Apple Client Pre-Requisites
Prepare only the Apple services your test needs
Choose one organization-approved test device and one management method before changing an Apple integration. A Mac can run the native FileWave Client, use Apple MDM, or use both. The Client performs file-level delivery and inventory work; Apple MDM installs management profiles and performs supported Apple management tasks. Installing the Client does not enroll a Mac in MDM.
| Your next task | Prepare now | Not required just for this task |
|---|---|---|
| Install the native Client on a Mac for a first file delivery | Correct Server connection, a supported Client PKG, local administrator approval | APNs, ADE, Apps and Books |
| Manually MDM-enroll an approved Mac, iPhone, or iPad | APNs certificate, trusted reachable enrollment URL, approved enrollment authentication | ADE assignment; Apps and Books unless delivering an App Store app |
| Enroll an organization-owned device through ADE | APNs plus the organization's Apple enrollment service and the exact test serial assigned to FileWave | Apps and Books unless delivering an App Store app |
| Deliver an Apps and Books app | Working Apple MDM enrollment, an approved Location token, the correct app/platform, and an available license | A second ADE setup if the device is already correctly enrolled |
Use the selected FileWave release's platform requirements rather than treating this table as an OS support matrix. Hosted customers do not perform Server shell work. FileWave Support or your assigned representative owns hosted-server authentication and service changes. Self-managed Server owners must confirm readiness using FileWave Server Setup.
Protect existing management first
Record the test serial, current MDM owner, and intended cleanup. Do not reassign a working device, replace an existing APNs certificate, take ownership of another MDM's token, or change default enrollment rules merely to make the evaluation proceed. Use an approved spare device and a separate Apps and Books Location/token when another MDM is already in use. Stop on an ownership conflict and involve that owner.
1. Establish the APNs identity for Apple MDM
APNs lets FileWave notify Apple devices that management work is available. It is not the native Mac Client installer. Before creating anything, check whether this Server already has a valid certificate. In Central 16.4.1 and later, look under Preferences > Enrollment; in 16.4.0, the tab is Mobile. Older screenshots below show earlier labels.
For a new certificate:
- Use an organization-controlled Apple Account whose owner can renew the certificate. On a Mac, create a Certificate Signing Request in Keychain Access with Certificate Assistant > Request a Certificate from a Certificate Authority, saving it to disk. On Windows, follow the separate Windows certificate procedure below; do not improvise a Mac Keychain step there.
- Sign the CSR through FileWave's CSR portal, then submit the signed request to Apple's Push Certificates Portal using that Apple Account.
- Download Apple's certificate and combine/export it with the private key created by your CSR. The macOS Keychain procedure or Windows procedure supplies the platform-specific certificate/export steps. Keep the certificate and key files restricted; do not put them in screenshots or support notes.
- In Central's Apple push-certificate controls, select the prepared certificate/key file, upload it, and save Preferences. Check the displayed topic and expiration. If a current certificate already exists, renew that identity rather than replace it.
Renew the same certificate, with the same Apple Account and topic. A different certificate can break existing MDM communication and require reenrollment. Add the Server DNS name to the certificate's Notes in Apple's portal, compare topics in Apple and Central, and stop if they differ. Schedule reminders 45, 30, and 15 days before expiry; Dashboard email alerts are an additional reminder, not the only one. An accepted upload and a future expiration date establish configuration readiness; the enrollment and device-result checks on the next pages establish communication.
2. Configure ADE only if you chose ADE enrollment
- In Central, open Preferences > VPP & ADE > Configuration > Download Certificate on 16.4.0 and later. Earlier versions do not have the Configuration subtab.
- In the organization's Apple portal, create or select the intended external FileWave management service and upload that public certificate. Current Apple Business navigation uses Devices > Management Services; older Apple Business Manager/School Manager layouts and screenshots may say MDM Server under Settings.
- Download the Apple service token. In Central's Configure accounts control, add that token to the intended ADE account. Confirm account information and expiration. Keep the token private and assign an annual renewal owner. A healthy renewal normally does not require re-uploading the public certificate; see ADE token creation and renewal.
- In Apple's device inventory, select only the approved test serial and assign it to the FileWave service. In Assistants > ADE Association Management, use Synchronize and find that serial. If it is missing, first check the Apple assignment and account; use the optional full-sync guidance below only after those checks.
- Continue to Apple ADE Enrollment to create and assign the enrollment profile before device activation. Apple assignment alone is not MDM enrollment or Client installation.
3. Prepare Apps and Books when you are ready to deliver an app
