Jamf Blog

Understanding Apple IDs and MDM

Discover how to use Apple IDs with Apple's Volume Purchase Program (VPP) and Device Enrollment Program (DEP).

Apple Deployment Programs Apple ID

You’ll use this Apple ID for the Volume Purchase Program (VPP) and the Device Enrollment Program (DEP). If this is your first time enrolling in any program on the Apple Deployment Programs website, you can create a new program agent account by following the steps below:

  • Go to https://deploy.apple.com.
  • Choose your country or region from the lower right corner of the window. Not all programs are available in all countries or regions.
  • Click Enroll Now.
  • Click Enroll next to Volume Purchase Program.
  • Enter and review your information carefully, then click Next.
  • Check your email for a message with the subject line “Enroll your Organization in Apple Deployment Programs,” then note your temporary password.
  • The program agent account will receive email notifications about the progress of your organization’s acceptance in the Volume Purchase Program. Make sure that any mail filters allow mail from all apple.com domains.

The following information is required:

  • First and last name of the individual enrolling on behalf of the organization
  • This must be a legal, human name. First and last names such as “IT Coordinator” or “iPad Deployment” will be returned to you to correct the information.
  • A work email address that isn’t associated with an iTunes or iCloud account, and that hasn’t been used as an Apple ID for any other Apple service or website

CAUTION: Don’t use this new Apple ID with an iTunes or iCloud account, or any other Apple services or website other than the Apple ID for Students program and the Volume Purchase Program. Doing so causes the Apple ID to stop working with all Apple Deployment Programs.

  • Work phone number
  • Title/Position
  • Business information
  • Data Universal Numbering System (D-U-N-S) number, which must match the legal organization name and address
  • Tax status (exempt or non-exempt)

Tax exempt status requires a VAT number from countries in the European Union. In Canada, an Apple customer number or Cert ID is required.

Apple Push Notifications Service (APNS) Apple ID

With Bushel, you will get up and running by obtaining an SSL certificate from Apple. The certificate allows Bushel to securely communicate with the Apple Push Notification service. You will complete this as a part of the account activation process. Here’s an overview of what will happen:

  1. Download the Certificate Signing Request (CSR) during account activation.
  2. Sign into the Apple Push Certificate Portal, then create a certificate and agree to the terms of use.
  3. Select the signed CSR downloaded from Bushel and click upload. After a moment, your certificate will be available for download.
  4. This certificate can now be uploaded to Bushel for use with the Apple Push Notification service.

iOS and the new IT

Employee / Device Apple ID

“An Apple ID is an identity that’s used to log in to various Apple services such as FaceTime, iMessage, the iTunes Store, App Store, iBooks Store, and iCloud. These services give users access to a wide range of content for streamlining business tasks, increasing productivity, and supporting collaboration.

To get the most out of these services, users should use their own Apple IDs. If they don’t have one, they can create one even before they receive a device or use the Setup Assistant built into iOS. This gives users an easy and streamlined way to create an Apple ID right from their iOS devices. Users do not need a credit card to create an Apple ID.”

iOS Enterprise Deployment Overview

In other words, your users can log in with their personal Apple IDs on the enrolled devices. It will allow them to have the full product experience with access to all of the device’s capabilities.

Importantly, Bushel allows your organization to enforce security policies and protect company information accessed on those devices. Bushel leverages Managed Distribution with the Volume Purchase Program, which integrates directly with each employee’s Apple ID. Simply use Bushel to email each employee an invitation to receive Apps and Bushel takes care of the rest.

That means your organization doesn’t have to deal with the headache of company-owned Apple IDs to have a successful deployment. It also gives your organization access to a feature called “Managed Open-in,” which limits data from flowing outside of work email and work apps.

Bushel Account Login

You’ll use an email address to create your Bushel account. This email is not tied to any Apple programs and can be whatever you’d like.

As with other examples, using a company or shared work email (i.e. mdm@company.com or bushel@company.com) would allow for personel transitions without interrupting access to Bushel.

Note: there is only one administrator account for Bushel.

Subscribe to the Jamf Blog

Have market trends, Apple updates and Jamf news delivered directly to your inbox.

To learn more about how we collect, use, disclose, transfer, and store your information, please visit our Privacy Policy.