Skip to main content

VPP and ADE Preferences

What

FileWave supportsCentral bothuses Apple'sPreferences > VPP & ADE to configure and monitor Apple Apps and Books tokens, Automated Device Enrollment accounts, and the Apple School Manager or Apple Business Manager API integration.

Apple now calls the Volume Purchase Program (VPP)Apps and AutomatedBooks. DeviceFileWave Enrollment (ADE) which was formally calledretains the VPP abbreviation in parts of the interface and documentation. Apple's Device Enrollment Program (DEP) is now Automated Device Enrollment (ADE).

In order to get these working within FileWave,

Before you willbegin

need
toSet configure certain preferences. This section just discussesup the settingsrequired requiredlocations, MDM Servers, and API credentials in Apple Business Manager or Apple School Manager. Use a separate Apps and Books token for each production, test, or migration MDM Server. Do not use the same token on multiple MDM Servers at the same time. Doing so can cause ownership conflicts, lost control of the token, or unexpected VPP user retirement. Have the primary FileWave administrator credentials available. FileWave may require fwadmin authentication when changing tokens, accounts, or certificates.

Apple's current platform instructions are available in the Preferences.

Note: Instructions for joining and working with the Apple VPP and ADE programs from the Apple side are outlined in detail on these web sites:
Business Manager User Guide
 and Apple School Manager User Guide
Deployment.

Reference

Open Guide - iPhoneVPP & iPad
DeploymentADE ReferencePreferences

Guide
    Open FileWave Central. Select FileWave Central > Preferences. Select VPP & ADE. Use Status for Machealth and synchronization information. Use Configuration to change tokens, accounts, certificates, API credentials, and advanced behavior.

    FileWave Central 16.4 VPP and ADE Configuration tab

    FileWave 16.4 separates VPP and ADE health information from configuration tasks.

    Status

    The Warning:Status Alltab provides a quick operational view without exposing detailed account configuration.

    Sanitized FileWave Central 16.4 VPP and ADE Status tab

    The Status tab shows token and account health, synchronization controls, and the most recent synchronization times. Example counts and timestamps are shown.

    Apps and Books status

      Displays the number of configured Apps and Books tokens. Shows the configurationmost stepsrecent VPP Web service synchronization. Synchronize requests an incremental synchronization. Hold Option on macOS while selecting Synchronize to request a full synchronization. Full synchronization is more expensive and should be used only when needed.

      Automated Device Enrollment status

        Shows ADE account health and the number of configured accounts. Shows the last successful Device Assignment Services synchronization. Synchronize requests an ADE synchronization with Apple.

        FileWave synchronizes Apple account data in thisthe sectionbackground. mustUse bea donemanual whilesynchronization signedwhen inrecent aspurchases, fwadmin.
        token changes, or device assignments cannot wait for the next scheduled synchronization.

        Configuration

        Volume Purchase Program—Apps and Books

        Select Configure tokens to add, renew, remove, or inspect Apps and Books tokens. FileWave supports multiple tokenslocation-based tokens.

          In Apple School Manager or Apple Business Manager, download the Apps and Books token for the VPPrequired service.location. This allows you to create multiple purchase authorities for your institution's App Store content. Content is automatically synchronized every 24 hours with the Apple VPP service. You may force a full synchronization when you are deploying a large number of App Store items, or any time that a delay may interfere with operational needs by holding down the Option key and clicking on the Synchronize button.

          Volume Purchase Program preferences

          This pane contains the information for your VPP account with Apple.

          In orderFileWave toCentral, proceed, you will have to have created a VPP for Education or VPP for Business account with Apple. Once you have a VPP account, you can download your VPP token for inclusion into FileWave. You may add as many tokens as you have purchasing agents.

          Configure VPP token(s)

          Select theselect Configure Accountstokens.

          buttonAdd (1or inreplace the graphicapplicable ontoken and save the nextconfiguration. page). You will haveReturn to authenticate as the primary FileWave Admin (fwadmin).

          Adding a VPP service token

          Click on the [+]Status button (2) and importsynchronize.

          your downloaded VPP token (3). When you import the token into this pane, you will see a long alphanumeric hash as shown. Continue these actions until you have added all of the VPP tokens you plan to use for content distribution.

          qTrH0PnEDRr4rmhI-embedded-image-g54h9i4a.png

          Note: Make sure you are not using a given VPP token on more than one MDM server. Problems, such as loss of control of the token or automatic VPP user retirement, can result.