A Location in Apple School Manager owns its Apps and Books licenses. Current Apple Business calls these organizational units; FileWave and older Apple Business Manager screens still use Location/token terminology. Its server token lets FileWave synchronize those licenses. FileWave still uses VPP in several controls.
- Have the Apple administrator select or create a separate evaluation Location if another MDM uses the existing token. Download that Location's token from the portal's Apps and Books/server-token settings. Never accept an ownership takeover as a routine import step.
- In Central Preferences > VPP & ADE > Configuration (16.4.0+; the single pane in earlier versions), open Configure tokens, add a distinguishable token name, and import the downloaded
.vpptoken. Record its owner and expiration. If it is not visible, ask a FileWave administrator to check your token permissions before importing it again. - Create an unassigned evaluation Fileset group. In the token's Auto create filesets settings, use Choose to select that destination, then save the token and Preferences. Do not choose a Fileset group already deployed to a fleet: newly imported content could become part of that Deployment. The administrator can review token visibility under Assistants > Manage Administrators > Manage VPP Tokens; the Manage VPP codes permission also affects access. See Managing FileWave Administrators.
- Acquire one approved free app for the correct platform and test Location, with enough licenses for the test. Apple requires a configured payment method even for free licenses; have the authorized Apple administrator arrange that rather than purchase paid content as a workaround. Current Apple Business uses Apps & Services > Apps and Books > App Store and an organizational-unit selection; School Manager uses Apps and Books and Location. Choose managed licenses, not personal redemption codes. Wait for Apple to make the licenses available; an acquisition receipt is not installation evidence.
- In Central License Management, select Synchronize VPP. Review any automatic-Fileset-creation message and confirm both the license counts and the resulting app Fileset in the intended group. Availability is not guaranteed within a fixed number of minutes.
Return to iOS and iPadOS Software and Profiles for the one-app exercise. Mac Client-only evaluators can proceed through Apple Manual Enrollment to the macOS file exercise without configuring Apps and Books.
Resolve authentication without weakening it
Use the organization's approved enrollment identity policy. A generic shared account, an identity-provider flow, and no generic authentication are different decisions. An unexpected login prompt is a reason to confirm the policy and URL—not permission to disable authentication.
Central Preferences explains the hosted boundary and enrollment-authentication decision. For a self-managed Mac Server or Debian appliance, the authorized Server owner must validate a release-appropriate scoped change, backup, configuration check, reload, enrollment test, and rollback. The historical whole-file replacement below is review-only, not a runnable evaluation recipe. The linked LDAP example also contains the literal AuthBasicProvider lda4; do not silently change it or treat a guessed replacement as tested.
Ready to continue: the intended route is recorded, required integration identities are accepted, the test device is approved, and no existing fleet integration was taken over. If any of those is uncertain, stop before enrollment.
Optional detail and preserved examples
APNs renewal identity and older portal examples
Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.
The sections below retain integration details and older interface examples. Complete only the services selected in the first-device route above.
Apple Push Notification Service (APNS) Certificate
The APNs certificate enables FileWave to notify managed Apple devices of MDM work. It is required for Apple MDM, not for a native-Client-only Mac installation.
To create and upload an APNS certificate follow the instructions at one of the following links depending on your platform macOS or Windows. If you have a macOS machine available, the process is usually found to be easier on the Mac versus a Windows machine since macOS includes the built-in Keychain Access and Certificate Assistant.
The APNS certificate must be renewed annually. We recommend setting calendar reminders 45, 30, and 15 days before it expires. You can also configure FileWave Central's Dashboard to send expiration alerts by email.
When renewing your APNS certificate, be sure to use the same Apple ID that was used to originally create it. Creating a new certificate, or creating a certificate with a different Apple ID, rather than renewing the existing one used by FileWave, will break MDM communication with your mobile devices and require un-enrollment and re-enrollment. Take the following precaution to prevent this.
|
|
ADE account exchange and synchronization detail
Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.
Apple Automated Device Enrollment (ADE)
Use ADE when the approved test device belongs to the Apple organization and is ready for its authorized activation/enrollment route. Manual URL MDM enrollment does not require ADE.
Add new MDM Server to Apple
- Sign into the organization’s Apple portal with a role permitted to manage device services.
- On current Apple Business, use Devices > Management Services; the retained earlier portal example uses Settings and Add MDM Server.
- Create the approved FileWave service with a distinguishable name.
- In Central 16.4.0+, use Preferences > VPP & ADE > Configuration > Download Certificate. Earlier versions lack the Configuration subtab.
- Upload the downloaded public
FileWave ADE.pemcertificate to the correct Apple service and save it.


