Cortado Support

My Tickets Visit www.cortado.com
Welcome
Login

Embedding company-owned iOS/iPadOS devices (COBO/COPE)

Connect Cortado with Apple Business Manager (ABM)

Create configuration profile in the administration portal

Configure devices

Connect Cortado with Apple Business Manager (ABM)

The fastest way to enroll company-owned iOS/iPadOS devices is with Automated Device Enrollment (ADE). Using ADE, you can configure a large number of iOS devices remotely without picking them up.

Prerequisite: You have registered your company and all iOS/iPad devices in Apple Business Manager. You can find further instructions here.

Once all the serial numbers of the iOS/iPadOS devices have been loaded into Apple Business Manager, you can start the configuration. For this, Cortado´s administration portal must firstly be connected to the Apple Business Manager.

Note! Create up to four additional administrator accounts to configure Cortado MDM.
  • In the administration portal open Administration→ Settings.
  • In the Apple Automated Device Enrollment tab under ADE Certificate,you have the following options (right column):
  • Download: Download the ADE certificate here. This is a Cortado gener­ated certificate.
  • Renew: You can generate a new ADE certificate here, if necessary (for example, if the old one expires).
Note! When you renew an expired ADE certificate, the token of the certificate must also be renewed. To do this, proceed as described in our help article How to renew the token of an ADE profile for iOS devices.
  • Import: If required, you can import a previously generated certificate here.

a screenshot of the apple appliance certificate.

  • The ADE certificate downloaded in the last step (arrow in upper picture), has to be uploaded to Apple in the next step.
  • For this purpose, open the Apple Business Manager under https://business.apple.com/ and log in with your Apple ID.
  • Then click in your profile (left arrow in illus.) under Preferences on MDM Server Assignment(middle arrow in illus.).

    Then select Add MDM Server (right arrow in illus.).

a screenshot of a web page with the mdm server assignment highlighted.

  • Under MDM Server Info enter a name of your choice (e.g.: department, location, user groupe) (upper arrow in illus.).

Note! At this point, you need to add a separate MDM server for each ADE profile you want to add, since a separate server token is needed for each profile.

  • Under MDM Server Settings→ Choose File (lower arrow in illus.) select the ADE certificate, that you down­loaded in the administration portal under Settings→ ADE→ Download.
  • Then save the settings by clicking Save.

a screenshot of a web page with the mdm server highlighted.

  • Download your Token now (arrow in illus.). You must load this token into the ADE profile later in the administration portal.

a screen shot of a cell phone description.

  • Then, under Device (left arrow in illus.) select the devices, you want to assign (middle arrow in illus.).
  • After this, click on Edit MDM Server (right arrow in illus.).

a screenshot of a cell phone description.

  • Under Assign to the following MDM (arrow in illus.) select your MDM ser­ver (or your ADE profile).
  • Confirm by clicking on Continue.

a screenshot of a cell phone description.

Create configuration profile in the administration portal

  • In the Cortado administration portal select Settings→ ADE→ Add (arrow in illus.).

a screenshot of the apple appliance certificate.

Configure the ADE profile as follows:

a screenshot of the advanced device settings page.

  • Mandatory: Specify here whether the use of the profile should be mandatory for the users. If the checkbox is left empty, the users can choose whether to install the ADE profile or to create a profile of their own.
  • Verify profile: If this checkbox is enabled, the device configuration can only be completed if all steps required in the Cortado administration portal have been carried out.
  • Supervised: Currently, all devices that receive this profile are placed into supervised mode. This is regardless whether this checkbox is crossed or not.
  • Enable pairing: If this checkbox is enabled, the user may connect his device to a Mac or a PC and connect to iTunes.
  • Shared iPad: Activate this checkbox if an iPad should be used by multiple users. This allows different user profiles to be set up on one iPad. You can find more information on the Apple page.
  • Upload token: Select the Select token button and upload the Token from the Apple Business Manager (arrow in illus.).
  • Device setup steps: You can specify what steps the user is allowed to make during setup of the device itself. 

Click on OK to finish configuration.

Configure devices

Users now only have to switch on the devices. The newly created ADE profile will now be automatically used for the device configuration (left illus.). Provided that the devices are new and unused or have been reset to factory settings.

remote management iPhone

The user has to enter his/her username and password during the configuration, therefore users must have been imported into the administration portal before configuration.

  • Cortado MDM with Microsoft Entra ID groups: Microsoft users use their Microsoft login (lower arrow in left illus. and right illus.).
  • Cortado MDM with local users: Local users must create a password for login (upper arrow in left illus.) using the invitation email and their email address. Alternatively, you can assign a password for the user during user import.

login with local user (left) and with Microsoft user (right)

That means that, during the configuration, the user only needs to carry out the setup steps that you selected under Device setup steps.




Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.