          Once the token has been properly imported, you will see a dialog pop up telling you that everything is in order.
          If you want more than the FileWave superuser/admin account (fwadmin) to be able to manage VPP applications later on, you will need to use the /Assistants/ Manage Administrators… pane to assign other administrators to manage the VPP token(s). This is covered at the end of this chapter.

          Auto-create Filesets

          The first time you set up VPP, you will get Filesets automatically created for each of your existing VPP purchases. You can assign those Filesets to a designated FileWave Group for management. The default is the (Root) Group. 

          VPP account protection (aka "Take ownership")

          One of the new features in FileWave v10 is protection of the VPP accounts and tokens that you use with your server. The concept is very simple: an identifier (called "client context") is sent to Apple for a given VPP account. When an MDM server has to use a VPP account, it will query this identifier and compare with its own; if they match, everything is fine. If they don't match, the server should not use the token.

          As long as you are the confirmed owner of the token, the Is Owner flag says Yes;. If you have changed servers, or let another process, such as Apple Configurator, use that VPP token, then you will get an alert stating

          Confirm that the token is owned by another server.

          If you have a mismatch, your VPP token entry will turn red,healthy and youthat willpurchased notapplications beand ablebooks are available to useFileWave.

          that token. Your first indication of an issue may be an alert in your Dashboard:

          In order to regain control ofAfter the token,initial yousynchronization, willFileWave needcreates managed-license Filesets for eligible purchases according to select the token entryconfiguration. andToken-specific clickoptions oncan thealso Take ownership button in the lower right corner of the VPP tokens pane. Once you have done that, you will get a confirmation dialog:

          K1fXHI7WpDkY0YO5-embedded-image-ejqg6hyy.png


          The key to this process is making sure you do not apply any of your VPP tokens to a different server, tool, or application. If you are running a test/beta FileWave server or Apple Configurator, you should create a unique VPP account and token for that purpose.

          Createcontrol VPP users for newly enrolled devices

          Backand inwhere theautomatically Volumecreated Purchase Program pane, you can elect to Create VPP users for newly enrolled devices. VPP usersFilesets are internally created accounts that link your enrolled device to the FileWave VPP management process. It's not an actual "user" account; but more of a placeholder for the assignment of VPP apps and books. Each VPP user account may contain a link to an actual end user's Apple ID.

          ddSthrPKDI9V778u-embedded-image-puxcasia.png


          If this checkbox is selected, then newly enrolled devices will automatically get a VPP user and that user account will be associated with the device. This can speed up mass deployments, as well as reduce the overhead on 1:1/BYOD deployments. Used in conjunction with settings in the VPP Assistant, your FileWave server can then automatically notify new user's to register their Apple ID with your FW MDM server. You can select a single VPP token to be the primary token related to those VPP users. Also, you can change which tokens are associated with specific VPP users as you need.placed.

          Note:Never import the same Apps and Books token into two active MDM Servers. If youFileWave arereports that another server owns the token, use Take ownership only when the token has intentionally moved and the previous server or tool is no longer using VPP device assignment for application distribution (versus assignment by user - Apple ID), a "ghost" or invisible VPP user account is created. This account is not visible within the VPP User Management pane.it.

          Synchronization

          The VPP Synchronization setting lets you determine how often the FW MDM server will match data with your assigned VPP token account. You can push an incremental synchronization by clicking on the Synchronize button;

          Apps and youBooks canadvanced forcesettings

          a full synchronization by holding down the

          Select OptionShow Advanced Settings keyto while pressing the Synchronize now button.configure:

          Configuring

            The VPP email invitation templatetemplate. The minimum delay between license assignment and application installation. The preferred license distribution model for new associations: Automatic, Device, or User. Automatic assignment uses Device when possible and otherwise uses User. VPP v2 notifications. LDAP synchronization, automatic email-address association, and invitation behavior for registered users.

            Automated Device Enrollment

            ThisThe templateADE willconfiguration connects FileWave to one or more MDM Server entries in Apple School Manager or Apple Business Manager.

              Select Download certificate and authenticate when prompted. In Apple School Manager or Apple Business Manager, create or open the FileWave MDM Server entry and upload the certificate. Download the resulting ADE server token from Apple. In FileWave Central, select Configure accounts and import the token. Save the configuration, return to Status, and synchronize.

              Select Show Advanced Settings to choose the MDM certificate added to ADE profiles. Using an MDM certificate provides a more secure setup but requires ADE profiles to be usedupdated bywhen that certificate is renewed.

              For complete token lifecycle instructions, see Add or Renewing your ADE (DEP) Account Token.

