Apple ADE Enrollment
Enroll one approved device through ADE
Apple Automated Device Enrollment (ADE, formerly DEP) applies an organization's setup choices when an eligible device activates and enrolls with Apple MDM. It is separate from installing the native FileWave Client on a Mac. Your goal here is one correctly identified MDM-enrolled test device, plus native Client check-in if your Mac evaluation needs file delivery.
Before you start
- Finish the APNs and ADE portions of Apple Client Pre-Requisites. Apps and Books is not required solely to enroll.
- In Apple School Manager or Apple Business, confirm the approved serial is assigned to the intended FileWave management service. In Central Assistants > ADE Association Management, synchronize and locate that same serial.
- Use an authorized spare device. Confirm backup, recovery ownership, network access, and any Activation Lock requirements before an erase. Erasing removes data. If the device is already managed elsewhere, get an owner-approved migration plan before reassigning it or removing its profile for this test.
- Review existing group membership, default Deployments, and automatic admission with the Server owner. A single new device can inherit existing work; a test name alone does not isolate it.
If the device is not eligible for this route, use Apple Manual Enrollment. Apple Configurator can add eligible Macs, subject to Apple's hardware requirements.
1. Create a profile without changing fleet defaults
- Open Assistants > ADE Association Management in FileWave Central and select + under Profiles. Give the profile an unmistakable evaluation name.
- Review the Information details and the management choices under Options. Agree with the device owner on whether to enforce enrollment and whether to allow removal of the MDM profile. Making the profile non-removable affects cleanup; do not choose that setting based on a screenshot without the device owner's approval.
- Review Setup Assistant rather than skipping every pane. Keep the network and account steps needed to finish setup. On a Mac, ensure a documented administrator/account-creation route remains available. Leave managed-account creation, Shared iPad, naming templates, migration customization, and Activation Lock changes out of this first test unless they are the explicitly approved purpose of the test.
- Inspect certificate settings and save the profile. Do not substitute arbitrary trust certificates or copy values from examples. The optional tab explanations below describe their purpose; they are not a universal checkbox preset.
Stop if you cannot explain a selected setting or the recovery path. Ask the enrollment owner to approve the profile for the chosen OS and hardware before activating the device.
2. Assign only the test serial
Drag the evaluation profile onto the one test device, or drag that device onto the profile. Check the association shows the intended serial and profile, then use Synchronize to send the profile assignment to Apple. Confirm the assignment reaches Apple before activation; see the FileWave migration procedure for related synchronization guidance. Do not configure a Default ADE Profile or apply broad assignment rules for this first enrollment.
The Profile Status column is useful assignment evidence. It is not sufficient proof that a device completed Setup Assistant, received every setting, or installed the native Client. Keep the device-side and Server checks below separate. ADE synchronization and profile assignment alone do not require a Model Update.
3. Mac only: prepare the native Client if needed
Skip this section for iPhone/iPad and for a deliberately MDM-only Mac test. For file-level Mac delivery, prepare the package before MDM enrollment:
- With Server and Central 16.4.0 or later, connect to the intended Server. Open Preferences > Enrollment > macOS in Central 16.4.1+, or Preferences > Mobile > macOS in 16.4.0.
- Select Show settings and check the Server, Client naming, routing/Boosters, and remote-connection settings. Do not overwrite existing fleet package settings casually. A Booster is optional for this evaluation.
- Select Build macOS client package. In 16.4.1+, review its separate configuration dialog; in 16.4.0, review the platform-pane settings before building.
- Wait for Ready for Enrollment and verify the displayed version. Keep Install for initial enrollment only enabled for the normal route. The generated package is already stored for enrollment; do not download and re-upload it.
For Servers earlier than 16.4.0, use the earlier-Server build and upload steps below and custom installer guidance. Changing or uploading a package with initial-only protection disabled can affect existing MDM-enrolled Macs. Enrollment packages are not the normal upgrade path for existing Clients; use Upgrading FileWave Clients.
4. Activate and observe the device
On a new test device, or one erased with explicit approval, connect to the intended network and continue Setup Assistant. Review the Remote Management organization and complete the approved enrollment authentication, if required. Stop on an unexpected organization, certificate, or credential prompt. Do not disable an organization's identity policy merely to continue.