Sync Apple ADE within FileWave
-
After creating a new MDM Server, select it from the list.
-
Click "Download Token" and accept the warning message.
-
Navigate to "FileWave Central > Preferences > VPP & ADE", click "Configure accounts" from the bottom "Device Enrollment Program" section, and authenticate.
-
Click the "[+]" button in the lower left-hand corner and select the recently downloaded "FileWave_Token_XXXX-XX-XXTXX-XX-XXZ_smime.p7m" token file.
-
If data is populated in all of the columns of the "ADE Accounts" window, the token import was successful.


Assign devices from ASM/ABM to FileWave MDM Server
- In Apple’s device inventory, search for the exact approved serial and select only that device.
- Assign it to the intended FileWave management service; do not choose all Unassigned devices.
- In Central, open Assistants > ADE Association Management and select Synchronize.
- If the serial is missing, verify the Apple account/assignment first. Holding Option or Alt exposes the full-sync action; use it as a deliberate troubleshooting operation rather than the default first step.
- Confirm the exact serial appears. Profile assignment and device enrollment still follow on page 98.


Create ADE Profile and enroll Apple Devices
- These workflows will be covered in the ADE Enrollment section.
Apps and Books tokens, ownership, licenses, and import detail
Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.
Apple Volume Purchase Program (VPP)
The Apple Volume Purchase Program (VPP) is integrated into Apple School Manager and Apple Business Manager and allows you to purchase and deploy applications from the App Store. When purchasing (free or paid) VPP licenses you will need to assign the licenses to a "Location" within ASM/ABM and each "Location" within ASM/ABM corresponds with a VPP Token. You will import each VPP Token into FileWave to sync the licenses assigned to the particular "Location".
Use a separate evaluation Location and token when another MDM owns the existing Apps and Books token. Importing or taking ownership of an in-use token can revoke existing license assignments. Stop on ownership conflicts; migration requires approval from both management owners.
This section will not cover creating a new "Location" in ASM/ABM but more information can be found here from Apple School Manager User Guide or found here from Apple Business Manager User Guide.
Download VPP Token from ASM/ABM
- Log into Apple School Manager (ASM) or Apple Business Manager (ABM) using your organization's Administrator account.
- Navigate to "Preferences" in the lower left-hand corner.
- Select "Payments and Billing" from the middle pane.
- Find the desired "Location" name from the "My Server Tokens" section.
- Click "Download".

