Apple Manual Enrollment
Choose a manual route for one test device
Use URL Enrollment to MDM-enroll an approved, previously configured Mac, iPhone, or iPad without a factory reset. If the goal is only native Client file delivery on a Mac, install the correct Client PKG instead. These are different management connections: a Client check-in does not prove Apple MDM enrollment, and an installed MDM profile does not prove the native Client is running.
Adding a device to Apple School Manager or Apple Business for future ADE is a third task. It may require erasure; it is not a prerequisite for this manual URL exercise. Personal-device User Enrollment is a separate privacy-focused route described below, not another name for ordinary URL Enrollment.
Before either route
Choose one organization-approved test device. Record its identity, existing management, and cleanup owner. Back up any data that matters. Stop if it already belongs to another MDM or points to another FileWave Server; migration and configuration overwrite need explicit approval. Review inherited groups and Deployments before admission so your test cannot unexpectedly receive production work.
For Apple MDM, complete the APNs and trusted enrollment-URL checks in Apple Client Pre-Requisites. ADE and Apps and Books are not required solely for manual MDM enrollment. A Mac user needs local administrator approval to install the MDM profile. Confirm the approved authentication policy rather than disabling it when a prompt appears. Hosted customers send Server-side questions to FileWave Support or their assigned representative; they do not run Server shell commands.
Prepare a Mac Client package before enrollment or installation
Do this only if the Mac needs the native Client. For Server and Central 16.4.0+:
- Connect Central to the correct Server. Open Preferences > Enrollment > macOS in 16.4.1+, or Preferences > Mobile > macOS in 16.4.0.
- Select Show settings. Review the Server address, naming, routing/Boosters, and remote-connection settings. Do not enable location tracking or remote control just because an older example did. Do not change an existing Mac's connection settings without its owner's migration plan.
- Select Build macOS client package. In 16.4.1+, review the separate settings dialog; in 16.4.0, review settings in the platform pane. Wait for Ready for Enrollment and check the version.
- For MDM-assisted initial installation, keep Install for initial enrollment only enabled. The package is already stored for enrollment and does not need to be uploaded again. For Client-only installation, select Download macOS client package, transfer the PKG securely to the approved Mac, and install it with local administrator approval.
For Servers earlier than 16.4.0, use the external-builder branch in the optional reference below and Build Custom FileWave Client and Booster Installers. The package must be uploaded before an older Server can use it for MDM enrollment. A standalone Client-only installation does not require that upload. A Booster is optional. For an already enrolled Client, follow Upgrading FileWave Clients instead of using an enrollment PKG as an upgrade recipe.
Route A: manually enroll Apple MDM
- On the test device, open the enrollment URL supplied by your FileWave administrator, normally
https://yourfilewaveserver.domain.com:20443with your actual Server hostname substituted. Confirm the hostname and certificate identity before proceeding. Do not blindly trust a self-signed certificate or an unexpected profile; have the owner resolve trust first. - Select Enroll Device and complete the approved enrollment authentication if prompted. Download the management profile.
- Mac: open the downloaded
enroll.mobileconfig. In current macOS, open System Settings > General > Device Management, open the downloaded profile, and review the organization and permissions. Choose the applicable Continue, Install, or Enroll action and supply local administrator authorization when asked. Older macOS uses a different Profiles location; choose the installed OS version in Apple's profile-installation guide. The retained System Preferences screenshot is an older example, not a current navigation promise. - iPhone/iPad: use Safari for the download, allow the profile download, then open Settings > Profile Downloaded or Settings > General > VPN & Device Management. Select the downloaded profile, review its management permissions, and complete Install and the Remote Management approval prompts. Enter the device passcode only on the device when requested.
- Return to the device's management settings and confirm the installed FileWave MDM profile. On a Mac where the enrollment package was prepared, wait for the native Client to install and check in; package readiness alone is not installation proof.
The profile gives the organization management authority. Manual enrollment may allow the user to remove it, unlike enforced ADE management. An App Portal icon is not the success criterion, and the old iOS/iPadOS IPA-based Kiosk is retired. Apple Vision Pro uses the FileWave mobile enrollment workflow, but its on-device labels and capabilities follow the installed visionOS version; have the owner confirm those before treating the iPhone/iPad steps as identical.
Route B: native Client only on a Mac
Install the approved custom PKG prepared above, then confirm native Client arrival in Central. This supports the first Mac file exercise without adding APNs/ADE as Client-only prerequisites. Apple MDM profiles, Apps and Books management, and Apple-managed security controls need their own supported enrollment and platform conditions. Do not rely on an old Client-versus-MDM feature list to decide whether a specific encryption, recovery, firmware, update, lock, or erase workflow is supported on today's Mac.
Admit the record and check the result
First check whether Central already accepted the device. If it did, inspect that record rather than add another one. Otherwise use New Client, match the actual test identity, and choose Add Clients from the applicable queue: Desktop Clients for native Mac Clients, Enrolled Mobile Devices for the documented iPhone/iPad MDM route. For FileWave 16.4, Vision Pro guidance confirms New Client > Enrolled Mobile Devices. If a Mac's MDM/native Client records do not match your expectation, stop for owner review; do not select a similarly named record to proceed.