Finish setup. On the device, inspect the installed management profile and its organization. On a Mac, inspect Device Management in System Settings (use the OS-specific profile location on older releases). On iPhone/iPad, inspect Settings > General > VPN & Device Management. A Remote Management screen is an intermediate step; it is not the final success check.

The macOS Remote Management screen shown uses an older interface. Confirm that the organization on your device matches the approved enrollment, not the example shown.

On iPhone/iPad, follow the steps above using your approved enrollment settings; the interface may differ from this screenshot. After setup, check the installed management profile to confirm enrollment.
5. Admit the correct record and prove the connection
In Central, first look for the existing record. If it was automatically accepted, do not add a duplicate. Otherwise open New Client, match the serial/device identity, and select Add Clients from the applicable queue. Desktop Clients is the native Mac Client queue; Enrolled Mobile Devices is the documented iPhone/iPad enrollment queue. A Mac's MDM status and native Client arrival must be checked separately. If the expected queue/record is unclear, stop and have the enrollment owner resolve it instead of selecting a similarly named device. For FileWave 16.4.x, Vision Pro guidance confirms New Client > Enrolled Mobile Devices; check the installed visionOS profile and supported outcome separately. Have the owner confirm the tvOS admission and device-side checks before extending this exercise to Apple TV.
Manual Add Clients changes the model. Review pending work with the other administrators, then run Update Model. This commits shared pending model changes, not just your test. Update Server Model is a confirmation dialog, not a change preview. A higher model number proves the commit, not device completion; see How FileWave turns changes into device work.
Record the serial, installed MDM profile, matching Central record, and recent management information. On a Mac where you requested the native Client, also confirm its version and recent Client communication with the intended Server. Client Last Connect and inventory Last Connected describe different events; use their timestamps with the device-side evidence. Do not use Verify as a passive refresh—it can process installation, removal, and self-healing work.
If enrollment or Client check-in fails: First check the Apple assignment, account, and profile synchronization. Then check the enrollment hostname, certificate, APNs, and whether device profile approval is complete. For a Mac that needs the native Client, also check package readiness and Client check-in. Do not reset the device again or target more devices to troubleshoot.
Next outcome and cleanup
Continue to the iPhone/iPad app exercise or Mac file exercise. Keep this test serial isolated. Before removing enrollment, review dependent apps, profiles, data, and recovery access. Removing a non-removable ADE profile may require an authorized MDM/offboarding procedure or an erase; deleting a Central record or unassigning an ADE profile is not a universal cleanup procedure.
Existing-device migration is a separate project
Apple supports managed-service migration for eligible organization-owned ADE devices on iOS 26, iPadOS 26, and macOS 26 or later, with additional restrictions. Configurator-added devices must be past their provisional period, and Shared iPad is excluded. See Apple's migration requirements. This is not a promise that changing an Apple assignment migrates every device or preserves all data. Have both management owners validate FileWave readiness, profiles/apps, network continuity, licensing, and new recovery/Activation Lock information before setting a deadline. Do not erase an in-use device merely because this starter exercise uses Setup Assistant.
Review the ADE profile choices
An ADE profile controls enrollment and setup. It is not the same as a Profile Fileset that delivers settings after enrollment. Review the choices against the target OS and hardware rather than using one checkbox preset for every Apple device.
| Area | Decision for your evaluation |
|---|---|
| Information and Options | Identify your organization; decide whether enrollment must complete and whether the MDM profile can be removed. Record the authorized offboarding route before enforcing management. |
| Setup Assistant | Keep the account, network, accessibility, and other setup choices the test needs. Showing the Location Services pane does not by itself enable FileWave location tracking. |
| Account | For a Mac, retain a documented account-creation and administrator-access route. Create a managed administrator only when its access, credential handling, and recovery are part of the approved design. |
| Anchor Certs and Supervising Certs | Have the enrollment owner confirm the certificates required by the intended trust and Configurator workflow. These are not fields for arbitrary certificate imports. |
| Device Naming | A naming template can combine text and supported inventory or Custom Field variables. Choose values that identify the device without exposing personal information, and verify the resulting name. |
| Activation Lock | Agree who can recover the device and where recovery information is held before changing management behavior. |
FileWave 16.3.x adds do_not_use_profile_from_backup, which lets a restored device fetch its current ADE assignment rather than use the profile embedded in its backup. It also adds Age Based Safety Settings while retaining AdditionalPrivacySettings; do not assume the newer key replaces every older privacy setting.