Import VPP Token into FileWave Central
VPP Token Permission
If the token is not visible, ask a FileWave administrator to verify your token access and confirm the import succeeded. Do not import again or take ownership to bypass a permissions issue. The older link to an “Allow new users to access existing VPP Tokens” section did not supply that procedure.
VPP Import.png — image omitted because it exposes a credential. The surrounding steps remain; use the approved settings, not screenshot values.

VPP Ownership
An ownership warning means another tool owns this Location token. Stop and involve the Apple and MDM owners. Use a separate evaluation Location rather than revoke working license assignments. A deliberate migration must review license availability, application impact, and rollback before taking ownership.
Purchase VPP Licenses from ASM/ABM
Please consult Apple School Manager User Guide or Apple Business Manager User Guide for more in-depth information regarding purchasing Apps and Books.
- Log into Apple School Manager (ASM) or Apple Business Manager (ABM) using your organization's Administrator or Content Manager account.
- Select "Apps and Books" from the left pane.
- Search for the application name you wish to purchase and verify its intended platform (iOS App vs. macOS App).
- Select the desired "Location" from the "Assign to" drop-down menu.
- Specify the quantity of licenses you'd like to purchase.
- For the evaluation, acquire only the approved quantity needed for the test. Large future license acquisitions belong in capacity and ownership planning, not this exercise.
- Click "Get" button to complete your purchase.
- Wait for Apple to make the acquired licenses available and check the resulting quantities; the elapsed time is not a completion guarantee.

Sync VPP Licenses into FileWave
After importing at least one VPP Token into FileWave and purchasing licenses, you can sync VPP within FileWave and automatically create Filesets for each VPP application.
Open FileWave Central and navigate to "License Management" from the left pane.- Click the "Synchronize VPP" button in the black menu bar.
- Synchronize VPP requests license synchronization. Inspect the resulting licenses and Filesets rather than assuming a fixed completion interval.
- You should receive a pop up message asking if you'd like to automatically create Filesets for your VPP applications. Click "OK".
- You should now see the VPP License information in the "License Management" section and a new Fileset in the "Filesets" section.
- If you'd like to change where the VPP Filesets are imported to, please refer to this section of "Software Group Structure".


Enrollment authentication choices
Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.
Enrollment Credentials
Choose the approved enrollment identity policy before enrollment. Generic credentials, an identity provider, and no generic authentication are distinct choices. Hosted customers contact FileWave; self-managed Server owners validate any scoped change and recovery plan. These reference links are not authorization to replace authentication configuration.
- Okta Credentials:IdP Setup: Okta
- Google Credentials:IdP Setup: Google
- Microsoft Entra ID: IdP Setup: Microsoft Entra ID
- LDAP Credentials: Using LDAP to enroll macOS/iOS/Android devices
Historical authentication commands — review only, do not execute
Historical reference for owner validation only. Do not execute commands, apply the old capability split, or launch a privileged capture from this section without a release-specific approved procedure. Hosted users perform no Server shell work.
Generic Username/Password:
-
Review-only historical account commands, not instructions to run on a hosted or unvalidated self-managed Server:
Manual Enrollment(OTA)sudo fwcontrol mdm adduser [name]Automated Device Enrollment (ADE):
sudo fwcontrol mdm adddepuser [name]Where [name] is the name of the account
-
Historical prompt description only: administrative authorization depends on the Server OS and account; do not use this as a root-login instruction.
-
The historical procedure then instructed you to enter a password for this account.

No Authentication:
-
Review-only historical whole-file replacement (unsafe as a starter recipe; do not execute):
cp /usr/local/filewave/apache/conf/mdm_auth.conf.example_no_auth /usr/local/filewave/apache/conf/mdm_auth.conf -
The historical overwrite instruction is withdrawn. Replacing the whole file can remove unrelated authentication controls.
-
Historical reload command retained for review; no replacement or reload procedure has been validated here.
/usr/local/filewave/apache/bin/apachectl graceful


No comments to display
No comments to display