Manual admission changes the model. Review pending work with the other administrators before Update Model; a test device does not make that shared commit private. The Update Server Model dialog confirms the commit; it does not preview changes. Check the resulting model number, then separately confirm recent device communication. See the Model Update lesson.
Record the test identity, matching Central record, and recent information. For MDM, also record the installed profile/organization on the device. For the native Mac Client, record its version and recent Client communication. Desktop Last Connect and inventory Last Connected are different observations. Do not use Verify as a harmless refresh: it can execute manifest work. If the record is missing, check URL/certificate, profile approval, Server package readiness, and network connectivity before changing authentication or reinstalling.
Next: deliver one iPhone/iPad app or one Mac test file. Before cleanup, review which apps, profiles, accounts, certificates, and data depend on management. Removing MDM may remove managed items and their data; uninstalling the native Client is a separate operation. Do not wipe, lock, or enable tracking as an enrollment test.
Optional: add eligible devices to the Apple organization with Configurator
Eligible Macs can be added. Apple's Configurator requirements and procedure cover Macs with Apple silicon or an Apple T2 Security Chip, with macOS 12.0.1 or later, using Apple Configurator for iPhone. Those are Apple's Configurator requirements, not a FileWave OS support statement. An already configured Mac must first have its content and settings erased. Back up, obtain erase approval, and confirm recovery/Activation Lock ownership before starting.
For a qualified Mac, sign into Configurator with an authorized Managed Apple Account, arrange network access, and pair at Select Your Country or Region in Setup Assistant. Wait for Apple assignment to complete and shut down as directed. Then assign the correct FileWave service, synchronize the serial and enrollment profile, and return to Apple ADE Enrollment before continuing setup.
Configurator for Mac supports adding eligible iPhone/iPad and Ethernet-capable Apple TV devices; it is not the app used to add a Mac. Follow Apple's platform-specific preparation instructions, not a universal reset recipe. Manually added devices have a 30-day provisional period beginning after assignment and successful enrollment, during which the user can release the device from the organization, supervision, and management. Removal in some Configurator enrollment flows can erase and release the device; it is not a harmless cleanup shortcut.
Optional: personal iPhone/iPad User Enrollment
Use a separate, approved BYOD design when the device is personal. User Enrollment separates organizational management from personal data and has more limited management capabilities. It needs Managed Apple Accounts and the corresponding identity/discovery configuration.
For modern iOS/iPadOS, use Account-Driven User Enrollment, supported by FileWave 15.5+. Profile-based User Enrollment was deprecated in iOS/iPadOS 17 and is not supported in 18 and later. The older User Enrollment overview below remains historical context, not a current enrollment recipe. The organization must configure its discovery domain, authentication, and permitted apps first; do not copy example well-known URLs or Server configuration into production. Return to the same record/profile verification checks after the owner has validated that separate workflow.
Optional detail and preserved examples
Configurator and URL-enrollment context
Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.
Choose a manual enrollment method
A device missing from the Apple organization may still support manual URL MDM enrollment. Eligible Apple silicon or T2 Macs can also be added using Apple Configurator for iPhone; follow the hardware, OS, erase, and provisional-period requirements in the optional route above. DEP is the older name for ADE.
Add eligible devices to the Apple organization with Configurator
Adding a device for future ADE is distinct from enrolling it by URL now. Apple Configurator for iPhone supports qualifying Macs; Configurator for Mac supports qualifying iPhone/iPad and Ethernet-capable Apple TV devices. Use Apple’s current platform-specific procedure, prepare for any required erasure, and then return to Apple ADE Enrollment. The 30-day provisional release period and removal/reset consequences must be part of the owner’s plan.
MDM-enroll Apple devices using URL Enrollment
If ADE is unavailable, you can MDM-enroll an iPhone, iPad, Apple Vision Pro, or Mac using FileWave URL Enrollment. This method allows an end user to enroll a previously configured device without a factory reset. The user may be able to remove the MDM profile and unenroll the device. On macOS, the user also needs administrator privileges to install the MDM profile.
An authentication prompt must match the approved policy. Confirm it with the Server owner; do not disable authentication as a troubleshooting shortcut. Hosted readers contact FileWave Support.
Older profile-download and approval examples
Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.
macOS URL Enrollment

Apple mobile URL Enrollment: iPhone, iPad, and Vision Pro
Use the same FileWave enrollment URL and MDM-profile approval flow on Apple Vision Pro. The exact on-device labels follow the installed visionOS version.
![]() |
![]() |
![]() |
![]() |
![]() |
User Enrollment and historical capability questions
Historical reference for owner validation only. Do not execute commands, apply the old capability split, or launch a privileged capture from this section without a release-specific approved procedure. Hosted users perform no Server shell work.
iOS User Enrollment (BYOD)
User Enrollment is a separate BYOD design with Managed Apple Accounts, privacy separation, and limited management. Use Account-Driven User Enrollment for the modern route (FileWave 15.5+). Profile-based User Enrollment is deprecated in iOS/iPadOS 17 and unsupported in 18 and later. Do not use a historical iOS 13 walkthrough as current setup guidance.