FileWave 16.4.x includes Managed Migration Assistant controls in macOS ADE profiles, including account and file selection and handling of Security & Privacy settings. That Mac-to-Mac data-transfer feature is different from migration between MDM services. See ADE Profiles for an explanation of Managed Migration Assistant and its declarative device management (DDM) alternative. That reference uses Anywhere; follow this page's navigation when working in Central. Test selected accounts, files, settings, and app behavior on representative Macs before wider use.
Optional: automate ADE profile assignment
Manual assignment is enough for the first device. Default profiles and rules are useful later, once you can predict which devices will match and what setup they will receive. Review existing assignments and rules with their owner before applying a change.
Default profile
- Open Assistants > ADE Association Management > Edit Assignment Rules.
- Review the existing Default ADE Profile. Choose the intended profile only after approving the devices that will use it.
- Select OK, then Apply Assignment Rules. Use the required synchronization and review every affected serial; a full sync is a deliberate broader operation, not the one-device test's default.
Rule-based assignment
- In Edit Assignment Rules, select + and choose the intended ADE profile.
- Add the identifying inventory fields to Criteria. Review the devices returned under Fields, not only the wording of the rule.
- Select Save for the query and OK for the rule definition. Review all rules from top to bottom before Apply Assignment Rules and synchronization.
- Confirm the resulting assignments, then validate enrollment on an approved representative device before extending the rollout.
The first matching rule, evaluated from top to bottom, wins. Rules take precedence over the default profile; the default is used only when no rule matches and a default is set. Keep the original rule/default configuration so the owner can restore intended future assignments if the test changes them. Restoring a rule does not undo enrollment or settings already applied to a device.
Profile Status reports assignment state, not complete device success. Empty shows no assigned profile; Assigned records an assignment; Pushed is a profile-workflow state that still needs device verification. Removed concerns unassignment, not device unenrollment. Confirm Apple's assignment and the installed profile before drawing conclusions.

The assignment interface shown is from an earlier FileWave version. Follow the steps above and use your approved profile and device scope, not the values shown.

Use criteria approved for your devices rather than copying the illustrated rule. Review matching devices and rule order before applying changes, and follow the steps above if your interface differs.
Earlier Servers: build the Mac Client package externally
For FileWave Servers earlier than 16.4.0, use the Mac custom installer builder. This remains a separate route from Central's integrated builder; it is for a new Client installation, not an upgrade of an existing Client.
- Choose the intended Product Version and enter your FileWave Server's fully qualified domain name under Server Name. Review the release's platform requirements first.
- Review Sync Computer Name and any Client naming settings. With Sync Computer Name enabled, the Client reads the Mac hostname at startup. Use the organization's naming choice rather than a screenshot's example.
- Keep Server Port at 20015; the Client converts that setting to the appropriate connection port. Do not manually substitute 20017. Review certificate trust with the Server owner. A trusted CA-signed Server certificate does not require a separate self-signed certificate upload.
- Review Overwrite Configuration, location tracking, remote-control prompting, and Booster/routing settings. Do not overwrite an existing Mac's configuration without an approved migration plan. A Booster is optional; tracking and remote control are not enrollment requirements. The builder says Client Password is not used for 16.0.0+ Clients; do not use the older password description to infer how current remote connections are authorized. Leave other connection defaults unchanged unless FileWave directs otherwise for this release.
- Select Build, wait for the download, and extract the archive. Keep the customized PKG restricted to the people provisioning the approved devices.
For a Client-only installation, transfer the PKG securely and install it on the approved Mac with local administrator authorization. Then return to the admission and check-in steps above.
For MDM-assisted initial installation, prepare the package before enrollment: open Preferences > Mobile > macOS, select Upload macOS client package, authenticate when prompted, and choose the extracted PKG. Wait for upload confirmation, retain Use for initial enrollment only, and select OK to save Preferences. Clearing the initial-only setting can send newly uploaded packages to existing MDM-enrolled Macs. Upload readiness does not prove Client installation; verify check-in after enrollment.
For instructions specific to your FileWave version, see Build Custom FileWave Client and Booster Installers. For an existing Client, use Upgrading FileWave Clients.
No comments to display
No comments to display