in Enrollment & installers as a configuration check. Validate actual delivery on a test device before distributing profiles broadly.
Download and enroll
Configure or renew the push certificate
When the connected service exposes platform setup, owners and administrators can complete the certificate flow directly under Enrollment & installers → Apple enrollment:
- Choose Download Apple certificate request.
- Open the linked Apple Push Certificates Portal and use the Apple account responsible for your organization's management certificate.
- Complete Apple's certificate-issuance flow, then upload the returned
.pemcertificate with Upload Apple certificate. Upload the certificate only; enrollment keys stay on the server. - Check the displayed certificate identity, expiration date, and days remaining. For renewal, use the same Apple account and Renew Apple certificate for the existing certificate.
Certificate setup still requires Apple account access and Apple's issuance process. An expiry indicator is not an automatic renewal service or a notification system. If these controls are unavailable, have your deployment operator verify the configured platform service before continuing.
Install the profile and desktop agent
- Open Device management → Enrollment & installers with an authorized operator account.
- Verify the workspace shown on the setup page.
- Download the Apple enrollment profile when available and deliver it through your approved private channel.
- On the test Apple device, follow the operating system's profile-installation prompts and review the management permissions.
- For a Mac requiring the desktop inventory agent, use the workspace's signed, notarized installer.
- Return to inventory and compare the device identity, enrollment status, OS version, and check-in time with the endpoint.
The enrollment profile is not a single-use invitation. Keep copies and links limited to the intended device operators. A desktop inventory agent alone does not establish Apple MDM enrollment.
Keep the management authority clear
For Beam response, verify the NanoMDM device-channel ID against the Fleet inventory record. iPhone and iPad erase actions require enrollment with erase rights; User Enrollment is not the equivalent of device enrollment.
Maintain enrollment
Renew the existing APNs certificate using the responsible account. Replacing identities instead of renewing them can interrupt management and require re-enrollment. Preserve certificate, SCEP, and engine encryption material under the deployment backup policy.
If the device is missing or remains unenrolled, check engine configuration, certificate validity, network reachability, and the device's installed management profile. Do not use a lock or wipe request as an enrollment test.