The older User Enrollment overview and its limitations explain historical context. Validate account-driven discovery, identity, supported OS, and permitted management with the owner before a personal-device test.
Enroll non-MDM macOS Client
A Mac can be enrolled with only the native FileWave Client by installing the correct PKG with local administrator approval. This does not create an Apple MDM enrollment. Choose the connection required for the intended task, then verify it separately.
| Original examples to validate for the exact release, hardware, and enrollment |
|---|
| Apps and Books/VPP; profile deployment and Security & Privacy restrictions; FileVault encryption and recovery-key escrow; shutdown/reboot; device lock; Activation Lock bypass; firmware passwords; MDM and legacy software updates; location tracking; PKG/app/script Filesets; limited profile restrictions; Observe Client; Remote Wipe; inventory and Custom Fields. |
| The old available/unavailable split mixed legacy OS and hardware behavior. The native Client file exercise above is the bounded route taught here. Lock, wipe, tracking, remote observation, and encryption changes are not enrollment verification tests. Consult the relevant release and feature owner before evaluating them. |
Version-specific native Client package detail
Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.
Generate a custom FileWave Client PKG
Server 16.4.0 and later: Use Build Custom FileWave Client and Booster Installers to configure, build, and download the macOS package in Central. Install that PKG on the new device, then continue with Finalizing adding of clients. A package already prepared for MDM enrollment does not need to be uploaded again. To upgrade an existing Client, follow Upgrading FileWave Clients instead.
Servers earlier than 16.4.0: External builder
The builder steps, field reference, and screenshot below apply to the earlier-Server workflow.
- custommsi.png — image omitted because it exposes a credential. The surrounding steps remain; use the approved settings, not screenshot values.Open the FileWave Customer Installer Builder for macOS.
- Fill out the settings accordingly.
- Click the "Build" button and wait for the automatic download.
- Extract ZIP and install the customized FileWave Client PKG.
Legacy field descriptions, not universal defaults: The current external Mac builder says the Client Password is not used for FileWave 16.0.0+ Clients. Earlier field descriptions below are retained for older deployments; do not infer that this password controls current remote connections. Review the actual version-specific builder settings before changing ports, tracking, overwrite behavior, or remote access.
| Mandatory Settings |
| Product Version = Your FileWave Server Version |
| Sync Computer Name = macOS Hostname will be FileWave Client Name (recommended) |
| Server Name = Fully Qualified Domain Name of your FileWave Server |
| Server Port = 20015 (do not modify) |
| Client Password = Password used to change individual Client Preferences |
Note: The default port setting for Server Port above is 20015. However, SSL is now required, and the system will automatically use port 20017 instead when 20015 is entered. Do not manually set the port to 20017. Always enter 20015, and the system will handle the SSL port change for you.
| Optional Settings |
| Is Tracking = Is Location Tracking Enabled for macOS Clients |
| Monitor Port = Port used for FileWave Client Monitor (do not modify) |
| Overwrite Configuration = Overwrites existing Client configuration; require owner approval before changing an already configured Mac |
| Remotecontrol Enabled = Screen-sharing enabled for macOS Clients |
| Remotecontrol Prompting = Whether to prompt the end user before starting a screen-sharing session |
| Server Certificate = Upload a certificate only if you are using a self-signed certificate; not required for a CA-signed certificate |
| Server Publish Port = 20005 (do not modify) |
| Tickle Interval = Idle time for macOS Clients before checking for new Model Update (do not modify) |
| Vnc Relay Port = 20030 (do not modify) |
| Vnc Server Port = 20031 (do not modify) |
| Booster Settings |
| Initially you may want to make an installer that does not include Boosters. Read more about them here: Boosters |
Admission and older Central interface examples
Use this detail only for the selected optional task. Older screenshots retain their original labels and examples; do not copy their values or treat them as current device-test evidence.
Finalizing adding of clients
Check for an already accepted record before opening New Client. If approval is pending, match the exact identity and admit only that record. Native Mac Client arrival and MDM enrollment are separate observations.
- Open FileWave Central.
- Click on the “New Client” button in the tool bar
- Select Desktop Clients for native macOS Clients or Enrolled Mobile Devices for iPhone, iPad, and Apple Vision Pro.
- Select your new client from the list presented.
- Click the “Add Clients” button in the lower right.
Manual Add Clients changes the model. Coordinate with other administrators, review shared pending work, and use Update Model. The confirmation dialog is not a preview; verify actual device completion separately.
Automatic admission is an optional Server policy, not a prerequisite. If already enabled, inspect the accepted record rather than adding a duplicate. Review Central Preferences with the owner before changing a shared policy.
Making Changes to the Model
Use Update Model for reviewed model-changing operations such as manual Client admission and Deployments. Do not append it to every ADE sync, profile approval, or unrelated preference. A higher model number proves publication, not receipt or completion.
Continue only after matching device-side enrollment evidence with the correct Central record and recent communication. Then perform the single app or file exercise, not a fleet rollout.

Navigate to "https://yourfilewaveserver.domain.com:20443" using your preferred web browser.






No comments to display
No comments to display