              Apple School or Business Manager API

              FileWave server16.4 tocan sendconnect an invite to users enrolling in your MDM from iOS devices and macOS computers. If you have configured your setup to use LDAP authentication for enrollment, then your users will get an email addressed to the mail account in their LDAP record. It will contain a custom URL pointing themdirectly to the Apple AppSchool StoreManager where they will authenticate with theiror Apple IDBusiness Manager API. This integration provides current Apple device inventory, ADE assignment history, and AppleCare coverage information in FileWave.

                Create the required API credentials in Apple School Manager or Apple Business Manager. Download the API private key and associated metadata. Place the .p8 key and its metadata in a single ZIP archive. In FileWave Central, select Configure under Apple School or Business Manager API and upload the ZIP archive. Save the configuration and allow the initial synchronization to registercomplete. that ID with your FileWave MDM.

                lSANZG2GidN1afCk-embedded-image-6ojor5hd.png

                Minimum delay and Preferred Distribution

                Starting with FileWave v10, you have the ability to establish a delay between the time you associate a VPP application with a license and when the application is made available to install at the client. This avoids issues during large scale deployments where clients are trying to install VPP applications; but haven't gotten their license assignment yet.

                PreferredAppleCare Distribution allows you to choose the method of deploying a VPP application. The original method has been to assign an application to a registered Apple ID (User). The license shows up in the user's Purchases, and the licensesynchronization can betake managed by the FileWave MDM. The new method, supported in iOS 9+ and OS X v10.11+, allows you to assign VPP applications directly to an enrolled device (provided the app developer has coded the app to support this). This method applies only to VPP applications - iBooks are still required to be assigned to individual Apple IDs.

                ka0CnBXHm1DnHuZE-embedded-image-klcvixwc.png



                The default setting can be overwrittentime for a givenlarge associationfleet. ofApple's acoverage managedservice licensesupports Fileset.
                single-device lookups and is subject to undocumented rate limits.

                AppleCare refresh intervals

                Select Show Advanced Settings under the API section to configure separate refresh intervals for renewable, active, and inactive AppleCare coverage. Shorter intervals keep coverage data more current but increase API load and can trigger throttling. Select Reset to Defaults to restore FileWave's standard intervals.

                mBVtmHcVyRbMlRS8-embedded-image-hqn0qe3v.pngFileWave Central 16.4 VPP and ADE advanced settings

                UsingAdvanced LDAPSettings synchronizationcentralizes allowsApps youand toBooks linkbehavior, yourthe LDAPADE usersprofile certificate, and AppleCare refresh intervals. Values shown are examples from the supplied 16.4 interface.

                  Apple’s Volume Purchase Plan and License Management VPP Notifications (Apple VPP API v2) VPP Token Renewal Working with VPPApple’s users, who can then be associated with their email addresses (if those exist in the LDAP directory). This allows you to have VPP/MDM emails automatically sent to those users. This process can be left off if you are going to use device assignment of all your distributed VPP applications.

                  i8laQNZwE0TXtkw8-embedded-image-fpe7opc1.png

                  Device Enrollment Program preferences

                  Apple'sAutomated Device Enrollment Program(ADE)

                  isAdd designedor toRenewing support OTA (over the air - Wi-Fi) supervision of devices. FileWave supports iOS devices and macOS computers using ADE. Institutionally purchased devices are registered with Apple, and Apple provides ayour ADE token(DEP) forAccount youToken to link your FileWave MDM server to the ADE service.Troubleshooting When a device comes up online, it is recognized by the Apple ADE service, matched to the downloaded token, and automatically configured for supervised management with your FileWave MDM. The preferences you set to get this process up and running are shown below.

                  skKOchmQtvsQTLvo-embedded-image-5i80uakz.png


                  Using the "Download certificate" button, download a special "FileWave ADE" certificate to your administrator machine. You will be required to authenticate with the fwadmin FileWave Admin account. Use that certificate to get a ADE token from the Apple ADE site (https://deploy.apple.com or https://school.apple.com).
                  Select the "Configure accounts" button, and authenticate using the primary fwadmin account. You'll be presented with the option of uploading new tokens. You can have a token for each of the ADE facilitators you have.

                  kBNyoOjme7WAt5yj-embedded-image-0weoeeen.png


                  shWfsT3Oa7mZk5MR-embedded-image-jsfersr9.png


                  The Synchronize button works the same as the VPP synchronize button. ADE will synchronize between Apple and your FileWave Server once a day. You can hold the alt/option key down to force a full, immediate synchronization. Use that sparingly, since it may take a long time to synchronize with lots of devices in the system.

                  vT3aPHoQE1kEa2H3-embedded-image-vv8s4edb.png